Technical guide

Reject All Still Tracking: What to Check After You Say No

Prove whether Reject All actually blocks non-essential cookies and pixels: clean profiles, fresh versus reject versus accept, and scenario-labeled evidence for Shopify and DTC storefronts.

In brief

If Reject All still sets non-essential cookies or fires pixels, the banner UI is not enforcing consent. In a clean browser profile, click Reject All, reload or navigate once, then compare cookies and third-party requests to a fresh visit and to Accept All. Marketing, ads, and analytics should stay off after reject; if the network looks like Accept, the CMP is not wired to the tags. Keep screenshots and request lists labeled by scenario as evidence.

Hard boundary

This page is a technical checklist for storefront wiring. It is not a CMP vendor comparison, not legal advice, and not a fine estimate. Locale and timezone do not replace a real EU visit path when you claim an EU result. A free US-baseline audit is one technical record outside California. It does not produce EU reject conclusions.

The failure mode: banner is not a block

A Reject All control can sit on the page while tags still load through a tag manager, hard-coded scripts, theme embeds, or server Set-Cookie. Equal non-essential traffic after Reject and after Accept is a technical observation that the choice did not change the wire.

Frame that observation carefully. Matching hostnames alone do not prove every request is marketing, and they do not establish a compliance verdict. They do tell engineering which domains to inspect next.

Prep

Use a fresh browser profile or true isolation. Skip tracker extensions. Open the public HTTPS storefront URL only. Note the exact reject control label: Reject All, Decline, Essential only, or the local equivalent.

Claim EU results only with an EU-context visit. ConsentProbe lists paid EU fresh, reject-all, and accept-all scenarios on pricing. The free path remains a US-baseline visit for report format, not GDPR reject proof.

DIY proof in four isolated runs

Keep the URL and wait time stable. Change only the consent action. Label every screenshot and export by scenario.

  1. A — Fresh, no click: inventory cookies and third-party requests before any banner interaction.
  2. B — Reject All: in a new profile, click reject, confirm an observable preference or banner-state change, then reload or navigate once and recapture Application plus Network.
  3. C — Accept All: in another new profile, accept and inventory post-consent vendors.
  4. D — Diff: list domains and cookies present after Reject that also appear after Accept, or that are clearly analytics or ads.

What good looks like on the wire

Use the table as an observable checklist. Strictly necessary cookies may remain after reject. Cookieless or redacted pings still count as network evidence and need their own column.

Observable checks after Reject All. Technical checklist, not a legal pass or fail.
StateExpectRed flag
After Reject AllNon-essential cookies and pixels absent_ga, Meta or TikTok pixels, or ad IDs still set
After Reject + navigationBlock holds on the next pageTags reappear on product, cart, or checkout
After Accept AllChosen vendors appear as the inventory baselineUse only to compare against Reject, not as a verdict

Evidence pack

Every claim should cite a cookie name and domain, a request URL, a timestamp, and a screenshot of the reject control plus Network. Sanitize query values and secrets before sharing.

ConsentProbe maps findings to request, cookie, and screenshot IDs after a saved run. The sample report shows that layout. Soft path: when you need the same check as an evidence-linked EU reject scenario, use the regional EU product on pricing. Free US-baseline remains format only.

FAQ

Can Reject All still allow some cookies?

Strictly necessary cookies may remain. Analytics, ads, and marketing cookies should not appear after reject in opt-in setups you are testing. Record what stayed and why you classified it as necessary.

Why do pixels still fire after reject?

Common causes include tags not gated by the CMP signal, hard-coded scripts, cached consent from a reused profile, and server-side cookies. Confirm the reject action changed observable state before you escalate wiring.

Is Consent Mode enough?

No. Consent Mode signals are not proof of zero collection. Always verify Network and cookies, including cookieless or redacted pings.

What should I send engineering?

Scenario-labeled screenshots plus cookie and request lists for fresh, reject, and accept. Include timestamps and whether the reject click produced a verified preference change.

Does a US scan prove EU reject works?

No. You need an EU-context reject scenario with regional IP evidence. A free US-baseline audit does not claim EU reject conclusions.

Related guides

Pair this diagnosis with the pre-consent checklist, the GPC versus CMP claims page, and the runtime-audit versus CMP split.

Sources

These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.

Save a US-baseline technical record

After a DIY check, run a free US-baseline audit: one browser visit outside California, with cookies, requests, and screenshots stored as evidence. That visit does not run EU reject/accept or California GPC. EU, California, and Global 2 audits can be purchased from Billing after sign-in.

Reject All Still Tracking: What to Check After You Say No | ConsentProbe