How to spy on competitor dropshipping stores (legally)
Most of what you want is published because a regulator required it. Here is what each public ad library actually gives you, what a storefront proves and does not prove, and exactly where the legal line sits.
The short answer
You can learn a surprising amount about a competitor without doing anything a lawyer would blink at, because the most valuable part is published by law. Under the EU’s Digital Services Act, every very large platform has to run a public, searchable repository of the ads it serves. So a competitor’s ad creative, the page they send traffic to, the date the campaign started, and for ads delivered in the EU their targeting parameters and reach, are all sitting on a public page with a search box on it. Nobody has to be hacked for you to see them.
What you cannot do is take what sits behind a login, invent an account to get at it, or lift their video and run it as your own. The useful line is not public versus private. It is closer to three separate lines: reading is fine, breaking in is not, and copying is a different problem from both.
This guide is general information rather than legal advice, and the rules differ by country. Where a claim comes from a specific case or regulator, the source is named in the sentence so you can check it yourself.
What legal actually means here
Almost every argument about competitor research collapses once you sort the information into tiers. The tiers behave completely differently, and most people who get into trouble did so by treating the third one like the first.
| Tier | What is in it | Honest status |
|---|---|---|
| Published because a regulator said so | Meta Ad Library, TikTok Commercial Content Library, Google Ads Transparency Center, Pinterest’s EU ad repository | Read it freely, by hand or through the official APIs. This is the good stuff |
| Public, but the terms have opinions | A competitor’s storefront, product pages, sitemap, collection sorting, review counts | Reading it in a browser is unremarkable. Automated collection at volume is where contracts, database rights and privacy law start to bite |
| Behind a wall | Order counts, real ad spend, supplier invoices, customer lists, anything needing an account you are not entitled to | Off limits. Fake accounts and borrowed logins are how a research habit turns into a legal problem |
| Copying, not looking | Their video creative, product photography, brand name, store copy | A separate question from access entirely, and the one that actually gets stores and ad accounts shut down |
Start with the sources the law forces open
Article 39 of the Digital Services Act requires very large platforms to publish a searchable repository of every ad they serve, including the ad content, who the advertiser is, who paid, the dates it ran, whether it targeted specific groups and the main parameters used, and aggregate counts of how many people it reached. That obligation is why the four surfaces below exist and why they are free. They are not a favour from the platforms.
| Library | What you get | What is missing |
|---|---|---|
| Meta Ad Library | Every ad currently running on Facebook and Instagram, searchable by page name, with creative and landing page. For ads delivered in the EU, a European Union transparency panel adds the targeting parameters and reach | No spend on ordinary commercial ads. Meta keeps EU-delivered ads for about a year after their last impression and political ads for seven years, so history outside the EU is thin |
| TikTok Commercial Content Library | Advertiser, creative, first and last shown dates, targeting criteria and reach ranges, retained a year after the last view | Coverage is the EEA, the UK and Switzerland only. No spend, no click-through rate, and no US data at all |
| Google Ads Transparency Center | Ads across Search, YouTube, Maps, Play and Shopping: verified advertiser name, creative, landing URL, region and date range | No spend, no keywords, no bidding detail. Advertisers who never completed Google’s verification do not appear at all |
| Pinterest EU ad repository | EU-served ads with targeting keywords, including negative keywords, kept for a year | EU only, and Pinterest is a smaller advertising surface for most dropshipping niches |
Two honesty notes before you build a strategy on these. First, none of them show spend for ordinary commercial ads, so any tool quoting you a competitor’s ad budget is modelling a number it cannot see. Second, the repositories are not complete. On 15 May 2025 the European Commission preliminarily found that TikTok’s ad repository breached the Digital Services Act, specifically because it did not provide the content of the ads, who was targeted or who paid, and did not let the public search comprehensively. On 5 December 2025 the Commission accepted binding commitments from TikTok to fix it: the full ad content as it appears in feed including the URLs in the ad, updates within a maximum of 24 hours, the targeting criteria advertisers selected along with aggregated gender, age group and member state reach, and additional search filters. That is a real improvement, and it also tells you plainly that the data was incomplete before it. Treat a missing ad as missing data, never as proof that nobody is advertising.
The field is smaller than it looks
The first thing an ad library does for a beginner is deflate the panic. The niche that feels impossibly crowded on YouTube usually has a few dozen advertisers in it, not thousands.
As of August 2026, no niche on our radar carries more than roughly fifty products with live ads at once. That is the real shape of the competition: a field small enough to read in an afternoon. It also sets your expectations for how much there is to find, which stops the endless searching that substitutes for launching. If you want the wider version of that argument, see best dropshipping niches and how many products a store should have.
The most useful field is the start date
Everyone looking at an ad library reads the creative. The creative is the least reliable part, because you cannot tell a hit from a flop by looking at it. The valuable field is the date the ad started running, because it is the only public number that carries an economic fact: nobody keeps paying to run an ad that loses money. An ad still live after eight months has survived hundreds of decisions by someone with a spreadsheet.
As of August 2026, the longest continuously running ad in our data has been live past 1,000 days. That is close to three years of one advertiser choosing, every single day, not to switch it off. No store page, review count or follower number tells you anything that strong.
Be equally clear about what longevity does not tell you. It does not reveal their margin, their supplier cost, or whether the same product clears at your cost base rather than theirs. A long-running ad proves the product sells profitably for someone with their buying power and their creative, which is a different claim from proving it will work for you. Run it through the profit margin calculator before you believe anything about your own economics, and read dropshipping profit margins for why gross margin flatters almost every product on the radar.
Reading their store, by hand
Once the ad library tells you which product carries the budget, the storefront fills in price, positioning and page structure. All of it is visible in a browser. The trap is not access, it is over-reading: most of these signals prove far less than the tools built on top of them imply.
| Signal | Where it is | What it does not prove |
|---|---|---|
| Which product carries the budget | The landing pages in their ad library entries, not their catalog | That the rest of the catalog matters. Most of it is filler |
| Catalog and price points | Their sitemap.xml and collection pages. Most Shopify stores also serve a public /products.json with titles, prices, variants and images, up to 250 products per page, though merchants can and do switch it off | Their cost, and therefore their margin. A price tells you their positioning, not their economics |
| Best seller ordering | Sorting a collection by best selling | Real order volume. Shopify collections can be sorted and pinned manually, so the order can simply be what the owner wants you to see |
| Review counts | The product page | Sales. Review apps routinely import reviews with the product, so a new store can launch with hundreds |
| Price and page history | The Internet Archive Wayback Machine | Volume. It shows what they tested and kept, which is genuinely useful, and nothing about how much they sold |
| Theme and apps | Page source | That copying the stack helps. Their upsell app is not why they are profitable |
The one genuinely underrated move on this list is buying from them. A test order is legal, cheap and tells you what no amount of looking can: real delivery time, what the packaging says, whether the product matches the ad, what their post-purchase email flow does, and how they handle a return. If you sell into the EU, that also surfaces how they deal with the €3 import duty and the 14-day withdrawal right, which is where a lot of stores quietly fail. See dropshipping in Europe and how to find EU suppliers.
Where automated collection crosses a line
This is the part every guide either skips or gets confidently wrong, so here is the state of it with the cases named. In the United States, the Ninth Circuit in hiQ Labs v. LinkedIn held that scraping data that is already public does not amount to access without authorization under the Computer Fraud and Abuse Act, reaffirming that reading in April 2022. That is the ruling everyone quotes. What they leave out is that hiQ still lost on the contract: it had agreed to LinkedIn’s user agreement, which forbade scraping, and LinkedIn ultimately won a permanent injunction on that basis. Not a crime, still a breach of contract.
Meta Platforms v. Bright Data sharpened exactly that distinction. In January 2024 Judge Edward Chen held that Meta’s terms of service do not prohibit scraping of publicly available data performed while logged out, because someone who is not logged in is not a user bound by those terms, and dismissed Meta’s breach of contract claims. A claim for tortious interference survived, so this is not a clean win for scrapers. The practical lesson is narrow and useful: whether you were logged into an account when you collected the data can decide the case.
In the EU the shape is different again. The Database Directive gives a database maker a sui generis right to prevent extraction of a substantial part of a database where they made a substantial investment in it, and EU courts have applied it to systematic scraping even where every individual data point was public. The reported test focuses on whether the extraction threatens the maker’s ability to recoup that investment, so reading a few hundred prices is a genuinely different act from mirroring an entire catalog. Separately, if what you collect includes personal data, GDPR applies on its own terms: the European Data Protection Board opened its Guidelines 03/2026 on web scraping for public consultation on 7 July 2026, treating legitimate interest as the realistic legal basis and, in practice, making compliance a documented record of what you excluded and filtered rather than a yes or no permission.
Translated for a person running one store: you almost certainly do not need to scrape anything. Everything in this guide is a browser tab, and the moment you are writing a crawler against a competitor you have taken on a legal question in exchange for data that will not change your decision.
Four things that are never worth it
- Fake accounts and borrowed logins. Creating an account under a false identity to reach a members area, a wholesale price list or a private community is the point where research becomes misrepresentation, and it is also the version that breaches terms you personally agreed to.
- Running their creative as your own. Downloading a competitor’s video, trimming it and putting spend behind it is copyright infringement, and it is the fastest self-inflicted store death in dropshipping. Meta and TikTok both act on DMCA complaints quickly, and a disabled ad account takes the store’s revenue with it. Study the structure of an ad, the hook, the objection it answers, the order of proof, then shoot your own. Structure is not protected. The footage is.
- Product photography that is not yours. Supplier images you are licensed to use are fine. A competitor’s studio photography is theirs, and the assumption to hold is that any image you find is copyrighted unless you know otherwise.
- Their brand name. Trademark law is not the same as copyright and does not care whether you copied anything: a confusingly similar name in the same category is a problem on its own.
The trap: finding the winner is not permission to sell it
The reason competitor research disappoints so many beginners is that it is very good at the easy half of the problem. Finding what sells is straightforward now. Selling it against the person you found it from is not, because they have been optimising that auction for months, they have a creative library you do not have, and they may be buying at a volume price you cannot reach.
This is what a niche that every spy tool has already surfaced looks like. There is nothing wrong with entering it, but enter it knowing that your ad has to beat an incumbent, not just exist. That means the honest question after research is arithmetic, not inspiration: at your price and your product cost, what return do you need before you break even, and is that plausible for a newcomer in that auction? Work it out on the breakeven ROAS calculator, sanity check the crowding with the product saturation checker, and if you are selling into Europe, add the duty with the EU landed cost calculator before you decide. The related reading is how to validate a product and Facebook ads vs TikTok ads, which covers what the budget floor on each platform actually is.
A 30-minute competitor teardown
- Find the advertisers, not the stores. Search your niche keyword in the Meta Ad Library and the Google Ads Transparency Center, and in the TikTok Commercial Content Library if you sell into Europe. Note every advertiser running more than one ad.
- Sort by how long each ad has run. Anything past a few months goes on the shortlist. Everything else is someone testing, which tells you nothing yet.
- Open the landing page from the ad, not the homepage. The ad tells you which product they are betting on. The homepage tells you what they want visitors to think the brand is.
- Write down the price and the offer. Price, shipping charge, delivery promise, guarantee, bundle. That is the offer you would have to beat, and it is usually the offer rather than the product that is winning.
- Check the EU transparency panel if the ad ran in the EU. Targeting parameters and reach are published there, which is the closest thing to seeing someone’s audience setup that exists legally.
- Do the arithmetic before the inspiration. Your cost, your price, your breakeven return. If the numbers do not work, you found a competitor rather than an opportunity, and knowing that took half an hour instead of half a budget.
Where SpotPeaks fits, honestly
Everything on our radar comes from the public ad libraries described above. We do not scrape competitor storefronts, we do not estimate anyone’s revenue, and we do not sell you a spend figure that the libraries do not publish, because we would be making it up. What we add is the one thing you cannot get by opening the library today: time. We record ads continuously, so we can show how long each one has been running rather than just that it exists right now.
The SpotPeaks radar currently tracks 640 products with live ads across 80 niches, and that coverage is Facebook-weighted at the moment, so read it as a Facebook-first view rather than a complete picture of every platform.
You can browse the niches free at winning products and Facebook products, and every calculator on this page needs no account. The Ad Finder and Store Intel, which pairs the advertisers we see with products you can actually source, are part of the paid product: $39 per month after a 14-day free trial.
The verdict
Legal competitor research in 2026 is mostly a reading exercise, and the best material is published under legal compulsion rather than found. Work the ad libraries first, treat the start date as the most informative number on the page, use the storefront to fill in price and offer, and buy from them once. Skip the scraping, skip the fake accounts, and never run someone else’s footage.
We cannot guarantee profit, and no research method can: knowing exactly what a competitor sells and how long they have sold it still leaves the two things that decide your outcome, which are your cost base and your creative. What good research does is stop you spending a month and a budget discovering something that was published on a public page the whole time. Next step: pick one niche on the winning products radar, run its top candidate through the profit margin calculator, and if the margin survives, go read how to find winning products and how to get traffic for what happens after the research stops.
FAQ
Is spying on competitor dropshipping stores legal?
Looking at what a competitor publishes is legal essentially everywhere, and the most valuable data is published because regulators require it: Article 39 of the EU Digital Services Act obliges very large platforms to run a public, searchable repository of every ad they serve, including the creative, the advertiser, who paid, the dates and, for EU-delivered ads, the targeting parameters and reach. What is not legal is accessing anything behind a login you are not entitled to, using a false identity to reach private areas, or copying their creative and running it as your own. This is general information rather than legal advice, and the rules differ by country.
What is the best free tool to see competitor ads?
The platforms' own libraries, and they cost nothing. The Meta Ad Library shows every ad currently running on Facebook and Instagram, searchable by page name, and adds a European Union transparency panel with targeting parameters and reach for ads delivered in the EU. The Google Ads Transparency Center covers Search, YouTube, Maps, Play and Shopping with the verified advertiser name, creative, landing URL, region and date range. The TikTok Commercial Content Library covers the EEA, the UK and Switzerland only. None of them publish spend for ordinary commercial ads, so any tool quoting a competitor's ad budget is estimating it.
Can I see how much a competitor spends on ads?
No, not for ordinary commercial ads. Meta publishes spend and reach only for political and social issue advertising, where the data is kept for seven years; commercial ads carry no spend field. TikTok's library shows reach ranges but no spend and no click-through rate, and Google's Transparency Center publishes no spend, keywords or bidding detail. Anyone selling you a competitor spend number is modelling it from reach and assumptions, so treat it as an estimate with unknown error rather than a measurement.
Is it legal to scrape a competitor's Shopify store?
It depends on where you are, whether you were logged in, and how much you take. In the United States the Ninth Circuit held in hiQ Labs v. LinkedIn, reaffirmed in April 2022, that scraping already-public data is not access without authorization under the Computer Fraud and Abuse Act, but hiQ still lost on contract because it had agreed to LinkedIn's user agreement. In January 2024 Judge Edward Chen held in Meta v. Bright Data that Meta's terms do not prohibit scraping public data while logged out, dismissing the contract claims, though a tortious interference claim survived. In the EU the Database Directive's sui generis right can block extraction of a substantial part of a database, and GDPR applies separately if personal data is involved. For a single store owner the practical answer is that scraping is unnecessary: everything useful is a browser tab.
How do I tell if a competitor's product is actually profitable?
You cannot know their margin, but ad longevity is the strongest public proxy: nobody keeps paying to run an ad that loses money, so an ad still live after many months has survived hundreds of decisions by someone watching their own numbers. As of August 2026 the longest continuously running ad on the SpotPeaks radar has been live past 1,000 days. What that proves is that the product sells profitably at their cost base and their creative quality, not at yours, so the next step is always your own breakeven arithmetic rather than an assumption.
Can I copy a competitor's ad if it is working?
You can copy the structure, not the file. The hook, the objection the ad answers, the order it presents proof in and the call to action are not protected and studying them is the point of the exercise. Downloading their video or their studio photography and running it as your own is copyright infringement; Meta and TikTok both act on DMCA complaints quickly, and a disabled ad account usually takes the store's revenue with it. Their brand name is a separate issue again, since trademark law does not care whether you copied anything if the name is confusingly similar in the same category.
Are the ad libraries complete?
No, and one of them has been officially found wanting. On 15 May 2025 the European Commission preliminarily found TikTok's ad repository in breach of the Digital Services Act because it did not provide the content of ads, who was targeted or who paid, and did not allow comprehensive search. On 5 December 2025 the Commission accepted binding commitments from TikTok to publish the full ad content including the URLs in the ad, update within a maximum of 24 hours, disclose targeting criteria with aggregated gender, age group and member state reach, and add search filters. Coverage is also uneven by region, and Google excludes advertisers who never completed verification. Treat a missing ad as missing data, not as evidence that nobody is advertising.
See who is advertising, and for how long
SpotPeaks reads the public ad libraries continuously, so you can sort competitors by how long each ad has survived instead of guessing from a screenshot. Free niche pages and calculators, no account needed.
Try SpotPeaks free →