Checklist

Does the Microsoft Clarity Shopify app stop after Reject All?

Start a free audit

After Reject All on Store C, Shopify consent was no on every field, _clck and _clsk were gone, and the browser still sent /collect POST requests.

In brief

After Reject All on Store C, Shopify consent was no on all four fields and _clck and _clsk were gone. The browser still sent /collect POST requests, 11 before reload, 12 on the reloaded home page, and 23 on a product page. clarity metadata returned a new userId and sessionId on each page view. One US session on October 5, 2026. This page is not legal advice.

Not legal advice

After Reject All on Store C, _clck and _clsk were gone, and the browser kept sending /collect POST requests.

This page records one browser session on Store C, a beauty brand on Shopify with OneTrust, on the US site, visited from a US exit in Illinois. It is not legal advice, not a Clarity install or dashboard guide, and not a ruling on any store. Observation is not counsel permission.

Last updated October 5, 2026. This is the third post in the Shopify app series. The before-Accept Clarity page has no capture of this store.

Short answer

After Reject All on the first layer of Store C's OneTrust banner, Shopify.customerPrivacy.currentVisitorConsent() returned no for analytics, preferences, marketing, and sale_of_data. _clck and _clsk were gone from document.cookie and from the Application panel. The browser still sent POST /collect, and each response was 204. The tag and clarity.js loaded again on every navigation. clarity('metadata') returned a new userId and sessionId on every page view.

Reject reached Clarity in the sense that the cookies cleared and the IDs rotated. Observed /collect POST requests still left the browser. The consent API v2 page names no-consent mode, with no cookies and a new ID per page view. The consent-mode page says /collect calls continue. The consent management page uses cookieless for that no-cookie state. This capture did not include the consentv2 call, so this page does not describe its timing or its contents. No consentStatus field was read.

Before any click, Shopify consent was analytics yes, preferences yes, marketing no, and sale_of_data no. The www.clarity.ms tag loaded about one second before consent-tracking-api.js. clarity.js loaded, _clck and _clsk were set, and seven y.clarity.ms/collect POSTs returned 204. There was no c.clarity.ms request and no c.bing.com request.

Three captures from October 5, 2026 came out differently. On Store A, Reject All left Shopify consent at yes, and the Klaviyo pixel kept loading. On Store B, the visitor turned every optional category off in the preference center and clicked Confirm My Choices. That banner hid Reject All. Shopify consent then read no, browser requests to TikTok stopped, and the _ttp and ttcsid cookies stayed. On Store C, the Clarity cookies were gone and the /collect POST requests kept going.

What the October 5, 2026 session showed

The browser was Chrome Incognito, a fresh window, with DevTools open before the first navigation. Preserve log and Disable cache were on. The exit was in the United States, Illinois. There was no Accept click, no login, and no email. The banner showed Accept Cookies, Reject All, and Manage Preferences. Reject All was clicked at about 09:36:10 UTC (17:36:10 CST).

The homepage tag request to www.clarity.ms was at 09:34:42 UTC, and consent-tracking-api.js followed about one second later. clarity.js loaded from scripts.clarity.ms. The seven /collect POSTs to y.clarity.ms returned 204 before the click.

After the click, observed /collect POST requests continued and each returned 204. There were 11 on y.clarity.ms before reload, 12 on n.clarity.ms after the home page reload at 09:37:09 UTC, and 23 on a product page at 09:38:35 UTC (1 on u.clarity.ms and 22 on j.clarity.ms).

The same pages also loaded Klaviyo and Google tags. Those rows are separate from the Clarity findings.

What loaded, and what stayed

Store C after Reject All. One US session.
ItemWhat the log shows
Shopify consent before any clickanalytics yes, preferences yes, marketing no, sale_of_data no
Shopify consent after Reject Allno for analytics, preferences, marketing, and sale_of_data
Tag timingwww.clarity.ms about one second before consent-tracking-api.js
Before the clickSeven y.clarity.ms/collect POSTs returned 204. _clck and _clsk were set. No c.clarity.ms. No c.bing.com.
Cookies after Reject All_clck and _clsk gone from document.cookie and the Application panel
POST /collect after Reject All11 before reload, 12 on the reloaded home page, 23 on a product page. Each returned 204.
Scripts on later pagesThe tag and clarity.js loaded again on every navigation
clarity metadataprojectId, userId, and sessionId only. New IDs each page view. No consentStatus field was read.

Check the browser after Reject

One fresh profile. These steps read consent, cookies, and POST /collect.

  1. Open Incognito and DevTools before the URL. In Network, turn on Preserve log and Disable cache.
  2. Load the store. Do not click the banner. Note any www.clarity.ms tag, clarity.js, _clck, _clsk, and POST /collect.
  3. Run Shopify.customerPrivacy.currentVisitorConsent() and record analytics, preferences, marketing, and sale_of_data.
  4. Click Reject All on the first layer and write down the time.
  5. Run currentVisitorConsent() again. Check document.cookie and the Application panel for _clck and _clsk.
  6. Run clarity('metadata') and write down the fields that come back. Do not assume a consentStatus field is present.
  7. Reload the home page, then open a product page. Count POST /collect, note whether the tag and clarity.js load again, and compare userId and sessionId.

What the official docs say to configure

These steps come from the official docs. We have not verified each one ourselves.

Shopify admin: Settings > Customer privacy > Cookie banner. Microsoft's third-party cookie page says Clarity auto-detects consent once the Shopify cookie banner is enabled.

For a third-party CMP, the consent API v2 page says the site can call clarity('consentv2') with ad_Storage and analytics_Storage. Microsoft's CMP table lists Cookiebot, CookieYes, Ketch, Pandectes, and Usercentrics as integrations that pass consent on their own. OneTrust is listed under Coming soon. Store C used OneTrust.

Clarity project: Settings > Setup, Consent Mode. The consent-mode page says Consent Mode is on by default only for visitors from the EEA, the UK, and Switzerland. For other visitors, that page says to turn off default cookie setting.

The cookie page lists first-party _clck and _clsk, and third-party CLID, ANONCHK, MR, MUID, and SM. It does not state an expiry. The consent-signal requirement is dated October 31, 2025, for page visits from the EEA, the UK, and Switzerland.

For US visitors, check the project's Consent Mode setting, then test with clarity('metadata') and the Network panel after Reject.

What the browser cannot show

What Clarity does on its servers with no-consent data, whether that data is tied to the earlier _clck ID, and the project's Consent Mode setting are invisible in DevTools. This session did not test them. The no-consent description above is Microsoft's documentation, not a server log from this capture.

Check the browser half

Run Fresh and Reject for a labeled browser capture. A free US-baseline scan is not an EU or California legal conclusion. ConsentProbe records pixel rows, cookies, and requests. It does not replace Clarity's server logs, and it does not install a CMP.

FAQ

Does the Microsoft Clarity Shopify app stop after Reject All?

On this Store C session, _clck and _clsk were gone, Shopify consent was no on all four fields, and the browser still sent /collect POST requests. userId and sessionId changed on every page view.

Did POST /collect continue after Reject All?

Yes. This capture shows observed /collect POST requests after the click, 11 before reload, 12 on the reloaded home page, and 23 on a product page. It does not describe what Clarity stored on the server.

Did Reject All remove _clck and _clsk?

Yes, on this session. Both names were gone from document.cookie and from the Application panel.

How do I check this on a US visit?

Check the project's Consent Mode setting. After Reject, run clarity('metadata') and watch the Network panel for POST /collect, next to _clck and _clsk. Microsoft's docs say Consent Mode is on by default for the EEA, the UK, and Switzerland.

Is this the same page as the before-Accept Clarity check?

That page is a before-Accept check for Clarity and Hotjar-class tools, with no capture of this store. This page is one Reject All capture of the Clarity Shopify app on Store C.

Is this legal advice?

No. It is not legal advice. Observation is not counsel permission. ConsentProbe does not replace counsel, and it does not install a CMP.

Limits of this page

One US session on Store C, exit in Illinois, on October 5, 2026. These notes do not describe Shopify stores in general or every OneTrust setup. California-specific rules were not tested. The consentv2 call was not captured, and no consentStatus field was read. Server-side handling, any link to the earlier _clck ID, and the project Consent Mode setting were not tested. Configuration steps come from the official docs and were not checked one by one here. It is not legal advice. Observation is not counsel permission. ConsentProbe does not install a CMP.

Related guides

The before-Accept Clarity page is the check before Accept. The Klaviyo page is Store A. The TikTok page is Store B.

Sources

These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.

Save a US-baseline technical record

After a DIY check, run a free US-baseline audit: one browser visit outside California, with cookies, requests, and screenshots stored as evidence. That visit does not run EU reject/accept or California GPC. EU, California, and Global 2 audits can be purchased from Billing after sign-in.

Clarity Shopify App After Reject All | ConsentProbe