Checklist

After Decline on Shopify's own banner, six third parties still got requests

Start a free audit

One Shopify store with Shopify's cookie banner. After Decline, consent read no. GA4, Clarity, LiveIntent and three more still got requests. Not legal advice.

In brief

One Shopify store with Shopify's own cookie banner. After Decline, Shopify's consent record read no for marketing, analytics, and preferences. Six third-party services still received 46 requests over the next 144.2 seconds. Three of them carried the same visitor ID as before Decline. Captured 2026-10-09. Not legal advice.

Not legal advice

This page records one browser session on Store H, a US consumer brand on Shopify using Shopify's own cookie banner, captured 2026-10-09 with the store's configuration at that time. It is not legal advice, not a ruling on any store or vendor, and not a statement that any request broke a law. Observation is not counsel permission.

We did not verify which region Shopify assigned to this visit. The banner was shown and Decline set Shopify's consent record to no. In the EU and UK, non-essential tracking generally needs consent before it runs. California and other US state laws are mostly built around opting out of sale, sharing and targeted advertising, and a cookie-banner Decline is not the same control as a Do Not Sell or Share link or a GPC signal. This page does not say which of these rules apply to Store H.

Short answer

Decline changed Shopify's consent record. The six scripts still sent 46 requests over the next 144.2 seconds. GA4, LiveIntent, and Omniconvert carried the same visitor ID as before Decline.

Shopify's help says the cookie banner governs Shopify's own tools and Shopify Pixels. Shopify's developer docs say an app pixel loads only when the visitor has allowed every purpose it declares. Tags outside that system have to read the consent record themselves. See the Customer Privacy API limits.

On Store H the banner showed Manage preferences, Accept, and Decline. The click in this capture was Decline. The log does not name the theme file, tag manager, or app embed that started each of the six scripts.

How we captured it

Chrome Guest window, Chrome net-export, no request bodies. A Fresh pass came first. A new window then loaded the home page, clicked Decline, opened a collection page, a product page, and added to cart. Times are seconds after Decline. The chart marks the later page loads at 35.7 seconds and 39.0 seconds.

What Shopify recorded after Decline

Shopify.customerPrivacy.currentVisitorConsent() was read twice, at about 26 seconds and about 122 seconds. Both reads showed marketing, analytics, and preferences as no. sale_of_data was an empty string. analyticsProcessingAllowed was false.

26 seconds after Decline on Store H. The console line shows marketing, analytics, and preferences as no, sale_of_data as an empty string, and analytics as false. The clock is masked.

What still sent requests

Six services received 46 requests after Decline: Clarity 20, MarketingCloudFX 12, LiveIntent 6, GA4 4, Omniconvert 2, and Digioh 2. The filled dots on the chart are those requests. Open dots are the same services before Decline.

A Fresh pass on the same store, with no banner choice, had requests from the same six: Clarity 27, MarketingCloudFX 10, LiveIntent 12, GA4 6, Digioh 5, and Omniconvert 3. The two passes visited similar pages, so treat these counts as a rough reference.

Store H timeline for six services. The axis runs from 21 seconds before Decline to 145 seconds after. Filled dots are after Decline. Open dots are before Decline. Dashed lines mark later page loads at 35.7 seconds and 39.0 seconds.
Store H after Decline. Counts are from the Decline netlog. Times are seconds after the click.
ServiceAfter DeclineEndpointFirst / lastWhat the log shows
Google Analytics 44 (1 on the Decline page, 3 on later pages)POST analytics.google.com/g/collect36.8 s / 57.8 suser_engagement, two page_view, one scroll. gcd=13l3l3l3l1l1, no gcs, npa=0, dma=0. cid and sid match the hits before Decline.
Microsoft Clarity20 (5 on the Decline page, 15 on later pages)POST k.clarity.ms, r.clarity.ms, and g.clarity.ms /collect4.7 s / 144.2 sUploads from 246 B to 140,701 B. The 140,701 B upload was on the product page load. Request bodies were not captured.
LiveIntent6 (later pages only, 2 page loads x 3)GET i.liadm.com/sync-container and rp.liadm.com/j, then 302 to rp4.liadm.com/j37.6 s / 41.0 sduid matches before Decline. pu is the page URL. se={}. us_privacy and gdpr_consent were not present.
MarketingCloudFX (WebFX)12 (3 on the Decline page, 9 on later pages)POST bc.store-h.example /visit, /session, and /event10.0 s / 90.6 s/visit 9, /session 2, /event 1. The /event was 2,490 bytes at 76.2 seconds, the add-to-cart moment. Request bodies were not captured.
Omniconvert2 (later pages)POST app.omniconvert.com/mktzsave?event=view36.7 s / 39.6 sPage view events. The uid and session match the hits before Decline. page_url was present. No consent parameter was in the URL.
Digioh2 (later pages)GET campaigns.store-h.example/…/digibox.gif?e=p36.9 s / 39.8 sPage count for the popup service. The parameters seen were an account id and a timestamp. No visitor ID was seen.

Same visitor, same ID

The four GA4 hits carried the same client ID (cid) and session ID (sid) as the hits before Decline. gcd was 13l3l3l3l1l1. gcs was absent. npa was 0. dma was 0. dl and dt were populated on all four.

Google's consent mode guide says that, by default, no consent mode values are set. Google does not publish a gcd letter table. Simo Ahava's write-up lists the letter l as a signal that has not been set with Consent Mode, and he describes those letters as internal parameters that can change. On that reading, Consent Mode was never set on these four hits. They are real events that keep the client ID. The difference from a cookieless ping is on Consent Mode ping vs a real event.

The parameter card is one page_view whose dl is a collection URL on store-h.example. The measurement ID is masked as G-XXXXXXX.

GA4 parameter card for one page_view after Decline on Store H. gcd is 13l3l3l3l1l1, gcs is not present, npa is 0, cid is masked and matches before Decline, dl is a store-h.example collection URL, and tid is masked as G-XXXXXXX.

LiveIntent and Omniconvert

The six LiveIntent requests carried the same duid as before Decline. us_privacy and gdpr_consent were absent. The LiveConnect collector parameter list includes both names.

LiveIntent's Shopify article, updated 2024-09-27, tells merchants to add a custom pixel under Customer Events. On Store H the six requests were GETs to liadm.com during the page loads. The log does not name the script tag that started them.

Omniconvert's two page-view POSTs carried the same uid and session as before Decline. page_url was present.

LiveIntent parameter card for rp.liadm.com/j after Decline on Store H. duid is masked and matches before Decline. pu is a store-h.example page URL. se is empty. us_privacy and gdpr_consent are not present.

Collectors on the store's own subdomain

bc.store-h.example is an A record to a Google Cloud IP, not a CNAME. MarketingCloudFX posted there. campaigns.store-h.example is a CNAME to customers.lightboxcdn.com. Digioh requested that host.

The script name mcfx.js contains the MarketingCloudFX name and a globalPrivacyControl check. This capture did not send GPC. That check was not tested.

A Network filter that keeps only third-party domains misses both hosts. Read the initiator and the script name, and look for requests on your own subdomain.

Store H subdomain collectors. bc.store-h.example is an A record to a Google Cloud IP, not a CNAME. campaigns.store-h.example is a CNAME to customers.lightboxcdn.com.

What did not fire

Klaviyo scripts loaded; no event request seen. After Decline there were 48 Klaviyo GETs for scripts, form config, and fonts.

Crazy Egg sent no tracking request after Decline, only 8 GETs for its script and site config. Before Decline it sent 1 request to tracking.crazyegg.com/clock.

The Bing sync (3 requests to c.bing.com and c.clarity.ms c.gif) and stats.g.doubleclick.net (1 request) appeared only on the first page load, before Decline.

Meta, TikTok, Pinterest, Snap, and Reddit sent no requests in the Decline pass or the Fresh pass.

The 46 leave out page features such as product recommendations, chat, and loyalty widgets. Shopify's own telemetry (monorail-edge, 8 POSTs, and otlp, 21 POSTs) also continued after Decline. This page does not analyze it.

Clarity, briefly

This capture did not read _clck or _clsk, and it did not run clarity('metadata'). We cannot tell whether the 20 /collect POSTs, including the 140,701 byte upload, ran in a no-consent or cookieless mode.

Microsoft's Shopify cookie page says that once the Shopify cookie banner is configured, Clarity receives a consent signal and no further action is needed at this time. The browser check is on Clarity after Reject All.

Check your own store

One new private window. These steps read the consent record and the requests that follow Decline.

  1. Open a new private window. Open DevTools before the first load. Turn on Preserve log.
  2. Load the store and click Decline, or your banner's reject control.
  3. Run Shopify.customerPrivacy.currentVisitorConsent() and write down marketing, analytics, preferences, and sale_of_data.
  4. Open two new pages.
  5. In Network, search collect, liadm, /visit, mktzsave, and digibox. Read the initiator and the script name, including requests on your own subdomain. On a GA request, compare gcd and whether cid matches before and after Decline.

What this page cannot show

The log has no request bodies, so the contents of the Clarity and MarketingCloudFX uploads were not seen. What those services did on their servers was not seen. There is no full cookie table. GPC was not tested. An Accept pass was not tested. This is one store and one session, and the store's configuration can change.

Run Fresh and Decline on your storefront

Paste the storefront URL for a labeled Fresh and Decline capture.

FAQ

Does Shopify's own banner stop GA4 after Decline?

On Store H, no. Four GA4 hits after Decline used the same client ID. gcd was 13l3l3l3l1l1 and gcs was absent. On Simo Ahava's unofficial table, the letter l means the signal was not set with Consent Mode.

Is a GA4 hit after Decline always a problem?

No. A Consent Mode cookieless ping is a different row. Check gcs and gcd, and whether the client ID is still there. Compare it with /blog/consent-mode-cookieless-ping-vs-real-event.

What is LiveIntent doing on a store?

On Store H, each of two later page loads sent three requests to liadm.com. They carried the same duid as before Decline and the page URL. LiveIntent's Shopify article tells merchants to add a custom pixel under Customer Events. These requests were GETs to liadm.com during the page loads.

Did Klaviyo track after Decline?

Klaviyo scripts loaded; no event request seen.

Is this legal advice?

No. This page is not legal advice. Observation is not counsel permission.

Related guides

The hub is the Reject All test method. The other links are the method pages and the single-app captures for Clarity and Klaviyo.

Sources

These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.

Save a US-baseline technical record

After a DIY check, run a free US-baseline audit: one browser visit outside California, with cookies, requests, and screenshots stored as evidence. That visit does not run EU reject/accept or California GPC. EU, California, and Global 2 audits can be purchased from Billing after sign-in.

After Shopify Decline, 6 Tags Still Fired | ConsentProbe