Checklist
Does Attentive keep running on Shopify after Reject All?
On a Shopify store with OneTrust, Attentive kept loading after Reject All and sent the same visitor ID on the next two pages. Not legal advice.
In brief
On Store G, a US cosmetics Shopify store with a OneTrust banner, that page made no new Attentive requests after Reject All in the preference center. The next two pages loaded the tag, showed the sign-up bubble, and sent six requests whose visitor ID matched __attentive_id. The Attentive cookies set before the click stayed. Most Google tags on the same pages switched to denied. Store F kept requesting attn.tv after Reject All in a rougher capture. One US session per pass. This page is not legal advice.
Not legal advice
On Store G, a US cosmetics store on Shopify with a OneTrust banner, we opened Set my cookie choices and clicked Reject All on 2026-10-08. Attentive sent nothing more on that page. On the next two pages it loaded its tag again, showed its sign-up bubble, and sent six requests to <store>-us.attn.tv carrying the visitor ID stored in the __attentive_id cookie. That cookie was written before the click and was still there, unchanged, after it. On the same pages most of the store's Google tags switched to denied, so OneTrust had recorded the Reject. Store F, a US home-goods store on OneTrust, also kept requesting attn.tv after Reject All in an earlier, rougher capture. Each pass is one US session. The setup steps below come from Attentive's official docs. We have not verified each one. This page is not legal advice.
Short answer
On Store G the click page sent 0 new attn.tv requests. The next two pages sent six requests and two CORS preflights with visitor ID prefix 8794, the same prefix as __attentive_id. The Attentive cookies set before the click stayed. The GA group field went from ,C0001,C0002,C0003,C0004, to ,C0001,, and most Google tags went from gcs=G111 to gcs=G100. Store F's 2026-10-08 no-click HAR already POSTed a PageView to events.attentivemobile.com. Its 2026-10-07 host log still requested attn.tv and events.attentivemobile.com after Reject All.
What we tested
Two Shopify stores with OneTrust banners, a US exit, one new Chrome Guest window per pass, DevTools open. No Accept, no Global Privacy Control, no login. Store G is a cosmetics store, not the skincare store in the Omnisend Decline post. Its first layer offers Set my cookie choices, Accept All, and a close X. There is no first-layer Reject All. We opened Set my cookie choices, then clicked Reject All in the preference center. Store F's first layer had Reject All.
Store G is a Chrome net-export strip log: URLs, methods, status codes, timing, and upload sizes. Bodies and cookie values are not in the log. Cookie values are from Application screenshots. The Cloudflare edge was IAD. The operator read OneTrust geolocation as US;IL and did not screenshot that row. Times below are UTC. The log clock was China Standard Time, UTC+8, so 11:42 UTC is 19:42 CST. Store F's no-click pass is a 2026-10-08 HAR from a clean profile. The Reject pass is a 2026-10-07 Playwright host log. That profile was not clean. How to test Attentive before Accept is the method page. It is not a store capture.
Store G before any click
Pass A ran from 11:33 to 11:38 UTC on 2026-10-08. The banner stayed open. Home loaded at 11:33:45 UTC, a collection page at 11:35:08 UTC, and a product page at 11:35:47 UTC. At 11:33:47 UTC the first calls were HEAD cdn.attn.tv/<store>/dtag.js (200), GET <store>-us.attn.tv/d with attn_vid (200), HEAD cdn.attn.tv/attentive/dtag.js (200), GET a client-configs file on cdn.attn.tv (200), and POST <store>-us.attn.tv/unrenderedCreative with pv=1 (204, 29-byte upload). ss_ref was ORGANIC.
Pass A recorded 39 Attentive requests: 11 to cdn.attn.tv, 10 to <store>-us.attn.tv, and 18 to creatives.attn.tv. Home did not request the creative iframe. From the collection page, creatives.attn.tv/creatives-dynamic/multiPage/index.html loaded, impression used pt=bubble, and creative-interactions used crap=BUBBLE and crat=VIEW. Later unrenderedCreative calls returned 200, with pv=2 and pv=3. Pass A did not record cookie values. That screenshot's Application panel had no cookie selected.
Store G after Reject All
Pass B used a new Guest window. A mistyped ttps:// hit Google at 11:40:44 UTC, then home at 11:41:09 UTC. ss_ref was ORGANIC again. Guest windows start empty. There is no separate empty-jar screenshot before this load. From 11:41:10.892 to 11:41:13.025 UTC, before any click, home made 7 Attentive requests, including /d with attn_vid prefix 8794 and unrenderedCreative pv=1 (POST 204, 29 bytes). creatives.attn.tv was not among them.
Set my cookie choices was around 11:41:34 UTC. The log fetched OneTrust otPcCenter.json at 11:41:35.596 UTC. Reject All was around 11:41:42 UTC. The operator read OptanonAlertBoxClosed as 2026-10-08T11:41:43Z. The screenshots do not show that cookie. Their file times are 19:43:14 CST, saved together, so they do not time the click. From the click until the next navigation the log shows 0 attn.tv requests.
Collection navigation was 11:42:18.610 UTC. Product navigation was 11:42:33.130 UTC, and that round ran from 11:42:34.349 to 11:42:39.442 UTC: unrenderedCreative pv=3 (POST 200, 29 bytes), the iframe, impression PUT 204 (131 bytes), and creative-interactions POST 200, with the same ID. After the click, Pass B recorded 30 Attentive requests: 18 to creatives.attn.tv, 8 to <store>-us.attn.tv, and 4 to cdn.attn.tv. Eight URLs carried the visitor ID, six requests and two impression OPTIONS preflights. /d did not return. events.attentivemobile.com did not appear in either Store G pass.
On those URLs, id and vid match __attentive_id (so did attn_vid on the /d call before the click), and ses matches __attentive_session_id (prefix 26dd). The log match is character for character. This page prints four characters. No Cookie header was logged on attn.tv requests. In this strip log a Cookie header shows up as a stripped-byte marker, and Google requests in the same log have that marker. Chrome recorded privacy_mode enabled on the <store>-us.attn.tv calls that carried the ID. The ID left in the URL.
| Time UTC | Request | Method and status | Visitor ID in the URL |
|---|---|---|---|
| 11:42:19.868 | a client-configs file on cdn.attn.tv | GET 200 | No |
| 11:42:20.181 | <store>-us.attn.tv/unrenderedCreative, pv=2, 29-byte upload | POST 200 | Yes, id prefix 8794 |
| 11:42:21.266 | cdn.attn.tv/<store>/dtag.js with a shop parameter | GET 200 | No |
| 11:42:24.602 to 11:42:25.210 | creatives.attn.tv iframe and assets. Source map 403 | GET 200 | No |
| 11:42:25.446 and 11:42:25.462 | impression. PUT upload 131 bytes | OPTIONS 200, PUT 204 | Yes |
| 11:42:25.451 | creative-interactions, crat=VIEW | POST 200 | Yes, vid prefix 8794 |
Cookies before and after the click
Both Application screenshots are the home page, before the next navigation, and they show the same Attentive cookies. Reject All did not delete or rewrite them then. __attentive_pv is 1 in the shot. pv=3 is only a URL parameter on the 11:42:34.669 UTC unrenderedCreative request. There is no cookie shot of pv=3. The __attentive_id expiry is 2027-11-02. Attentive's cookie article lists 390 days for that name.
| Cookie | Screenshot |
|---|---|
| __attentive_id | Prefix 8794. Expires 2027-11-02. |
| __attentive_session_id | Prefix 26dd. |
| __attentive_pv | 1 |
| __attentive_dv | 1 |
| __attentive_ss_referrer | ORGANIC |
| __attentive_cco | 1791459670862 |
| _attn_ | 450 bytes. Expires 2027-11-02. |
| __attn_eat_id | Present |
Did the Reject register?
In the same netlog, GA up.user_consent was ,C0001,C0002,C0003,C0004, at 11:41:18.155 UTC, before the click, and ,C0001, at 11:42:18.570 UTC on the collection page. Google tags were gcs=G111 before the click. From 11:42:20 UTC most were gcs=G100. A few from 11:42:34 to 11:42:35 UTC were still gcs=G111. Consent Mode versus network requests covers those parameters. This log shows OneTrust stored the Reject. Attentive's hosts, paths, and visitor ID on the next pages did not change with it. OptanonConsent values are operator notes. The screenshots do not show that row.
Store F, the second data point
This Reject capture is coarser than Store G. On 2026-10-08 at 08:59 CST (00:59 UTC), clean profile, no click, the HAR has 8 Attentive requests: HEAD cdn.attn.tv/attentive/dtag.js, GET cdn.attn.tv/<store>/dtag.js, GET cdn.attn.tv/tag/2026-latest/unified-tag.js, GET <store>-us.attn.tv/d with attn_vid, POST events.attentivemobile.com/ct-ev (200), a client-configs file, POST <store>-us.attn.tv/unrenderedCreative (204), and GET dtag.js with a shop parameter. The ct-ev body has eventType PageView, visitorId, sessionId, and locationHref. The unrenderedCreative body is {"cookies":{},"utmParams":{}} and is 29 bytes. Store G's upload was also 29 bytes. That body was not in the strip log, so the contents are not the same observation.
The Reject All pass is 2026-10-07, Playwright, hosts only. The profile had visited before, so Attentive cookies were already there. The click was first-layer Reject All. About 10 seconds later home was reloaded once. After that the log still has cdn.attn.tv (3 requests), <store>-us.attn.tv, and events.attentivemobile.com. Attentive cookies were not cleared. There are no paths, query parameters, or bodies. Same Store F, free scanners versus Reject All is the earlier note on this store. A 2026-10-08 Reject HAR was cleared after the click: 3 Google pagead2 entries, no Attentive rows. That file is not the Reject result used here.
Check your own store in two minutes
Use the reject path the banner shows. Store G needed the preference center. Store F had Reject All on the first layer.
- Open a new Incognito or Guest window. Open DevTools before the URL. Turn on Preserve log and Disable cache. Filter Network by attn.
- Load the store. Do not touch the banner. Note dtag.js, /d, and unrenderedCreative. Under Application, Cookies, copy __attentive_id.
- Use the banner's reject path: Reject All, Decline, or the preference center. Write down the time.
- Open a collection page, then a product page.
- Look for unrenderedCreative, impression, and creative-interactions. Compare id= or vid= with __attentive_id. Also filter events.attentive.
- To see whether the reject was stored, open one Google request and check gcs, or read the CMP cookie.
- Write one sentence per finding: which host, which page, which ID, before or after the click.
Where Attentive gets onto a Shopify store
These steps come from Attentive's official docs (accessed 2026-10-08). We have not verified each one ourselves.
Shopify article, updated 2026-10-01: in Attentive open Marketplace, then Shopify, then Install. Enter the store name, choose Set up integration, install the app in Shopify, return to Attentive, and click Activate Attentive Tag. On the Shopify settings page, turn Attentive Tag on and save. The article says the tag is installed automatically as part of the integration. The same article says that if the theme switch looks off and Network still shows Attentive requests, leave the switch. Look for cdn.attn.tv. Do not judge the tag from the switch alone.
Other documented paths: paste into theme.liquid and checkout Additional scripts. The Shopify tag integration article, updated 2025-08-08, says that path does not apply to Checkout Extensibility and points to the integration. GTM Custom HTML is a third path, Google Tag Manager (direct in container), updated 2025-08-11. A store can have more than one. Find each path before expecting a banner to hold the tag. What the Customer Privacy API cannot block is the limit of that Shopify signal. We do not know which path Store G or Store F used, or how OneTrust classified Attentive.
The Attentive tag article, updated 2025-08-08, says dtag.js loads attn.js, attn.js stores a visitor ID in a cookie, and the tag builds an iframe at client_domain.attn.tv/creative. The article says the server collects data about the visitor, page referrer URLs, impression data, and the user agent, and returns a sign-up unit. That is the vendor's sentence. This capture shows requests that left the browser.
Attentive cookies article, updated 2025-08-08: __attentive_id (visitor ID, 390 days), _attn_ (visitor ID plus browse and session data, 390 days), __attentive_pv (session page count, 30 minutes), __attentive_ss_referrer (30 minutes), __attentive_dv (the article says used for CCPA compliance, 2 or 24 hours), __attentive_cco (390 days), plus checkout names attntv_mstore_email and attntv_mstore_phone.
On 2026-10-08 we did not find a help-center setting that waits for the cookie banner before loading the site tag. The region setting we found is Email Tracking Consent: an email-open checkbox on the sign-up unit, for France and Italy only. It does not cover the site tag. Ask Attentive support about the account.
Check the browser half
ConsentProbe runs Fresh and Reject on a store and labels the Attentive hosts it sees. Use the Reject All still tracking checker for a free browser pass. A free US-baseline scan is not an EU or California legal conclusion. ConsentProbe does not replace Attentive support or a CMP, and it does not install a CMP.
FAQ
Does Attentive keep loading after Reject All on Shopify?
On Store G it did, starting on the next page: the tag, the sign-up bubble, and six requests with the visitor ID.
Did the Reject All click register at all?
Yes. The GA consent-group field dropped to ,C0001, and most Google tags switched to denied on the same pages.
Is the Attentive visitor ID still sent after Reject?
On Store G, yes. It was in the URL of six requests and matched the __attentive_id cookie, which Reject did not clear.
Does Attentive have a setting that waits for cookie consent?
We did not find one in Attentive's help center on 2026-10-08. The only region-based consent setting we found covers email open tracking in France and Italy. Ask Attentive support about your account.
Does this mean the store broke the law?
We do not draw that conclusion. In the US, Reject may only opt the visitor out of sale or sharing, and we do not know how the store classified Attentive.
Can I see SMS or server-side sends from the browser?
No. The browser shows requests that left the page. It does not show an SMS send or what a server stored.
Is this legal advice?
No. This page is not legal advice. Observation is not counsel permission. ConsentProbe does not replace counsel, and it does not install a CMP.
Limits of this page
Two stores, US exit, one session per pass. No Accept, no EU exit, no Global Privacy Control. Store G's log has no bodies and no cookie values. Cookie values are screenshots. Pass A recorded none. Pass B has no empty-jar shot before load. OptanonConsent and OptanonAlertBoxClosed are operator notes, not in the screenshots. The GA field is the netlog evidence that the Reject was stored. Upload sizes of 29 and 131 bytes are visible. Their contents are not. Store F's Reject data is host-level, from a profile that had already visited. The cleared 2026-10-08 HAR is not that result. We see what left the browser. We do not see what Attentive stored, or whether a text message was sent. For a US visitor, Reject All may only opt out of sale or sharing, which is narrower than an EU-style refusal. These notes do not describe Shopify stores in general. The configuration steps were not checked one by one here. It is not legal advice. Observation is not counsel permission. A free US-baseline scan is not an EU or California legal conclusion. ConsentProbe does not install a CMP.
Related guides
Klaviyo, TikTok, Clarity, and Omnisend are the other Shopify app captures.
- Omnisend after Decline
- Klaviyo after Reject All
- Clarity after Reject All
- TikTok after opt-out
- Store F scanners versus Reject All
- Shopify apps and pixels before Accept
- Shopify Reject All still tracking
- Consent Mode versus network requests
- Shopify Customer Privacy API limits
- Shopify Customer Events vs the Customer Privacy API
- Reject All still tracking checker
- Cookie audit
Sources
These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.
- Attentive: Shopify (updated 2026-10-01)
- Attentive: The Attentive tag (updated 2025-08-08)
- Attentive: Attentive cookies (updated 2025-08-08)
- Attentive: Shopify tag integration (updated 2025-08-08)
- Attentive: Google Tag Manager, direct in container (updated 2025-08-11)
- Attentive: Setting Up Email Tracking Consent
- Chrome DevTools: Inspect network activity
- Chrome DevTools: Application panel
Save a US-baseline technical record
After a DIY check, run a free US-baseline audit: one browser visit outside California, with cookies, requests, and screenshots stored as evidence. That visit does not run EU reject/accept or California GPC. EU, California, and Global 2 audits can be purchased from Billing after sign-in.