Checklist
Does the Omnisend Shopify app keep loading after Decline?
On Store E, Decline cleared Omnisend cookies. Scripts, getSettings, and forms still loaded on every page. One US Ashburn session. Not legal advice.
In brief
On Store E, before any consent click, Omnisend cookies were already present and seven Omnisend-related requests had already fired. After Decline, omnisendSessionID, omnisendShopifyCart, and page-views were gone and were not rewritten on a homepage reload or a product page. Scripts, getSettings, and forms requests still loaded on every page. This capture did not inspect event payloads. One US session from Ashburn, Virginia, on October 7, 2026. This page is not legal advice.
Not legal advice
On Store E, a US skincare Shopify storefront with a Pandectes banner, Omnisend cookies and Omnisend-related requests were already present before any consent click. After Decline, omnisendSessionID, omnisendShopifyCart, and page-views were gone and did not return on a homepage reload or a product page. The same scripts, the getSettings call, and the forms requests still loaded on every page in that session. This capture did not read event payloads, so it does not say tracking events continued after Decline.
This page records one browser session on October 7, 2026. It is not legal advice, not an Omnisend install or email-flow guide, and not a ruling on any store. The record is cookie names and request hosts. Observation is not counsel permission. This is the fourth post in the Shopify app series. Configuration steps below come from Omnisend's support articles. We have not verified each one ourselves.
Short answer
Before any consent click, the jar already held omnisendSessionID, omnisendShopifyCart, and page-views. This log associated page-views with Omnisend. Seven Omnisend-related requests had already fired: omnisnippet1.com/platforms/shopify.js with a scriptTag source, omnisnippet1.com/inshop/launcher-v2.js, omnisnippet1.com/monitoring/monitoring.js, omnisnippet1.com/inShop/push-notifications.js, omnisnippet1.com/forms/main.js, wt.omnisendlink.com/REST/inShop/v1/getSettings, and forms.soundestlink.com/REST/forms/v1/renderedForms. omnisend-in-shop.js and api.omnisend.com were absent.
The click was the Pandectes first-layer button labeled Decline. Accept was not clicked. Within about 10 seconds the three Omnisend cookies were gone, and the same seven requests fired again. A homepage reload and a product page repeated those seven requests. The cookies were not rewritten.
On Store A, Reject All left Shopify marketing and analytics at yes, and the Klaviyo pixel kept loading, with no request to klaviyo.com/client/events after Reject. On Store B, Confirm My Choices stopped TikTok browser requests, and _ttp and ttcsid stayed. On Store C, Reject All cleared _clck and _clsk, and observed /collect POST requests continued. On Store E, Decline cleared the Omnisend cookies, and scripts, getSettings, and forms still loaded on every page.
What the October 7, 2026 session showed
The exit was Ashburn, Virginia, in the United States. The browser profile was shared, and site data could not be cleared, so earlier cookies for this host cannot be ruled out. Treat the first load as near-fresh, not a guaranteed clean first visit. There was no Accept click, no login, and no email. There is no HAR. Hosts and paths come from an automation request log. In-page JavaScript was blocked, so Shopify.customerPrivacy.currentVisitorConsent() was not read.
The first window was about 10 seconds after load, with zero consent clicks. Besides the three Omnisend cookies, the jar held _gcl_au, _scid, _scid_r, wisepops cookies, cart, localization, cart_currency, _shopify_essential, and sticky_lb_sess_id.
After Decline, the three Omnisend cookies were gone within about 10 seconds, and the seven requests fired again. A homepage reload and a product page each fired the seven requests again, and neither page rewrote the Omnisend cookies. _gcl_au, _ga, _scid, and wisepops cookies were still present. _ga and _sctr first appeared after Decline. Whether Decline wrote the Shopify Customer Privacy API was not tested.
What loaded, and what stayed
Cookie rows are names only. Request rows are hosts and paths. No request body or response body was inspected.
| Item | What the log shows |
|---|---|
| Before any click | omnisendSessionID, omnisendShopifyCart, and page-views were present. Seven Omnisend-related requests had already fired. |
| After Decline, cookies | Those three cookies were gone. They were not rewritten on a homepage reload or a product page. |
| After Decline, requests | The same seven scripts, getSettings, and forms requests loaded again within about 10 seconds, on reload, and on a product page. |
| Event payloads | Not inspected. |
| Shopify consent API | Not read. currentVisitorConsent() is untested for this Decline click. |
| omnisend-in-shop.js and api.omnisend.com | Not observed. |
Check Decline in DevTools
Use one fresh profile. On Store E the first-layer label was Decline.
- Open a fresh Incognito window and DevTools before the URL. In Network, turn on Preserve log and Disable cache.
- Load the store. Do not click the banner. Filter for omnisend, omnisnippet, and soundestlink. Note cookie names and request hosts.
- Click Decline, or the store's own first-layer reject label if the word is different. Write down the time.
- Wait about 10 seconds without navigating. Recheck Omnisend cookies and the same request hosts.
- Reload the homepage, then open a product page. Note whether Omnisend cookies return, and whether scripts, getSettings, and forms load again.
- If the console allows it, run Shopify.customerPrivacy.currentVisitorConsent() before the click and again after. This capture could not.
- Write cookies before and after, and request hosts before and after. Leave event bodies out unless you inspected them.
What the official docs say to configure
These steps come from the official docs. We have not verified each one ourselves.
In Omnisend admin, open Store settings, then Connected store. The support article's default mode is "Track visitors before they consent." The other mode named there is "Wait for consent before tracking." This capture does not know which Connected store mode Store E had selected.
Those articles say Shopify's native banner passes consent signals to Omnisend through the Customer Privacy API, and that a third-party CMP has to write that API. The documented check is Shopify.customerPrivacy.currentVisitorConsent(). This session could not run it.
The tracking-cookie article states an exception: "Started checkout and order events are not affected by this tracking-cookie setting." Those paths are invisible in this browser log and were not tested. That sentence is the vendor's. It is not a row from this capture.
An April 2023 Shopify Community thread, written in Italian, reported that Iubenda left omnisendSessionID in place. The replies included no fix. That report is about Iubenda. On this Pandectes session, Decline cleared omnisendSessionID, and the script, getSettings, and forms requests still loaded.
What the browser cannot show
Order sync and the server side of Started checkout do not appear in this request log. This session did not test them. A getSettings load after Decline is not a measurement of those server paths.
Check the browser half
Run a fresh visit and the Decline control the store shows. The cookie audit page describes that kind of labeled capture. A free US-baseline scan is not an EU or California legal conclusion. ConsentProbe records cookies and request hosts. It does not replace Omnisend admin or server logs, and it does not install a CMP.
FAQ
Does Omnisend keep loading after Decline?
On Store E, the Omnisend cookies were cleared after Decline. Scripts, getSettings, and forms requests still loaded on every page in the session.
Did tracking events continue after Decline?
This capture did not inspect event payloads. The log does not show whether tracking events continued after Decline.
Did Decline remove omnisendSessionID?
Yes on this session. It was deleted and was not rewritten on a homepage reload or a product page. omnisendShopifyCart and page-views were cleared on the same click.
What should merchants check in Omnisend?
The Connected store tracking mode, and whether the CMP writes the Shopify Customer Privacy API. These steps come from the official docs. We have not verified each one ourselves. This capture does not know which mode Store E had selected.
Is this the same as the Klaviyo, TikTok, and Clarity posts?
Same series, different app, different record. Store A is Klaviyo after Reject All. Store B is TikTok after Confirm My Choices. Store C is Clarity after Reject All. Store E is Omnisend after Decline.
Is this legal advice?
No. It is not legal advice. Observation is not counsel permission. ConsentProbe does not replace counsel, and it does not install a CMP.
Limits of this page
One US session on Store E, exit in Ashburn, Virginia, on October 7, 2026. The profile was shared, site data could not be cleared, and the first load is near-fresh. There is no HAR. Request hosts and paths come from an automation request log. Request bodies and response bodies were not inspected. Shopify consent after Decline was not read. These notes do not describe Shopify stores in general or every Pandectes setup. California-specific rules were not tested. A free US-baseline visit is not an EU reject conclusion and not a California conclusion. Started checkout and order events were not tested. Configuration steps come from the official docs and were not checked one by one here. It is not legal advice. Observation is not counsel permission. ConsentProbe does not install a CMP.
Related guides
The Klaviyo, TikTok, and Clarity posts are the earlier captures in this series.
- Klaviyo Shopify app after Reject All
- TikTok Shopify app after opt-out
- Clarity Shopify app after Reject All
- Shopify apps and pixels before Accept
- How do you test a Shopify cookie banner's Reject All button?
- Shopify pre-consent checklist
- Shopify Customer Privacy API limits
- Cookie consent testing hub
- Cookie audit
Sources
These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.
Save a US-baseline technical record
After a DIY check, run a free US-baseline audit: one browser visit outside California, with cookies, requests, and screenshots stored as evidence. That visit does not run EU reject/accept or California GPC. EU, California, and Global 2 audits can be purchased from Billing after sign-in.