E-commerce developer insurance: cover for the people who build online stores
Reviewed by Matthew Bartlett, Director, Apex Insurance Brokers Limited · Last reviewed 2026-08-06
If you build online stores for a living, you build the machinery your clients’ revenue flows through. That is what makes e-commerce development different from most other software work: when something you shipped goes wrong, the client does not just have a bug report — they have a number. Orders per hour, average basket value, conversion rate, hours of downtime. Multiply them together and you have the opening figure in a claim letter. This guide walks through the cover that fits that risk profile, whether you are a solo Shopify developer, a WooCommerce specialist or an agency running Magento builds and retainers.
Why is e-commerce development riskier to insure against than other dev work?
Plenty of software failures cause inconvenience. E-commerce failures cause measurable revenue loss, and measurable loss is what turns an annoyed client into a claimant. A checkout that silently fails after a Friday-evening deployment, a payment gateway integration that declines legitimate cards, a caching change that serves stale stock levels, a theme update that breaks the add-to-basket button on mobile — each of these can run for hours before anyone notices, and every one of those hours has a pound value the client can evidence from their own analytics.
Timing sharpens it further. Retail clients concentrate a disproportionate share of annual revenue into short trading windows — seasonal peaks, product launches, promotional weekends. A defect that would be a minor irritation in a quiet week becomes a significant loss if it lands during the client’s busiest days. Migrations carry a version of the same risk stretched over weeks: replatforming a store and losing URL structures, order history or search visibility in the process is one of the most recognisable fact patterns behind technology professional indemnity claims, because the client can chart their traffic falling off a cliff on the day you went live.
What does technology professional indemnity cover for an e-commerce developer?
Technology professional indemnity (tech PI) covers claims that your professional work was negligent, defective or fell short of what the contract promised, and that the client suffered financial loss as a result. It pays for your legal defence and, where you are liable, the damages — which matters, because even a claim you successfully defend can cost serious money in legal fees alone. You may also see this cover called technology errors & omissions, or tech E&O: that is the US name for broadly the same product, and contracts drafted for international clients often use the two terms interchangeably. It is one cover, not two.
For e-commerce work specifically, the scenarios a good tech PI policy is built for include:
- A deployment or plugin update breaks the checkout or basket during a trading period, and the client claims for lost sales.
- A platform migration loses product data, order history or established URLs, and organic traffic collapses.
- Misconfigured tax, shipping or discount rules mean customers are charged incorrectly and the client bears the cost of putting it right.
- An integration between the store and a fulfilment, ERP or email system fails, and orders are lost or duplicated.
Most tech PI wordings also pick up related exposures such as disputes over whether deliverables met the specification, allegations of unintentional infringement of intellectual property (a licensed image or a code library used outside its terms), and negligent advice — relevant if you recommend platforms, apps or hosting as part of your service. One point worth being precise about: professional indemnity is not a legal requirement for developers. No statute obliges you to hold it. It is, however, close to a universal contractual requirement — client master service agreements, agency subcontracts and marketplace terms routinely require evidence of PI before work starts. For a deeper look at how the cover works, see our guide to technology professional indemnity insurance.
Do I need cyber insurance if the stores belong to my clients?
Yes — and this is the exposure e-commerce developers most often underestimate. The stores may belong to your clients, but the access belongs to you: admin logins, API keys, deployment credentials, payment gateway configuration, and often staging environments holding copies of live customer databases. If your laptop, password vault or development environment is compromised, the attacker does not get one business — they potentially get a route into every store you maintain. That concentration of access is exactly what makes agencies and freelance developers attractive targets.
Cyber insurance responds to security events rather than professional mistakes. On the first-party side, it typically funds incident response — forensic investigation, specialist legal advice, notification of affected individuals — along with your own business interruption and costs such as data restoration. On the third-party side, it covers claims from clients or others who say your security failure caused them loss. If personal data is involved, UK GDPR and the Data Protection Act 2018 apply, and the Information Commissioner’s Office (ICO) is the regulator; a good policy funds the legal help you need to handle notification and any regulatory engagement properly. Be careful with one common assumption, though: whether regulatory fines themselves can be insured under English law is genuinely uncertain, and policies often exclude or restrict them. Treat cyber cover as funding your response, your downtime and your liability to others — not as a mechanism for paying a fine.
PI and cyber also interlock. A vulnerability you coded that an attacker later exploits can sit awkwardly between the two policies — is it defective work or a security event? Buying both covers together, with wordings designed to dovetail, removes the gap where each insurer might otherwise point at the other. We explain the boundary in plain English in cyber insurance explained.
Larger or more complex risk? Speak directly to a director — call 0117 325 0027 or email info@apexinsurancebrokers.co.uk.
We arrange tech PI and cyber for e-commerce developers and agencies every week — tell us what you build and we’ll match the cover to it.
Get a tailored quote →Is PCI DSS a legal requirement, and does it affect my insurance?
PCI DSS — the Payment Card Industry Data Security Standard — is not legislation. It is an industry standard set by the payment card brands and enforced contractually: merchants agree to comply as a condition of their agreements with acquirers and payment providers, and those obligations flow down to anyone who builds or touches the systems handling card payments. Nobody is prosecuted under PCI DSS, but the contractual consequences of non-compliance are real for your clients — assessments passed on by acquirers and, ultimately, the ability to take card payments at all — which is why serious e-commerce clients expect their developers to understand it.
For insurance purposes, what matters is scope. If your builds use hosted payment fields or platform-managed checkouts, cardholder data may never pass through systems you control, which keeps your exposure narrower. If you build custom payment integrations, handle redirects and tokens, or work directly with gateway APIs, you are closer to the cardholder data environment and insurers will want that described accurately on your proposal. Some cyber policies also address PCI-related contractual assessments, but treatment varies significantly between wordings — this is exactly the kind of detail a specialist broker reads before you buy, not after a claim.
Do I need public liability and employers’ liability insurance?
Public liability covers injury to people and damage to property in the physical world — less dramatic than a checkout outage, but not irrelevant. If you visit client offices, work from co-working spaces, attend trade events or occasionally host clients, PL picks up the everyday accidents: a client’s staff member tripping over your kit bag, a drink over someone else’s equipment. For most developers it is an inexpensive companion to the main covers and often a box clients expect ticked in supplier onboarding.
Employers’ liability is different in kind: once you employ staff, it is a legal requirement under the Employers’ Liability (Compulsory Insurance) Act 1969, with only narrow exceptions — for example, some businesses employing only close family members, and certain companies where a sole director holds most of the shares. The duty is drawn widely. Part-time staff count. Depending on how the working relationship is structured, some freelancers and long-term subcontractors can count too. If you have taken on your first junior developer, or you regularly bring the same contractor into your team under your direction, EL needs to be in place from day one — and it is worth a conversation rather than a guess about who falls inside it.
Does it matter whether I build on Shopify, WooCommerce or Magento?
Yes — not because insurers favour one platform, but because the platform shapes where your responsibility sits. On a hosted platform such as Shopify, the platform operator runs the infrastructure, so your exposure concentrates in what you control: theme and app code, integrations, data imports and the migration itself. On self-hosted stacks — WooCommerce on WordPress, or Magento (Adobe Commerce) — your remit often extends to hosting choices, server configuration, patching and security hardening. A wider remit is a wider duty, and insurers will ask whether you manage hosting and maintenance as well as build.
Maintenance retainers deserve particular attention. A retainer extends your duty through time: if a known vulnerability in a plugin or extension goes unpatched for months on a store you are paid to maintain, and that store is later breached, the client’s lawyers will look hard at your role. That is not a reason to avoid retainers — they are good business — but it is a reason to make sure your proposal form describes them, so the policy you buy actually reflects the work you do. Describing yourself as “web developer” when you are effectively the outsourced platform team for twenty retailers is how coverage disputes start.
What limits of cover do e-commerce clients usually ask for?
In practice, limits are driven by contracts. Client agreements commonly specify a minimum PI limit — £1m is a frequent floor, with £2m or £5m appearing in contracts from larger retailers and the agencies that serve them; these are illustrative options rather than recommendations. When deciding what is actually enough, think about three things: the revenue of the largest store you touch and what a day of its downtime is worth; when your riskiest deployments happen relative to your clients’ peak trading; and aggregation — whether one mistake, such as a bad update pushed to every store on your maintenance list, could generate several claims at once.
Remember too that PI is almost always written on a claims-made basis: the policy that responds is the one in force when the claim is made, not when the work was done. E-commerce claims often surface long after go-live — a migration’s SEO damage can take months to quantify — so keeping cover continuous, protecting your retroactive date when you switch insurer, and considering run-off cover if you ever close the business all matter more in this sector than most.
How should a solo e-commerce contractor approach this?
If you contract through your own limited company, the same logic applies at smaller scale: tech PI to satisfy agency and end-client contracts, cyber because you hold the same kind of privileged access an agency does, and EL only if you take someone on. One boundary worth stating plainly: if you work inside or around the off-payroll working rules, IR35 is a tax question about employment status, decided on the facts of each engagement — holding insurance neither changes nor evidences your status, and the right person to advise on it is a qualified accountant or tax adviser, not an insurer. What insurance does do is meet the contractual requirements agencies impose and protect you when a build goes wrong. Our IT contractor insurance guide covers the contractor-specific angles in more depth, or you can start a quote online in a few minutes.
Why arrange e-commerce developer insurance through Apex?
Because the difference between a policy that pays and a policy that argues usually comes down to how well your work was described and how well the wordings fit together. We are an independent, FCA-authorised broker based in Bristol, and technology businesses are our specialism — we know what a replatforming project looks like from the inside, why a Black Friday deployment freeze exists, and which insurers write e-commerce risk well. We will read the insurance clauses in your client contracts, align your PI and cyber so neither insurer can point at the other, and make sure retainers, hosting responsibilities and payment work are properly declared. If your situation is unusual — a mix of build work, retainers and your own SaaS product, say — speak to an Apex specialist and we will structure it properly rather than force it into a standard box.
Build stores for a living? Get PI and cyber that were actually arranged by people who understand what a broken checkout costs.
Get a tailored quote →Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This article is general information, not advice on a specific policy or a recommendation to buy any product.
