Checklist
After Decline on Shopify's own banner, six third parties still got requests
One Shopify store with Shopify's cookie banner. After Decline, consent read no. GA4, Clarity, LiveIntent and three more still got requests. Not legal advice.
In brief
One Shopify store with Shopify's own cookie banner. After Decline, Shopify's consent record read no for marketing, analytics, and preferences. Six third-party services still received 46 requests over the next 144.2 seconds. Three of them carried the same visitor ID as before Decline. Captured 2026-10-09. Not legal advice.
Not legal advice
This page records one browser session on Store H, a US consumer brand on Shopify using Shopify's own cookie banner, captured 2026-10-09 with the store's configuration at that time. It is not legal advice, not a ruling on any store or vendor, and not a statement that any request broke a law. Observation is not counsel permission.
We did not verify which region Shopify assigned to this visit. The banner was shown and Decline set Shopify's consent record to no. In the EU and UK, non-essential tracking generally needs consent before it runs. California and other US state laws are mostly built around opting out of sale, sharing and targeted advertising, and a cookie-banner Decline is not the same control as a Do Not Sell or Share link or a GPC signal. This page does not say which of these rules apply to Store H.
Short answer
Decline changed Shopify's consent record. The six scripts still sent 46 requests over the next 144.2 seconds. GA4, LiveIntent, and Omniconvert carried the same visitor ID as before Decline.
Shopify's help says the cookie banner governs Shopify's own tools and Shopify Pixels. Shopify's developer docs say an app pixel loads only when the visitor has allowed every purpose it declares. Tags outside that system have to read the consent record themselves. See the Customer Privacy API limits.
On Store H the banner showed Manage preferences, Accept, and Decline. The click in this capture was Decline. The log does not name the theme file, tag manager, or app embed that started each of the six scripts.
How we captured it
Chrome Guest window, Chrome net-export, no request bodies. A Fresh pass came first. A new window then loaded the home page, clicked Decline, opened a collection page, a product page, and added to cart. Times are seconds after Decline. The chart marks the later page loads at 35.7 seconds and 39.0 seconds.
What Shopify recorded after Decline
Shopify.customerPrivacy.currentVisitorConsent() was read twice, at about 26 seconds and about 122 seconds. Both reads showed marketing, analytics, and preferences as no. sale_of_data was an empty string. analyticsProcessingAllowed was false.

What still sent requests
Six services received 46 requests after Decline: Clarity 20, MarketingCloudFX 12, LiveIntent 6, GA4 4, Omniconvert 2, and Digioh 2. The filled dots on the chart are those requests. Open dots are the same services before Decline.
A Fresh pass on the same store, with no banner choice, had requests from the same six: Clarity 27, MarketingCloudFX 10, LiveIntent 12, GA4 6, Digioh 5, and Omniconvert 3. The two passes visited similar pages, so treat these counts as a rough reference.

| Service | After Decline | Endpoint | First / last | What the log shows |
|---|---|---|---|---|
| Google Analytics 4 | 4 (1 on the Decline page, 3 on later pages) | POST analytics.google.com/g/collect | 36.8 s / 57.8 s | user_engagement, two page_view, one scroll. gcd=13l3l3l3l1l1, no gcs, npa=0, dma=0. cid and sid match the hits before Decline. |
| Microsoft Clarity | 20 (5 on the Decline page, 15 on later pages) | POST k.clarity.ms, r.clarity.ms, and g.clarity.ms /collect | 4.7 s / 144.2 s | Uploads from 246 B to 140,701 B. The 140,701 B upload was on the product page load. Request bodies were not captured. |
| LiveIntent | 6 (later pages only, 2 page loads x 3) | GET i.liadm.com/sync-container and rp.liadm.com/j, then 302 to rp4.liadm.com/j | 37.6 s / 41.0 s | duid matches before Decline. pu is the page URL. se={}. us_privacy and gdpr_consent were not present. |
| MarketingCloudFX (WebFX) | 12 (3 on the Decline page, 9 on later pages) | POST bc.store-h.example /visit, /session, and /event | 10.0 s / 90.6 s | /visit 9, /session 2, /event 1. The /event was 2,490 bytes at 76.2 seconds, the add-to-cart moment. Request bodies were not captured. |
| Omniconvert | 2 (later pages) | POST app.omniconvert.com/mktzsave?event=view | 36.7 s / 39.6 s | Page view events. The uid and session match the hits before Decline. page_url was present. No consent parameter was in the URL. |
| Digioh | 2 (later pages) | GET campaigns.store-h.example/…/digibox.gif?e=p | 36.9 s / 39.8 s | Page count for the popup service. The parameters seen were an account id and a timestamp. No visitor ID was seen. |
Same visitor, same ID
The four GA4 hits carried the same client ID (cid) and session ID (sid) as the hits before Decline. gcd was 13l3l3l3l1l1. gcs was absent. npa was 0. dma was 0. dl and dt were populated on all four.
Google's consent mode guide says that, by default, no consent mode values are set. Google does not publish a gcd letter table. Simo Ahava's write-up lists the letter l as a signal that has not been set with Consent Mode, and he describes those letters as internal parameters that can change. On that reading, Consent Mode was never set on these four hits. They are real events that keep the client ID. The difference from a cookieless ping is on Consent Mode ping vs a real event.
The parameter card is one page_view whose dl is a collection URL on store-h.example. The measurement ID is masked as G-XXXXXXX.

LiveIntent and Omniconvert
The six LiveIntent requests carried the same duid as before Decline. us_privacy and gdpr_consent were absent. The LiveConnect collector parameter list includes both names.
LiveIntent's Shopify article, updated 2024-09-27, tells merchants to add a custom pixel under Customer Events. On Store H the six requests were GETs to liadm.com during the page loads. The log does not name the script tag that started them.
Omniconvert's two page-view POSTs carried the same uid and session as before Decline. page_url was present.

Collectors on the store's own subdomain
bc.store-h.example is an A record to a Google Cloud IP, not a CNAME. MarketingCloudFX posted there. campaigns.store-h.example is a CNAME to customers.lightboxcdn.com. Digioh requested that host.
The script name mcfx.js contains the MarketingCloudFX name and a globalPrivacyControl check. This capture did not send GPC. That check was not tested.
A Network filter that keeps only third-party domains misses both hosts. Read the initiator and the script name, and look for requests on your own subdomain.

What did not fire
Klaviyo scripts loaded; no event request seen. After Decline there were 48 Klaviyo GETs for scripts, form config, and fonts.
Crazy Egg sent no tracking request after Decline, only 8 GETs for its script and site config. Before Decline it sent 1 request to tracking.crazyegg.com/clock.
The Bing sync (3 requests to c.bing.com and c.clarity.ms c.gif) and stats.g.doubleclick.net (1 request) appeared only on the first page load, before Decline.
Meta, TikTok, Pinterest, Snap, and Reddit sent no requests in the Decline pass or the Fresh pass.
The 46 leave out page features such as product recommendations, chat, and loyalty widgets. Shopify's own telemetry (monorail-edge, 8 POSTs, and otlp, 21 POSTs) also continued after Decline. This page does not analyze it.
Clarity, briefly
This capture did not read _clck or _clsk, and it did not run clarity('metadata'). We cannot tell whether the 20 /collect POSTs, including the 140,701 byte upload, ran in a no-consent or cookieless mode.
Microsoft's Shopify cookie page says that once the Shopify cookie banner is configured, Clarity receives a consent signal and no further action is needed at this time. The browser check is on Clarity after Reject All.
Check your own store
One new private window. These steps read the consent record and the requests that follow Decline.
- Open a new private window. Open DevTools before the first load. Turn on Preserve log.
- Load the store and click Decline, or your banner's reject control.
- Run Shopify.customerPrivacy.currentVisitorConsent() and write down marketing, analytics, preferences, and sale_of_data.
- Open two new pages.
- In Network, search collect, liadm, /visit, mktzsave, and digibox. Read the initiator and the script name, including requests on your own subdomain. On a GA request, compare gcd and whether cid matches before and after Decline.
What this page cannot show
The log has no request bodies, so the contents of the Clarity and MarketingCloudFX uploads were not seen. What those services did on their servers was not seen. There is no full cookie table. GPC was not tested. An Accept pass was not tested. This is one store and one session, and the store's configuration can change.
Run Fresh and Decline on your storefront
Paste the storefront URL for a labeled Fresh and Decline capture.
FAQ
Does Shopify's own banner stop GA4 after Decline?
On Store H, no. Four GA4 hits after Decline used the same client ID. gcd was 13l3l3l3l1l1 and gcs was absent. On Simo Ahava's unofficial table, the letter l means the signal was not set with Consent Mode.
Is a GA4 hit after Decline always a problem?
No. A Consent Mode cookieless ping is a different row. Check gcs and gcd, and whether the client ID is still there. Compare it with /blog/consent-mode-cookieless-ping-vs-real-event.
What is LiveIntent doing on a store?
On Store H, each of two later page loads sent three requests to liadm.com. They carried the same duid as before Decline and the page URL. LiveIntent's Shopify article tells merchants to add a custom pixel under Customer Events. These requests were GETs to liadm.com during the page loads.
Did Klaviyo track after Decline?
Klaviyo scripts loaded; no event request seen.
Is this legal advice?
No. This page is not legal advice. Observation is not counsel permission.
Related guides
The hub is the Reject All test method. The other links are the method pages and the single-app captures for Clarity and Klaviyo.
Sources
These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.
- Shopify Help: Customer privacy settings (accessed 2026-10-10)
- Shopify.dev: Pixel privacy (accessed 2026-10-10)
- Simo Ahava: Consent Mode v2 for Google tags (accessed 2026-10-10)
- Google: Set up consent mode on websites (accessed 2026-10-10)
- LiveIntent: Shopify Checkout Extensibility upgrade (accessed 2026-10-10)
- LiveConnect: Collector parameters (accessed 2026-10-10)
- Microsoft Learn: Clarity cookie consent on Shopify (accessed 2026-10-10)
Save a US-baseline technical record
After a DIY check, run a free US-baseline audit: one browser visit outside California, with cookies, requests, and screenshots stored as evidence. That visit does not run EU reject/accept or California GPC. EU, California, and Global 2 audits can be purchased from Billing after sign-in.