Checklist
Shopify Customer Events vs Customer Privacy API: do pixels still fire before Accept?
Customer Events and Web Pixels Manager are separate from the Customer Privacy API signal. Check Fresh and Reject before you treat that signal as proof.
In brief
On Shopify, the Customer Privacy API records consent states. Customer Events and Web Pixels Manager register web pixels and custom pixels that can load on a visit. A marketing-not-allowed state does not by itself prove those pixels stayed dark before Accept or after Reject. Check hosts on Fresh, then again after Reject. A free US-baseline scan is not an EU or California legal conclusion. This page is not a Shopify pixel coding tutorial and not legal advice.
Not legal advice
This guide explains how to observe Shopify Customer Events and Web Pixels Manager surfaces relative to the Customer Privacy API consent signal and to Accept and Reject on a storefront. It is not legal advice, not a Shopify admin setup tutorial, not a Customer Events coding guide, and not a GDPR, ePrivacy, CPRA, or other compliance certificate. Confirm current Shopify docs at publish time. Admin and API names change. ConsentProbe reports are technical observations of what fired. They do not say what counsel would allow. Observation is not counsel permission.
Last updated September 29, 2026. The Customer Privacy API limits page already covers the myth that the API is a script firewall. The Shopify apps page covers app pixels that load outside theme.liquid. This page does not rewrite either one. It stays on Customer Events and Web Pixels Manager versus the Privacy API signal.
Short answer
On Shopify, the Customer Privacy API records and exposes consent states for themes and apps. Customer Events and Web Pixels Manager are where merchants and apps register web pixels and custom pixels that can load on storefront visits. Those are different surfaces.
A Privacy API state that says marketing is not allowed does not by itself prove every Customer Events pixel stayed dark before Accept or after Reject. Treat admin or banner claims as claims. Falsify them with a clean visit. Capture marketing and analytics hosts on Fresh. Repeat after Reject. Note any Customer Events or web-pixel hosts that still appear.
This page is not a Shopify pixel coding tutorial and not legal advice. A free US-baseline scan is not an EU or California legal conclusion.
Surface versus signal
Admin labels move. Confirm the current Shopify names before you quote a menu to a client. The audit question stays the same: did the host fire on Fresh, and did Reject hold.
| Surface | What it does | What a cookie audit still checks |
|---|---|---|
| Customer Privacy API | Records and exposes consent states for themes and apps | Whether runtime matches the claimed state. The API limits page owns that myth. |
| Customer Events / Web Pixels Manager | Registers web pixels and custom pixels that can load on visits | Whether those hosts fire on Fresh and on Reject |
| Theme and app embeds | Separate injection paths from the pixel manager | Covered on the Shopify checklist and the apps pixel page. One line here. |
Fresh and Reject on the storefront
These steps compare a Privacy API claim with cookies and requests. They do not click through Shopify admin as a setup tutorial, and they do not paste custom pixel code. The Shopify checklist holds the wider pass.
- Use a clean profile. Load the storefront once. Do not click Accept.
- Capture cookies and Network for marketing and analytics hosts, including any web-pixel or customer-events hosts engineering already listed.
- Screenshot the banner or privacy banner state. Label the pack Fresh.
- Open a new clean profile. Click Reject All, or the Shopify reject path the store actually shows. Navigate once more. Label the pack Reject.
- Recapture cookies and Network. Write one finding sentence per mismatch, such as a Privacy API claim that marketing is off while Fresh shows a host from a Customer Events pixel.
- Ask engineering for the Customer Events and Web Pixels Manager inventory labeled by the consent check they believe applies. Do not turn that ask into an install guide.
Which sibling page to open
Open the Customer Privacy API limits page when the claim is that the API blocks scripts. Open the Shopify apps pixel page when the source is an app pixel rather than a pixel you registered in Customer Events. Open the Shopify pre-consent checklist for the full storefront pass, and the Shopify Reject All guide or the general Reject leftovers guide when Reject fails. An EU three-state file has its own Shopify EU page.
Example of a storefront clue, not a customer capture: Fresh Network shows a web-pixel host before any banner click, while the admin copy says marketing is not allowed. After Reject and one more navigation, the same host is still there. That pair is a finding. It is not a coding fix on this page.
When matching inventory to Network gets slow
Matching a Customer Events inventory to Network rows across templates by hand takes a long time. ConsentProbe runs Fresh and Reject on the storefront URL. Each finding stays tied to a request, a cookie, or a screenshot.
Use the free US-baseline visit when you want the report format. Use paid EU or California scenarios when those regions are the claims. The free versus paid guide and the Shopify EU page draw that line. ConsentProbe does not configure Customer Events, Web Pixels Manager, or the Customer Privacy API, does not install a CMP, and does not issue a certificate. A free US-baseline scan is not an EU or California legal conclusion.
FAQ
Shopify Customer Events vs Customer Privacy API: do pixels still fire before Accept?
They can, when a web pixel or custom pixel is ungated. The Privacy API records a consent state. Customer Events registers pixels. Verify hosts on a Fresh visit before you treat the API state as proof.
Is the Customer Privacy API the same as Customer Events?
No. The API is the consent signal. Customer Events and Web Pixels Manager are the pixel registration surface. Check both, then check the storefront.
Does marketing not allowed in the Privacy API prove web pixels are off?
Not by itself. The API limits page covers the script-firewall myth. This page still wants a Fresh and Reject comparison of the hosts.
How is this different from the Shopify apps pixel page?
That page focuses on app injection versus theme.liquid. This page focuses on Customer Events and Web Pixels Manager versus the Privacy API signal. It does not rewrite that apps page.
Will this page teach custom pixel code?
No. This page is observation and a Fresh and Reject check, not a Shopify pixel coding tutorial.
Is this legal advice?
No. These are technical observations. It is not legal advice. Observation is not counsel permission. ConsentProbe does not replace counsel, and it does not install a CMP.
Limits of this page
This page tells you to treat Customer Events and Web Pixels Manager as a pixel registration surface, separate from the Customer Privacy API signal, and to falsify both with Fresh and Reject. It is not legal advice, not a Shopify pixel coding tutorial, and not a rewrite of the API limits page or the apps pixel page. Observation is not counsel permission. A free US-baseline scan is not an EU or California legal conclusion.
Related guides
Open the API limits page when someone treats the Privacy API as a firewall, the apps pixel page for app injection, the Shopify checklist for the full pass, and the Reject guides when Reject fails.
- Shopify Customer Privacy API does not block scripts
- Do Shopify apps inject pixels before Accept?
- Shopify pre-consent checklist: what to check before Accept
- How do you test a Shopify cookie banner's Reject All button?
- How to run a cookie audit before Accept
- Reject All Still Tracking: What to Check After You Say No
- Pre-consent audit checklist: what to verify before Accept
- Does Reject All stop marketing pixels?
- Shopify EU storefront: Fresh vs Reject vs Accept cookie audit
- What belongs in a cookie consent audit evidence pack?
- What does a free US-baseline cookie audit prove vs paid EU or California scans?
- CMP claims vs runtime evidence: how do you prove the banner actually works?
- Cookie audit hub: which consent test should you run first?
- ConsentProbe methodology
- Pricing and listed regional products
Sources
These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.
Save a US-baseline technical record
After a DIY check, run a free US-baseline audit: one browser visit outside California, with cookies, requests, and screenshots stored as evidence. That visit does not run EU reject/accept or California GPC. EU, California, and Global 2 audits can be purchased from Billing after sign-in.