Checklist
First-party vs third-party cookies before consent: what should you check?
Audit first-party and third-party cookies before Accept on Shopify and DTC storefronts, with a DIY checklist and evidence pack that treats first-party storage as reviewable, not automatically allowed.
In brief
Before Accept, inventory both first-party and third-party cookies plus the requests that set them. First-party hostnames are not automatically allowed: analytics, ads, and replay identifiers on your own domain still need a consent story. Capture Application and Network in a clean profile, label every cookie by name, domain, and party, and keep screenshots of the untouched banner as evidence.
Hard boundary
This page is a pre-consent technical checklist. It is not a legal classification of every cookie as necessary or non-essential, and it does not issue a pass or fail legal verdict. Party labels help engineering triage; they are not a substitute for counsel.
Why both parties matter before Accept
Third-party cookies and pixels are the obvious tracking surface. First-party cookies set by your shop domain, a first-party CDN, or a CNAME-cloaked vendor can carry the same analytics or ads identifiers without leaving your hostname.
If you only export third-party rows, you miss first-party `_ga`-style keys, Meta or TikTok identifiers written on your domain, and storage that appears only after a same-site redirect. Audit both before anyone clicks Accept.
DIY checklist before Accept
Use a fresh profile. Do not click the banner. Keep the public HTTPS URL stable. Record Application and Network together so a Set-Cookie can be tied to a request.
- Open the storefront and wait for the banner or CMP surface without interacting.
- In Application, list cookies for the first-party host and every third-party origin that appears.
- In Network, note requests that set cookies or load known analytics, ads, or replay scripts.
- Label each cookie: name, domain, path, party (first or third), and whether it appeared before any Accept click.
- Screenshot the untouched banner plus the cookie and request tables. Sanitize query values and secrets.
- Optional paired run: repeat after Reject All or Accept All in new profiles when you need post-choice diffs.
What to record in the evidence pack
Reviewers should be able to answer three questions from the pack: which cookies existed before Accept, which party set them, and which request or script introduced them.
| Field | Why it matters | Common miss |
|---|---|---|
| Cookie name + domain | Identifies the key and the host that holds it | Exporting names without domains or party labels |
| Party (first vs third) | Separates shop-host storage from cross-site vendors | Treating every first-party cookie as automatically allowed |
| Setting request or script | Links the cookie to a network or tag event | Cookie list without Network context |
| Banner screenshot | Proves the visit was still pre-Accept | Clicking Accept before the inventory |
Soft CTA
ConsentProbe’s free US-baseline visit can save a pre-choice technical record for a non-California path. It does not replace an EU reject pack or a California GPC pack when those are the claims under review. See the free versus paid scope guide before you stretch a baseline report.
FAQ
Are first-party cookies automatically allowed before consent?
No. First-party only describes the host. Analytics, ads, and replay identifiers on your domain still need review against your consent design.
Should I ignore third-party cookies if the CMP looks fine?
No. Inventory third-party cookies and the requests that set them before Accept, then compare after Reject or Accept in separate profiles.
What if a vendor uses a first-party CNAME?
Treat it as first-party host storage in the inventory, then note the vendor identity from the request or script that set it. Do not drop it because the hostname matches the shop.
Does a cookie list alone prove pixels are gated?
No. Pair cookies with Network hosts and scripts. Request-only or cookieless pings can still fire before Accept.
Which ConsentProbe product matches this checklist?
Start with the pre-consent checklist mindset on a free US-baseline visit for format and wiring. Use paid EU or California products when the claim needs reject/accept or GPC scenarios.
Related guides
Read the pre-consent storefront checklist, the Reject All leftovers page, and the free versus paid scope page together so party labels stay attached to the right product.
- Pre-Consent Cookie Audit: A Storefront Checklist
- Reject All Still Tracking: What to Check After You Say No
- What does a free US-baseline cookie audit prove vs paid EU or California scans?
- Pre-consent audit checklist: what to verify before Accept
- Consent Mode vs Raw Pixel Requests: A Storefront Checklist
- Runtime Audit vs CMP: What Each One Measures
- GPC vs CMP Claims: How to Spot a Mismatch
- ConsentProbe methodology
- Sample report
- Pricing and listed regional products
Sources
These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.
Save a US-baseline technical record
After a DIY check, run a free US-baseline audit: one browser visit outside California, with cookies, requests, and screenshots stored as evidence. That visit does not run EU reject/accept or California GPC. EU, California, and Global 2 audits can be purchased from Billing after sign-in.