Checklist
Does Klaviyo tracking fire before Accept?
Check Klaviyo onsite cookies and hosts before Accept. A gated browser script does not prove server events stayed off. Not a Klaviyo email setup guide.
In brief
Klaviyo shows up in the browser through an onsite script and, on some setups, through server events. Check cookies, storage, and requests to klaviyo, static.klaviyo, or a.klaviyo hosts on Fresh, then again after Reject. Gating the browser script does not prove the server path stayed quiet. ConsentProbe can store Fresh and Reject packs. A free US-baseline scan is not an EU or California legal conclusion. This page is not a Klaviyo email or flows setup guide and not legal advice.
Not legal advice
This guide explains how to observe Klaviyo onsite tracking, related cookies and storage, and any server-side event path relative to Accept and Reject. It is not legal advice, not a Klaviyo email, flows, forms, or onsite script setup tutorial, and not a GDPR, ePrivacy, CPRA, or other compliance certificate. ConsentProbe reports are technical observations of what fired. They do not say what counsel would allow. Observation is not counsel permission.
Last updated September 28, 2026. The before-Accept audit owns the general first load. The Reject leftovers guide owns a Reject failure. The pre-consent checklist owns the pass order. The marketing-pixels FAQ owns the wider pixel question. The first-party versus third-party guide owns party labels. HubSpot tracking and the Shopify pre-consent checklist are sibling pages. This page stays on Klaviyo.
Short answer
Klaviyo marketing can show up in the browser through an onsite script, and some setups also send events from the server. A cookie consent audit asks whether Klaviyo cookies, storage, or network requests to klaviyo, static.klaviyo, a.klaviyo, or related hosts appeared before Accept, and whether Reject All stopped them. Server-side or backend event paths can still send when the browser script is delayed.
Treat banner text that says marketing is off as a claim. Falsify it on a clean visit. Capture Klaviyo-related hosts and cookies on Fresh. Repeat after Reject. Note any fan-out that continues after the click. Host names are examples of where a browser test can look. This page does not tell you which host to block, and it does not say which Klaviyo cookies are essential.
Server sends are harder to see from DevTools alone. Ask engineering for event logs labeled by consent state when the browser pack is clean and Klaviyo reporting still shows traffic. First-party versus third-party labeling still applies when Klaviyo cookies sit on your domain. The party-label guide owns that distinction.
Browser script and server events
Three layers get mixed when someone says Klaviyo is off because the browser script waits for Accept. Separate the onsite script from the server send. Write the finding as a Klaviyo host before Accept, or a host after Reject. Leave permission with counsel.
| Layer | What a browser test can see | What you may need engineering for |
|---|---|---|
| Klaviyo onsite script in the browser | Cookies, storage, and Network rows to klaviyo, static.klaviyo, a.klaviyo, or related hosts before Accept | Usually nothing beyond those browser rows |
| Klaviyo server or backend events | Indirect storefront clues. DevTools rarely shows the full server payload | Klaviyo or integration logs labeled by consent state and timestamp |
| CMP marketing-off claim | A screenshot of the banner or the marketing category | Matching runtime on Fresh and Reject |
Fresh and Reject on the storefront
These steps compare a claimed wait-for-Accept state with cookies and requests. They do not install Klaviyo.js, open a Klaviyo account, or build a flow. The before-Accept audit and the pre-consent checklist hold the general method. The Reject leftovers guide and the marketing-pixels FAQ hold a Reject failure.
- Use a clean profile. Load the storefront once. Do not click Accept.
- Capture cookies, storage, and Network for Klaviyo-related hosts, including klaviyo, static.klaviyo, and a.klaviyo.
- Screenshot the banner state. Label the pack Fresh.
- Open a new clean profile, or clear storage. Click Reject All. Navigate once more.
- Recapture cookies and Network. Label the pack Reject. Compare it with Fresh and, if you ran one, with an Accept control.
- Write one finding sentence per mismatch, such as a Klaviyo cookie on Fresh, or the same host after Reject.
Server logs when the browser looks clean
A quiet browser script and a quiet server path are different results. Backend hooks, checkout, or integration jobs can still send Klaviyo events when the page delayed the script.
If Fresh and Reject look clean in the browser and Klaviyo reporting still shows events, ask engineering for server sends tagged by consent state and timestamp. Each row should carry a label, Fresh or Reject or Accept, that you can line up with the browser pack.
Klaviyo's onsite tracking notes name a browser script that requests static.klaviyo. Example of a storefront clue, not a customer capture: Fresh Network shows a request to a static.klaviyo host, or an a.klaviyo host, before any banner click. The same host appears after Reject and one more navigation.
This page does not walk through a Klaviyo account, flows, or email configuration. The question to falsify is whether a server send happened on Fresh or after Reject. HubSpot tracking uses the same browser-versus-server split on its own page. The Shopify pre-consent checklist covers storefront slots. This page stays on Klaviyo.
When checking Klaviyo hosts gets slow
Checking Klaviyo hosts across templates by hand takes a long time. ConsentProbe runs Fresh and Reject on the storefront URL. Each finding stays tied to a request, a cookie, or a screenshot.
Use the free US-baseline visit when you want the report format. Use paid EU or California scenarios when those regions are the claims. The free versus paid guide draws that line. ConsentProbe does not install or configure Klaviyo tracking, email, or flows, does not install a CMP, and does not issue a certificate.
FAQ
Does Klaviyo tracking fire before Accept?
It often does when the onsite script is ungated. Verify Network and cookies on a Fresh visit, including klaviyo, static.klaviyo, and a.klaviyo hosts, before you treat the banner as proof.
Does gating the browser script stop Klaviyo server events?
Not by itself. Ask engineering for server sends labeled by consent state. A delayed browser script leaves the server path untested.
What if Reject All still shows Klaviyo hosts?
Treat it as a Reject failure. The Reject leftovers guide is the network check. Keep the evidence pack.
Will this page teach Klaviyo email or flows setup?
No. This page is a Fresh and Reject check, not a Klaviyo email, flows, or onsite script setup guide.
How does this relate to HubSpot?
The Fresh and Reject idea matches. The hosts differ. HubSpot tracking stays on its own page. This page stays on Klaviyo.
Is this legal advice?
No. These are technical observations. Observation is not counsel permission. ConsentProbe does not replace counsel, and it does not install a CMP.
Limits of this page
This page tells you how to check Klaviyo onsite cookies and hosts on Fresh, how to repeat the check after Reject, and why a gated browser script leaves server events untested. It is not legal advice, not a Klaviyo email or flows setup guide, and not a certificate. Observation is not counsel permission. ConsentProbe reports stay tied to requests, cookies, and screenshots. A free US-baseline scan is not an EU or California legal conclusion.
Related guides
Open the before-Accept audit for the general first load, the Reject leftovers guide when Reject still tracks, the pre-consent checklist for the pass order, and the marketing-pixels FAQ for the wider pixel question. The party-label guide covers first-party versus third-party names. HubSpot tracking and the Shopify pre-consent checklist are the sibling checks.
- How to run a cookie audit before Accept
- Reject All Still Tracking: What to Check After You Say No
- Pre-consent audit checklist: what to verify before Accept
- Does Reject All stop marketing pixels?
- First-party vs third-party cookies before consent: what should you check?
- Shopify pre-consent checklist: what to check before Accept
- Does HubSpot tracking fire before Accept?
- What belongs in a cookie consent audit evidence pack?
- What does a free US-baseline cookie audit prove vs paid EU or California scans?
- CMP claims vs runtime evidence: how do you prove the banner actually works?
- Cookie audit hub: which consent test should you run first?
- ConsentProbe methodology
- Pricing and listed regional products
Sources
These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.
Save a US-baseline technical record
After a DIY check, run a free US-baseline audit: one browser visit outside California, with cookies, requests, and screenshots stored as evidence. That visit does not run EU reject/accept or California GPC. EU, California, and Global 2 audits can be purchased from Billing after sign-in.