Checklist

Does the Judge.me Shopify app send behavioral data after Decline?

Start a free audit

On bouncecurl.com, tested 2026-10-09, store configuration at the time, Judge.me sent no track_bulk_events before or after Decline. Not legal advice.

In brief

On bouncecurl.com, tested 2026-10-09, store configuration at the time, Judge.me was well-behaved: no track_bulk_events and no POST to a Judge.me domain, before a choice and after Decline. It loaded review content and images with GET requests, including eight video thumbnails, four from review-videos.judgeme.com and four from s3.amazonaws.com/me.judge.review-images. mrbeast.store, tested 2026-10-09, store configuration at the time, shows the same absence of those sends. These results are for the Shopify native cookie banner, with each store's configuration as of 2026-10-09.

Not legal advice

On bouncecurl.com, tested 2026-10-09, store configuration at the time, Judge.me loaded review content and images. We did not observe a behavioral-data send. Before a choice and after Decline there was no track_bulk_events request and no POST to a Judge.me domain. mrbeast.store, tested 2026-10-09, store configuration at the time, is the supporting capture and shows the same absence of those sends. These results are for the Shopify native cookie banner, with each store's configuration as of 2026-10-09.

Well-behaved, in this page, means that pair of absences. The Decline state on bouncecurl.com is the console screenshot. A consent POST is used only to time the click. This page does not describe that POST. This page is not legal advice, not a Judge.me install guide, and not a ruling on any store. Observation is not counsel permission.

Short answer

On bouncecurl.com, tested 2026-10-09, store configuration at the time, the pass before a choice and the Decline pass each sent Judge.me content requests as GET only. track_bulk_events was absent. tracking.aws.judge.me was absent. No POST went to a Judge.me domain. The widget still loaded review text and images, including four video thumbnails from review-videos.judgeme.com and four from s3.amazonaws.com/me.judge.review-images. Those GETs are content loads.

mrbeast.store, tested 2026-10-09, store configuration at the time, showed no request to a judge.me domain and no track_bulk_events request. Judge.me static files came from cdn.shopify.com. The storage check on that store covered names starting with jdgm. This page does not say that store had no Judge.me storage. There is no screenshot at the Decline moment.

What we tested

Two Shopify stores, each with the Shopify native cookie banner: Manage preferences, Accept, and Decline. Screenshots are a Chrome Guest window. Console clocks in the screenshots read Pacific Daylight Time. Times on this page are UTC+8. The logs are Chrome net-export files. They record URLs, methods, status, and timing. They do not store request bodies. These results are for the Shopify native cookie banner, with each store's configuration as of 2026-10-09. This page does not record which region the visitor was counted in.

Primary evidence is bouncecurl.com, tested 2026-10-09, store configuration at the time. Supporting evidence is mrbeast.store, tested 2026-10-09, store configuration at the time. On 2026-10-09, shopmrbeast.com redirected to mrbeast.store. A third store is not evidence. Its banner failed to load because of the vendor's certificate chain: the server sent only the leaf certificate, openssl verification returned 21, and we did not bypass the certificate.

Before a choice

On bouncecurl.com, tested 2026-10-09, store configuration at the time, the homepage loaded at 12:03:24 UTC+8. The product page for Chia Seed Clumping Gel, which showed 17 reviews, loaded at 12:03:56 UTC+8. Sort and pagination ran from 12:04:15 to 12:04:23 UTC+8. Add to cart was 12:04:38 UTC+8. The banner stayed up.

At 12:05:26 UTC+8 the console showed marketing, analytics, preferences, and sale_of_data as empty strings, and analyticsProcessingAllowed false. In that read, the localStorage, sessionStorage, and cookie names starting with jdgm were empty lists. A second console check, matching jdgm or judge in localStorage, sessionStorage, and document.cookie, returned an empty list.

bouncecurl.com, tested 2026-10-09, store configuration at the time. Before a choice, the Shopify banner shows Manage preferences, Accept, and Decline. The Network filter for judge lists thumbnail.jpg files from video_carousel.js and widget scripts.
bouncecurl.com, tested 2026-10-09, store configuration at the time. Reviews widget on the product page during the pass before a choice.
bouncecurl.com, tested 2026-10-09, store configuration at the time. Console at 12:05:26 UTC+8, before a choice: marketing, analytics, preferences, and sale_of_data are empty strings, and analyticsProcessingAllowed is false.
bouncecurl.com, tested 2026-10-09, store configuration at the time. Before a choice, the console checks localStorage, sessionStorage, and cookies for jdgm or judge.
bouncecurl.com, tested 2026-10-09, store configuration at the time. Before a choice, the Network filter track_bulk_events shows no matching rows, and the Shopify banner is still open.

After Decline

On bouncecurl.com, tested 2026-10-09, store configuration at the time, Decline was clicked at 12:08:28 UTC+8. The netlog has a POST to /api/unstable/graphql.json at 12:08:28.484 UTC+8. This page uses that timestamp to place the click. It does not describe the POST.

The Decline state is the console screenshot at 12:08:54 UTC+8. The screenshot clock reads Thu Oct 08 2026 21:08:54 GMT-0700. marketing, analytics, and preferences are "no". sale_of_data is empty. analyticsProcessingAllowed is false. Sort and pagination ran from 12:09:16 to 12:09:26 UTC+8. Add to cart was 12:09:44 UTC+8. At 12:10:30 UTC+8 the same consent values were still on screen, and the jdgm or judge storage check was still an empty list.

bouncecurl.com, tested 2026-10-09, store configuration at the time. Before Decline, an email popup covers the hero. The Shopify banner still shows Manage preferences, Accept, and Decline. The Network filter for judge lists thumbs_01.jpg.
bouncecurl.com, tested 2026-10-09, store configuration at the time. Before Decline, the Shopify banner shows Manage preferences, Accept, and Decline. The Network filter for judge lists thumbs_01.jpg from video_carousel.js.
bouncecurl.com, tested 2026-10-09, store configuration at the time. After Decline the cookie banner is gone. Keep log still lists earlier thumbs_01.jpg and widget script rows in the judge filter.
bouncecurl.com, tested 2026-10-09, store configuration at the time. Console at 12:08:54 UTC+8 shows marketing, analytics, and preferences as no, sale_of_data empty, and analyticsProcessingAllowed false. This screenshot is the Decline proof.
bouncecurl.com, tested 2026-10-09, store configuration at the time. After Decline, the reviews widget is on the product page and the Network filter for judge lists reviews_for_widget GET requests.
bouncecurl.com, tested 2026-10-09, store configuration at the time. Console at 12:10:30 UTC+8 still shows marketing, analytics, and preferences as no, with the jdgm or judge storage check empty.
bouncecurl.com, tested 2026-10-09, store configuration at the time. After Decline, the Network filter track_bulk_events shows 0 of 1446 requests.

What Judge.me loaded

On bouncecurl.com, tested 2026-10-09, store configuration at the time, each netlog has 18 unique requests to Judge.me hosts and to the me.judge.review-images bucket on s3.amazonaws.com. Every one is a GET. Judge.me files served from cdn.shopify.com are not in that count. The inventory is cdn.judge.me four times (one carousel request plus reviews_for_widget pages 1, 2, and 3), review-images.judgeme.com six times, review-videos.judgeme.com four times (thumbnail.jpg), and s3.amazonaws.com/me.judge.review-images four times (thumbs_01.jpg under _video_thumbnails). The four s3 thumbnails are on the homepage, before Decline. None of these responses set a cookie.

On the Decline pass, at 12:08:09 UTC+8, about 19 seconds before the click, the log has the carousel request, four review-videos thumbnails, and the four s3 video thumbnails. After Decline, review-images.judgeme.com accounts for six GETs from 12:09:09 to 12:09:26 UTC+8. reviews_for_widget page 1 is 12:09:16.397 UTC+8, page 2 is 12:09:21.260 UTC+8, and page 3 is 12:09:26.395 UTC+8, with product_id=8199910162494. The carousel URL carries shop display settings, including the store homepage, shop_domain, and max_reviews. It does not carry a visitor id.

On bouncecurl.com, Judge.me JavaScript and CSS loaded from cdn.shopify.com/extensions/.../judgeme-775/assets/, including useEventTracking and useImpressionTracking. Those modules loaded. We saw no track_bulk_events, no tracking.aws.judge.me, and no non-GET request to a Judge.me host. A search of both netlogs found track_bulk_events zero times and tracking.aws.judge.me zero times. The same two strings are zero in all four netlogs from the two stores. Judge.me's web pixel did not load, so this page does not show what that pixel sends after consent.

bouncecurl.com. Judge.me hosts and the me.judge.review-images bucket in each netlog.
RequestMethodWhen on the Decline pass
cdn.judge.me carouselGETBefore Decline, 12:08:09 UTC+8. Shop display settings, no visitor id.
cdn.judge.me reviews_for_widget pages 1, 2, and 3GETAfter Decline, 12:09:16.397, 12:09:21.260, and 12:09:26.395 UTC+8.
review-videos.judgeme.com thumbnail.jpg, four filesGETBefore Decline, with the carousel.
s3.amazonaws.com/me.judge.review-images video thumbnails, four filesGETBefore Decline, on the homepage.
review-images.judgeme.com, six filesGETAfter Decline, 12:09:09 to 12:09:26 UTC+8.
track_bulk_events and any POST to a Judge.me domainNoneAbsent before a choice and after Decline.

The supporting capture

On mrbeast.store, tested 2026-10-09, store configuration at the time, the homepage loaded at 11:53:12 UTC+8 and add to cart was 11:54:54 UTC+8. At 11:55:51 UTC+8 the console showed the four consent fields as empty strings and analyticsProcessingAllowed false. Names starting with jdgm were absent from that read. The banner was still open. The product on this pass had 0 reviews. The Decline pass used a different product with 1 review, so this capture did not page through reviews.

Decline is about 11:57:32 UTC+8, taken from a POST in the netlog at 11:57:32.575 UTC+8. The click time was not written down on its own. This page does not describe that POST. Add to cart on the Decline pass was 11:59:05 UTC+8. The console screenshot is 11:59:54 UTC+8, after that add to cart: marketing, analytics, and preferences are "no", sale_of_data is empty, analyticsProcessingAllowed is false, and the three jdgm-prefix arrays are empty. There is no screenshot at the Decline moment.

On mrbeast.store, the netlog has no request to a judge.me domain in either pass. Judge.me files that did load came from cdn.shopify.com/extensions/.../judgeme-775. The capture shows no request to a judge.me domain and no track_bulk_events. It does not show where the review content was served from. The storage check searched the jdgm prefix only, so this page does not say the store had no Judge.me storage.

mrbeast.store, tested 2026-10-09, store configuration at the time. Before a choice, the Shopify banner shows Manage preferences, Accept, and Decline. The Network filter for judge lists loader.js.
mrbeast.store, tested 2026-10-09, store configuration at the time. Reviews widget during the pass before a choice. This product shows 0 reviews.
mrbeast.store, tested 2026-10-09, store configuration at the time. Console at 11:55:51 UTC+8, before a choice: four consent fields are empty strings, analyticsProcessingAllowed is false, and the jdgm-prefix storage arrays are empty. The banner is still open.
mrbeast.store, tested 2026-10-09, store configuration at the time. Before a choice, the Network filter for judge lists widget scripts and styles. The netlog has no request to a judge.me domain.
mrbeast.store, tested 2026-10-09, store configuration at the time. Reviews widget on the Decline pass. This product shows 1 review.
mrbeast.store, tested 2026-10-09, store configuration at the time. Console at 11:59:54 UTC+8, after add to cart, not at the Decline click: marketing, analytics, and preferences are no, analyticsProcessingAllowed is false, and the jdgm-prefix arrays are empty.
mrbeast.store, tested 2026-10-09, store configuration at the time. On the Decline pass, the Network filter for judge lists widget scripts. The netlog has no request to a judge.me domain.
mrbeast.store, tested 2026-10-09, store configuration at the time. On the Decline pass, the Network filter track_bulk_events shows no matching rows.

Check Decline in DevTools

This check is the method used for the captures above. It is not an official Judge.me step. On bouncecurl.com, tested 2026-10-09, store configuration at the time, the first-layer label was Decline.

  1. Open a fresh Guest or Incognito window. Open DevTools before the URL. Turn on Keep log (Preserve log in older Chrome) and Disable cache.
  2. Load the store. Do not click the banner. In Network, filter for track_bulk_events, then for judge.
  3. In the console, run Shopify.customerPrivacy.currentVisitorConsent() and Shopify.customerPrivacy.analyticsProcessingAllowed().
  4. Click Decline. Write down the time. If a POST to /api/unstable/graphql.json appears, use it only as a clock. Prove the Decline state from the console.
  5. Open a product page with reviews. Sort and page the reviews. Add the product to the cart.
  6. Filter track_bulk_events again. Then filter judge, and keep GET requests for review content separate from any POST.
  7. Search localStorage, sessionStorage, and document.cookie for jdgm and judge. If the check only covered names starting with jdgm, write that limit down.

What the official docs say to configure

Steps are from official documentation; we have not verified each one.

Review widgets load from the Judge.me app embed in the theme: Shopify admin, Online Store, Themes, Edit theme, App embeds. The widget article says the embed is required for all widgets to show correctly. Adding the review widget (accessed 2026-10-09).

Judge.me's app permissions article says the app installs a web pixel and can read customer events such as page views and cart actions. That pixel did not load in our sessions, so this page does not say what it sends. Declared consent categories are under Settings, Customer events, View customer privacy. Shopify's pixel privacy document says the app pixel loads only when the visitor has granted every category the pixel declares as required. App permissions (accessed 2026-10-09). Shopify app pixels (accessed 2026-10-09). Pixel privacy (accessed 2026-10-09).

Review request emails go to all buyers by default. To limit them to customers who accept marketing, open Judge.me admin, Settings, Review Requests, Request Scheduling, Advanced, and clear "Send review requests to customers who have opted out of Shopify marketing emails". The article says Judge.me uses Shopify data and does not manage consent directly. Review requests and Shopify marketing consent (accessed 2026-10-09).

Banner regions are under Shopify admin, Settings, Customer privacy, Cookie banner. With automatic settings, the banner shows in the UK and the EEA when the store has an active market there. Shopify's banner covers Shopify's own cookies and Pixels. Scripts an app adds on its own may need a third-party banner or custom logic. Customer privacy settings (accessed 2026-10-09).

The docs do not say which cookies or local storage the storefront widget sets, whether the widget reads the Customer Privacy API, or whether there is a switch that turns off widget tracking alone. The Judge.me privacy policy is about judge.me's own website, and it says "We do not support Do Not Track." Judge.me privacy policy (accessed 2026-10-09). This capture does not know which of those settings were selected.

Check the browser half

Run a fresh visit and the Decline control the banner shows. ConsentProbe records cookies and request hosts from that visit. It does not replace Judge.me admin, and it does not install a CMP. A free US-baseline scan is not an EU or California legal conclusion.

FAQ

Does Judge.me send behavioral data before a choice or after Decline?

On bouncecurl.com, tested 2026-10-09, store configuration at the time, no track_bulk_events request was sent and no POST went to a Judge.me domain, before a choice or after Decline. mrbeast.store, tested 2026-10-09, store configuration at the time, shows the same absence of those sends.

Did Judge.me load review content anyway?

Yes on bouncecurl.com, tested 2026-10-09, store configuration at the time. The requests were GET only: the homepage carousel, review widget pages 1 to 3, six review images, and eight video thumbnails from review-videos.judgeme.com and s3.amazonaws.com/me.judge.review-images. Those GETs are content loads.

How is the Decline state shown?

On bouncecurl.com, tested 2026-10-09, store configuration at the time, the console screenshot at 12:08:54 UTC+8 shows marketing, analytics, and preferences as "no", sale_of_data empty, and analyticsProcessingAllowed false. A POST at 12:08:28.484 UTC+8 only times the click.

What did the supporting capture show?

mrbeast.store, tested 2026-10-09, store configuration at the time, showed no request to a judge.me domain and no track_bulk_events request. The storage check covered the jdgm prefix only. There is no screenshot at the Decline moment. The console shot is 11:59:54 UTC+8, after add to cart.

Did the Judge.me web pixel load?

No Judge.me web pixel loaded in these sessions, so this page does not show what that pixel sends after consent. useEventTracking and useImpressionTracking loaded from the Shopify CDN and we saw no send from them.

What should a merchant check in the docs?

Steps are from official documentation; we have not verified each one. Check the theme app embed, the web pixel's declared categories, review-request scheduling, and the Shopify cookie banner region. The docs do not say the storefront widget reads the Customer Privacy API.

Is this legal advice?

No. This page is not legal advice. Observation is not counsel permission. ConsentProbe does not replace counsel, and it does not install a CMP.

Limits of this page

These results are for the Shopify native cookie banner, with each store's configuration as of 2026-10-09. Primary evidence is bouncecurl.com, tested 2026-10-09, store configuration at the time. Supporting evidence is mrbeast.store, tested 2026-10-09, store configuration at the time. A third store is not evidence. Visitor region was not recorded. Net-export logs do not store request bodies, so this page does not describe the consent POST. On mrbeast.store, storage was checked for the jdgm prefix only, and there is no screenshot at the Decline moment. Judge.me's web pixel did not load, so behavior after consent for that pixel was not observed. Content GETs loaded review text and images. Configuration steps come from the official docs and were not checked one by one here. These notes do not describe Shopify stores in general. It is not legal advice. Observation is not counsel permission. A free US-baseline scan is not an EU or California legal conclusion. ConsentProbe does not install a CMP.

Related guides

Klaviyo, TikTok, Clarity, Omnisend, and Attentive are the other Shopify app captures. The Reject All hub is the method page for the banner control.

Sources

These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.

Save a US-baseline technical record

After a DIY check, run a free US-baseline audit: one browser visit outside California, with cookies, requests, and screenshots stored as evidence. That visit does not run EU reject/accept or California GPC. EU, California, and Global 2 audits can be purchased from Billing after sign-in.

Judge.me Shopify App After Decline | ConsentProbe