Checklist
Does the Klaviyo Shopify app keep loading after Reject All?
After Reject All on Store A, OneTrust had marketing and analytics off, Shopify still returned marketing yes and analytics yes, and Klaviyo's pixel kept loading.
In brief
After Reject All on Store A, OneTrust had marketing and analytics off, and Shopify's Customer Privacy API still returned marketing yes, analytics yes, preferences yes, and sale of data no. The Klaviyo app pixel loaded on all three later page loads. Four other app pixels stopped. klaviyo.js reloaded each time. __kla_id was already set and kept the same value. __kla_off never appeared. One US session on October 5, 2026. This page is not legal advice.
Not legal advice
This page records one browser session on Store A, a US beauty brand on Shopify with OneTrust, after Reject All. It is not legal advice, not a Klaviyo email, flows, or onsite-script setup guide, and not a ruling on any store. The record is network rows, cookies, and storage. Observation is not counsel permission.
Last updated October 5, 2026. This is the first post in a series, one popular Shopify app at a time, from a Reject All capture and the app's official docs. The before-Accept Klaviyo page has no runtime capture.
Short answer
After Reject All on Store A, OneTrust's cookie recorded the marketing and analytics groups as off. Shopify.customerPrivacy.currentVisitorConsent() still returned marketing yes, analytics yes, and preferences yes, with sale_of_data no. Shopify's pixel manager uses that API when it decides which app pixels load. The Klaviyo app pixel loaded on all three page loads after the click. Four other app pixels that had been loading stopped.
No request to klaviyo.com/client/events appeared in the session, including after Add to Cart. One sessions POST before the click returned 403, and the console reported CORS.
The US default on this visit was opt-out. Before any click, OptanonConsent already had groups C0001:1, C0002:1, C0003:1, and C0004:1. That matches Klaviyo's published line, "Klaviyo does not automatically suppress tracking in other regions."
What the October 5, 2026 session showed
The browser was Chrome Incognito, a fresh window, with DevTools open before the first navigation. Preserve log and Disable cache were on. The exit was in the United States, Illinois. There was no Accept click, no login, and no email. Reject All in the preference center did not ask for a second confirm.
The homepage loaded at 09:13:03 UTC (17:13:03 CST). OptanonConsent was already C0001:1, C0002:1, C0003:1, C0004:1. __kla_id was already present, 88 bytes, an anonymous cid once decoded. The HAR has no Set-Cookie for it, so a script wrote it. klaviyo.js loaded from static.klaviyo.com with about 11 script chunks. a.klaviyo.com/forms/api/v3/geo-ip returned 200. One POST to a.klaviyo.com/client/sessions returned 403, and the console reported CORS.
Reject All was clicked at 09:14:37 UTC (17:14:37 CST). OptanonConsent then read C0001:1, C0002:0, C0003:0, C0004:0. Those flags are how this store's OneTrust cookie recorded marketing and analytics as off. At the same time, Shopify.customerPrivacy.currentVisitorConsent() returned marketing yes, analytics yes, preferences yes, and sale_of_data no. The Klaviyo app pixel loaded at 09:14:46, 09:15:09, and 09:15:42 UTC, on the reloaded homepage, a collection page, and a product page where Add to Cart was clicked. The pixel is Klaviyo's because its script references klaviyo.com/client/events. The same script references klaviyo.com/client/event-bulk-create. Four other app pixels stopped. klaviyo.js and the chunks downloaded again on each of those pages, and geo-ip returned 200 each time. __kla_id kept the same value. __kla_off did not appear. Add to Cart had no Klaviyo request, and the sessions POST did not appear again.
What loaded, and what stayed
The sessions row is a browser request that came back 403. It is not a delivered Klaviyo event.
| Item | What the log shows |
|---|---|
| Klaviyo app pixel | Loaded on all three page loads. The script references klaviyo.com/client/events. |
| Four other app pixels | They had been loading. They did not load after Reject. |
| klaviyo.js | Reloaded from static.klaviyo.com on every page, with about 11 script chunks. |
| geo-ip | a.klaviyo.com/forms/api/v3/geo-ip returned 200 on each load. |
| client/events | No request, including after Add to Cart. |
| Sessions POST | One pre-Reject POST to a.klaviyo.com/client/sessions returned 403. Console: CORS. It did not repeat. |
| __kla_id | Written before any click. Same value after Reject. No Set-Cookie in the HAR. |
| __kla_off | Did not appear. |
Check the Shopify value in DevTools
One fresh profile. These steps read the value Shopify is using.
- Open Incognito and DevTools before the URL. In Network, turn on Preserve log and Disable cache.
- Load the store. Do not click the banner. Note klaviyo.js, any a.klaviyo.com row, and whether __kla_id is already set.
- Open the preference center and click Reject All. Write down the time.
- In the console, run Shopify.customerPrivacy.currentVisitorConsent(). Record marketing, analytics, preferences, and sale_of_data.
- Read the CMP cookie. On OneTrust, read the groups in OptanonConsent.
- Reload, open another page, then open a product page and click Add to Cart. Filter Network for klaviyo.
- Note whether the app pixel loads again, and whether klaviyo.js loads again. Look for klaviyo.com/client/events.
- Check __kla_id and __kla_off. Write what loaded and what stayed.
What the official docs say to configure
These steps come from the official docs. We have not verified each one ourselves.
Shopify admin: Settings > Customer privacy for the banner, or for a CMP that writes the Customer Privacy API. Settings > Customer events lists the Klaviyo pixel and its privacy settings. Pixel Helper's Test action can show that a pixel is awaiting consent.
Klaviyo admin: Integrations > Shopify > Onsite tracking. Check Track behavioral events, choose Turn on, then open theme App embeds, turn the Klaviyo embed on, and Save. The account switch is Account > Settings > Email > Tracking. Preference pages do not control this cookie.
OneTrust, from Klaviyo's doc: Cookiepedia > Categorizations, set __kla_id to Targeting Cookies, Source https://static-tracking.klaviyo.com, Automatic Blocking on. After publish, the change can take up to four hours.
__kla_id is a first-party cookie the script writes, base64 JSON, with a cid while the visitor is anonymous. Documented maximum age is two years. Chrome caps it at 400 days. __kla_off=true keeps the JavaScript and turns tracking off. The docs say a CMP can block static-tracking.klaviyo.com. This capture loaded klaviyo.js from static.klaviyo.com.
Automatic suppression covers the EU, the EEA, the UK, and Switzerland. The article says, "Klaviyo does not automatically suppress tracking in other regions." On this Illinois visit the OneTrust groups were already on before a click.
Check that the CMP writes Reject into Shopify's Customer Privacy API. The banner button, on its own, is not proof. After the click, run Shopify.customerPrivacy.currentVisitorConsent() and put those four fields next to the CMP cookie.
What the browser cannot show
Order sync to Klaviyo, profile creation, and the server side of Extended ID are invisible in DevTools. This session did not test them. On Klaviyo's community thread about the app embed, Klaviyo wrote that if a person places an order on Shopify, their information will be sent to Klaviyo even if they did not consent to marketing, and they will be marked Never Subscribed. That sentence is the vendor's. It is not a row from this capture.
Check the browser half
Run Fresh and Reject for a labeled browser capture. A free US-baseline scan is not an EU or California legal conclusion. ConsentProbe records pixel rows, cookies, and requests. It does not replace Klaviyo's server logs, and it does not install a CMP.
FAQ
Does the Klaviyo Shopify app keep loading after Reject All?
On this Store A session, yes. The app pixel loaded on all three page loads after Reject. OneTrust had marketing and analytics off. Shopify still returned marketing yes and analytics yes, with sale of data no.
Did Klaviyo send events after Reject All?
No Klaviyo event request was in the log after Reject, including Add to Cart. The sessions POST was before the click and returned 403.
How do I check Shopify after I click Reject?
Run Shopify.customerPrivacy.currentVisitorConsent() and read marketing, analytics, preferences, and sale_of_data. Then read the CMP cookie. On Store A those two records disagreed.
Did Reject All remove __kla_id?
No. The cookie was written before any click and kept the same value. __kla_off did not appear.
Is this the same page as the before-Accept Klaviyo check?
That page is a before-Accept check and has no runtime capture. This page is one Reject All capture of the Klaviyo Shopify app.
Is this legal advice?
No. It is not legal advice. Observation is not counsel permission. ConsentProbe does not replace counsel, and it does not install a CMP.
Limits of this page
One US session on Store A, exit in Illinois. These notes do not describe Shopify stores in general or every OneTrust setup. California-specific rules were not tested. No Klaviyo event request was observed after Reject. Order sync and profile creation were not tested. Configuration steps come from the official docs and were not checked one by one here. It is not legal advice. Observation is not counsel permission. ConsentProbe does not install a CMP.
Related guides
The before-Accept Klaviyo page has no runtime capture.
Sources
These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.
Save a US-baseline technical record
After a DIY check, run a free US-baseline audit: one browser visit outside California, with cookies, requests, and screenshots stored as evidence. That visit does not run EU reject/accept or California GPC. EU, California, and Global 2 audits can be purchased from Billing after sign-in.