Technical guide

Consent Mode vs Raw Pixel Requests: A Storefront Checklist

Compare Google Consent Mode signals with the cookies and network requests a Shopify storefront actually sends, including cookieless pings and browser-visible Conversion API limits.

In brief

Consent Mode is a tag signal. It is not a record of what the browser sent. Open a clean storefront session, leave the banner untouched, and compare cookies with Network hosts, including cookieless or redacted pings. Repeat after Reject All and Accept All. Client pixels are visible in the browser. Conversion API traffic that never hits the page is outside this checklist.

Hard boundary

A US-baseline visit is one technical record for that browser profile. It is not an EU or California regional result. A Consent Mode default or update call is not a CMP, and a CMP banner is not proof that tags waited. This checklist records observed cookies, requests, and scripts. It is not legal advice and does not assign a compliance verdict.

Treat Consent Mode as a signal, not as the wire

Google documents Consent Mode as a way for tags to adjust behavior from consent signals such as analytics_storage and ad_storage. Those signals can deny storage and still leave network traffic, including cookieless or redacted pings depending on basic or advanced setup.

A storefront review that only exports the cookie table will miss request-only pixels. A review that only reads a Consent Mode debug panel will miss third-party hosts that never honor that signal.

  • Record the banner state and any visible Consent Mode or CMP debug output.
  • Record cookies, localStorage, and sessionStorage on first load.
  • Record Network hosts, paths, and whether a request ran before any click.
  • Mark cookieless or redacted pings separately from cookie writes.

Fresh visit checklist

Start a clean profile with no extensions that inject analytics. Load the public HTTPS storefront URL only. Leave Accept, Reject, settings, and close controls untouched.

  1. Open DevTools before the first load so Network records the first document.
  2. Wait until the banner is visible or it is clear that no banner appeared.
  3. Capture Application cookies and storage for first-party and third-party origins.
  4. In Network, note google-analytics, googletagmanager, doubleclick, and other ads or analytics hosts, including pings with no matching cookie.
  5. Screenshot the banner, the cookie list, and the key requests. Label the pack as fresh.

Reject All and Accept All as paired runs

Repeat the same URL in new profiles after a verified Reject All and after Accept All. A click with no banner-state or preference-storage change is a weak consent test.

Matching hostnames after Reject and after Accept do not prove Consent Mode was ignored. A first-party CDN, a necessary endpoint, or a cookieless ping can look like a full pixel. Record what stayed, what stopped, and what you could not classify.

Client pixels versus Conversion API

A browser audit can see client pixels, theme scripts, Customer Events pixels that emit in the page, and tag-manager loads. It cannot inspect Shopify admin privacy settings, server logs, or Conversion API posts that never reach the storefront.

If a Meta or Google conversion is configured only as a server event, absence in Network is not proof the event was never sent. Presence of a browser pixel is still a storefront finding and should be timestamped against the consent action.

How to read the difference

Use Consent Mode documentation to interpret denied-storage pings. Use the Network and Application panels to decide whether a vendor still loaded. Use a saved US-baseline report when you need the same evidence layers attached to findings. Regional EU or California products are listed on pricing.

Related guides

Pair this checklist with the first-load cookie method and the CMP versus runtime-audit split.

Sources

These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.

Save a US-baseline technical record

After a DIY check, run a free US-baseline audit: one browser visit outside California, with cookies, requests, and screenshots stored as evidence. That visit does not run EU reject/accept or California GPC. EU, California, and Global 2 audits can be purchased from Billing after sign-in.

Consent Mode vs Raw Pixel Requests: A Storefront Checklist | ConsentProbe