The myaddress+shop@gmail.com
should be trivial to defeat by a spammer. Its a very simple string remove/replace to get back to a stock email address, or change it to impersonate another service, eg. myaddress+netflix@gmail.com
.
It's only useful for the actual service, after that, you can't rely on it.