Checklist
Shopify pre-consent checklist: what to check before Accept
On a Shopify storefront, load a clean profile and check pixels, theme embeds, apps, and cookies before Accept. Admin CMP settings still need a live visit.
In brief
On a Shopify storefront, a pre-consent check is a clean browser load with no Accept click, plus a record of pixels, cookies, and the apps that set them. Customer events, theme app embeds, and third-party apps can each fire before a choice. List first-party and third-party cookies, capture key requests, then compare Reject All and Accept All in fresh profiles. An installed CMP app still needs that live visit. Use the pre-consent audit checklist as the shared pass order.
Not legal advice
This checklist is for Shopify and DTC storefront wiring. It is not legal advice, not an official Shopify document, and not a click-path for one CMP brand. Admin labels change. Describe the capability you checked, such as customer events, theme app embeds, or app pixels. Shopify Customer Privacy settings can gate many pixels. Theme scripts and hard-coded tags still need a storefront check. A first-party shop-host cookie still needs a name, a domain, and a reason.
Short answer
Load the public HTTPS shop URL in a fresh profile. Do not click Accept. Record cookies, storage, and network requests. Then, in separate profiles, click Reject All and navigate once, and click Accept All as the baseline for expected vendors.
The pre-consent audit checklist is the hub for that pass order. This page adds the Shopify surfaces that usually explain a miss: pixels, theme embeds, and apps. Confirm the checks on the public storefront URL customers open. An installed CMP app in the admin leaves those checks undone.
Why a Shopify shop needs its own list
A Shopify shop can load tags from the customer privacy banner, app pixels, custom pixels, theme app embeds, and apps such as chat, reviews, or upsell. Those owners are different. A setting that delays app pixel callbacks can leave a theme script running.
The Customer Privacy API records consent and exposes that state. It does not itself block a script. Read the limits page, then keep this table on the live URL. The Shopify pixel testing guide covers the three consent states in more detail. This page is the merchant pass you can finish in one sitting and send to a developer.
Prep
Use a clean profile with no leftover cookies or storage. Cover the homepage and one product URL. Write down the banner name and the exact Reject label you will click. Prefer the public storefront customers hit, whether that host is a custom domain or a myshopify.com host. A password-protected preview can miss apps that load only on the published theme.
State the region you actually tested. A free US-baseline visit is a format and wiring record outside California. It does not produce an EU reject conclusion or a California GPC conclusion. Read the free versus paid guide before you extend the pack.
Checklist
Fill one row per pass. A row with no file is not done. Pass means the wire matches the choice on that URL. Fail means the wire does not. About 15 minutes is enough for the homepage and one product URL when the profiles are already clean.
| Check | Pass signal | Fail signal |
|---|---|---|
| Fresh load, no click | No ads or marketing pixels before a choice | Meta, Google Ads, TikTok, or similar pixels before Accept |
| Cookies before Accept | No marketing or analytics IDs beyond storage you can justify for that load | _ga, ads IDs, or similar identifiers already present |
| Reject All, then one navigation | Marketing stays off on the next page | The next page matches the Accept baseline |
| Accept All, new profile | Expected vendors appear after the choice | The accept visit still looks like the fresh baseline |
| Apps and embeds | Optional chat, review, and upsell scripts wait | Those apps inject trackers on the fresh load |
| Evidence | URLs, tables, and screenshots labeled by step | Banner-only screenshot |
How to run the passes
Isolation matters more than a long export. One reused profile can carry an earlier accept into the fresh row.
- Note the banner state without interacting. If you cannot find a Reject control, write that down. Do not invent a click.
- In Application, list cookies for the shop host and every third-party origin. Note the name, the domain, and the request or script that set the key. Read the first-party versus third-party guide before you drop a shop-domain cookie because the hostname matches the shop.
- In Network, capture pixel, analytics, ads, and replay requests, including cookieless pings. Separate app pixels, custom pixels, and theme scripts in your notes so the owner is clear.
- In a new profile, click Reject All, confirm the banner or preference state changed, navigate once, and recapture the same layers. The Reject All leftovers guide is the deeper pass when marketing remains.
- In a third profile, Accept and recapture. This row shows what expected vendors look like after a choice. If the reject row matches this row, reject did not change the wire.
- Screenshot the untouched banner plus the cookie and request tables. Remove query values that carry identifiers before you share the pack.
What to send a developer or agency
Tie each cookie or pixel to a request or script and a pre-Accept screenshot. Name the surface: customer events, theme app embed, or app. Send the filled table with the URL and the region you tested.
ConsentProbe can store that pack for the public shop URL. A free US-baseline visit matches a pre-consent technical record outside California. Use pricing when the next claim needs EU reject and accept, or California GPC. The report stays a technical record.
FAQ
Does the Customer Privacy API or a CMP app replace this checklist?
Only when the storefront runtime matches the banner. Walk this table and the pre-consent audit checklist on the public URL.
Can theme app embeds fire before Accept?
Yes. Include them in the fresh-load network list. Admin pixel settings can miss a script the theme injects.
Is a password-protected preview enough?
Prefer the public storefront URL customers open. A preview can omit apps that load only on the published theme.
Does a free US scan answer an EU shopper question?
An EU reject or accept claim needs the EU scenarios. Read the free versus paid guide before you extend a US-baseline file.
Are first-party Shopify cookies allowed before consent?
First-party describes the host. Analytics and ads identifiers on the shop domain still need review.
Where do custom pixels show up?
In the admin customer events list and in the storefront Network list. Confirm both. Settings alone are not the runtime record.
Related guides
Pair this table with the pre-consent audit checklist, the Customer Privacy API limits page, the pixel testing guide, and the first-party inventory.
- Pre-consent audit checklist: what to verify before Accept
- Shopify Customer Privacy API does not block scripts
- Testing Shopify Pixels Before Consent
- Pre-Consent Cookie Audit: A Storefront Checklist
- First-party vs third-party cookies before consent: what should you check?
- Reject All Still Tracking: What to Check After You Say No
- What does a free US-baseline cookie audit prove vs paid EU or California scans?
- CMP claims vs runtime evidence: how do you prove the banner actually works?
- How do you read a cookie audit report?
- ConsentProbe methodology
- Sample report
- Pricing and listed regional products
Sources
These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.
Save a US-baseline technical record
After a DIY check, run a free US-baseline audit: one browser visit outside California, with cookies, requests, and screenshots stored as evidence. That visit does not run EU reject/accept or California GPC. EU, California, and Global 2 audits can be purchased from Billing after sign-in.