Checklist
Do Shopify apps inject pixels before Accept?
Shopify app embeds and App or web pixels can fire before Accept even when theme.liquid is gated. Fresh and Reject checks. Not an app install guide.
In brief
Shopify apps can inject pixels, embeds, and web pixels on paths that do not depend on theme.liquid alone. Check app-originated cookies and hosts on Fresh, then again after Reject. A theme gate does not prove those hosts stayed quiet. ConsentProbe can store Fresh and Reject packs. A free US-baseline scan is not an EU or California legal conclusion. This page is not a Shopify app install tutorial and not legal advice.
Not legal advice
This guide explains how to observe Shopify app-originated pixels, embeds, and web pixels relative to Accept and Reject. It is not legal advice, not a Shopify app install tutorial, and not a GDPR, ePrivacy, CPRA, or other compliance certificate. ConsentProbe reports are technical observations of what fired. They do not say what counsel would allow. Observation is not counsel permission.
Last updated September 28, 2026. The Shopify pre-consent checklist owns the theme and storefront pass. The Customer Privacy API limits page owns the API boundary. The Shopify Reject All guide owns a Reject failure on Shopify. This page does not rewrite those guides. It adds the app layer: hosts that can fire when theme.liquid looks gated.
Short answer
Shopify apps can inject pixels, embeds, and web pixels through paths that do not depend on theme.liquid alone. A storefront that gates marketing tags in the theme can still show app-originated cookies, storage, or Network rows before Accept. A cookie consent audit asks whether those app-related hosts appeared on Fresh, and whether Reject All stopped them.
Treat the sentence "we blocked it in theme.liquid" as a claim about one injection path. Falsify the storefront with a clean visit. Capture marketing and analytics hosts on Fresh, including hosts you recognize from installed apps. Repeat after Reject. Note any fan-out that continues after the click. App inventories differ by store. This page does not publish a master app list.
Customer Privacy API wiring does not by itself firewall every script. The API limits page owns that boundary. Theme checklists still matter. The Shopify pre-consent checklist owns those slots. This page adds the app layer.
Theme gate and app injection
Three surfaces get mixed when a theme file looks gated and marketing hosts still appear. Separate theme scripts from app embeds, App Pixel, and web pixels. Write the finding as an app host before Accept. Leave permission with counsel.
| Surface | What a browser test can see | Common miss |
|---|---|---|
| theme.liquid and theme scripts | Hosts and cookies from theme-injected tags | Assuming the theme gate covers apps |
| App embeds, App Pixel, and web pixels | Hosts and cookies tied to installed apps, often independent of theme.liquid | Skipping the app list when the theme looks clean |
| Customer Privacy API or banner UI | A screenshot of the claim or the category state | Matching runtime on Fresh and Reject |
Fresh and Reject with apps in view
These steps compare a claimed theme gate with cookies and requests from the live storefront. They do not install an app, open a Partner dashboard, or configure a pixel. The Shopify checklist holds the theme pass. The before-Accept audit and the pre-consent checklist hold the general method.
- Use a clean profile. Load the storefront once. Do not click Accept.
- Capture cookies, storage, and Network for marketing and analytics hosts. Note hosts that match installed apps. Labels only. The inventory differs by store.
- Screenshot the banner state. Label the pack Fresh.
- Open a new clean profile, or clear storage. Click Reject All. Navigate once more.
- Recapture cookies and Network. Label the pack Reject. Compare it with Fresh and, if you ran one, with an Accept control.
- Write one finding sentence per mismatch, such as an app marketing host on Fresh, or the same host after Reject while theme tags stayed quiet.
Where the theme-only pages stop
The Shopify pre-consent checklist covers checklist slots for the storefront. This page narrows to app-originated fan-out. It does not paste that checklist.
The Customer Privacy API limits page covers the API boundary. A setting in that API is a claim until Fresh and Reject match it. This page does not paste that boundary.
The Shopify Reject All guide covers a Reject failure on Shopify. Use it when app hosts stay live after Reject. The general Reject leftovers guide and the marketing-pixels FAQ stay the wider checks. This page does not paste them.
This page does not walk through Shopify admin app install steps. The question to falsify is whether an app-originated host appeared on Fresh or after Reject. Example of a storefront clue, not a customer capture: Fresh Network shows a marketing host you recognize from an installed app, before any banner click, while the theme-injected tags stayed quiet. After Reject and one more navigation, that app host is still there. The Shopify EU Fresh, Reject, and Accept page is the regional vertical. This page stays on app-originated hosts.
When listing app hosts gets slow
Listing every app host by hand across templates takes a long time. ConsentProbe runs Fresh and Reject on the storefront URL, including hosts theme.liquid never mentioned. Each finding stays tied to a request, a cookie, or a screenshot.
Use the free US-baseline visit when you want the report format. Use paid EU or California scenarios when those regions are the claims. The free versus paid guide draws that line. ConsentProbe does not install Shopify apps or configure the Customer Privacy API, does not install a CMP, and does not issue a certificate.
FAQ
Do Shopify apps inject pixels before Accept?
They can, including through App Pixel, web pixel, and embed paths that sit outside a theme.liquid-only gate. Verify those hosts on a Fresh visit.
If theme.liquid looks gated, am I done?
No. Recheck app-originated hosts on Fresh and after Reject. A quiet theme file leaves the app layer untested.
Does the Customer Privacy API block all app scripts?
Not by itself. The API limits page is that boundary. Runtime on Fresh and Reject still decides what fired.
What if Reject All still shows app hosts?
Treat it as a Reject failure. The Shopify Reject All guide and the Reject leftovers guide are the network checks. Keep the evidence pack.
Will this page teach Shopify app install?
No. This page is a Fresh and Reject check, not a Shopify app install tutorial.
Is this legal advice?
No. These are technical observations. Observation is not counsel permission. ConsentProbe does not replace counsel, and it does not install a CMP.
Limits of this page
This page tells you how to check app-originated hosts on Fresh, how to repeat the check after Reject, and why a theme.liquid gate does not prove apps stayed quiet. It does not rewrite the Shopify pre-consent checklist, the Customer Privacy API limits page, or the Shopify Reject All guide. It is not legal advice, not a Shopify app install tutorial, and not a certificate. Observation is not counsel permission. ConsentProbe reports stay tied to requests, cookies, and screenshots. A free US-baseline scan is not an EU or California legal conclusion.
Related guides
Open the Shopify pre-consent checklist for theme slots, the Customer Privacy API limits page for the API boundary, and the Shopify Reject All guide when Reject fails on Shopify. The before-Accept audit, the Reject leftovers guide, the pre-consent checklist, and the marketing-pixels FAQ are the general bridges.
- Shopify pre-consent checklist: what to check before Accept
- Shopify Customer Privacy API does not block scripts
- How do you test a Shopify cookie banner's Reject All button?
- How to run a cookie audit before Accept
- Reject All Still Tracking: What to Check After You Say No
- Pre-consent audit checklist: what to verify before Accept
- Does Reject All stop marketing pixels?
- Shopify EU storefront: Fresh vs Reject vs Accept cookie audit
- What belongs in a cookie consent audit evidence pack?
- What does a free US-baseline cookie audit prove vs paid EU or California scans?
- CMP claims vs runtime evidence: how do you prove the banner actually works?
- Cookie audit hub: which consent test should you run first?
- ConsentProbe methodology
- Pricing and listed regional products
Sources
These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.
Save a US-baseline technical record
After a DIY check, run a free US-baseline audit: one browser visit outside California, with cookies, requests, and screenshots stored as evidence. That visit does not run EU reject/accept or California GPC. EU, California, and Global 2 audits can be purchased from Billing after sign-in.