I build this in stages, starting with a documented feasibility spike. Every attachment point Shopify checkout exposes is tested as a numbered experiment, with a written verdict, and a blockers register of what does not work. Then I write a legal-risk memo in plain language your counsel can act on — this is technical implementation, not legal advice. Only if a working path exists do I build it: a custom-distribution Shopify app with checkout UI extensions for the pay, retry and confirm flow, webhook signature verification, and a single correlation rule. The rule is strict: only the provider’s paid status marks an order paid, never a browser return, and every order marking is read back from the API.