Checklist
Does the TikTok Shopify app stop after you opt out?
On Store B, after all optional categories were off and Confirm My Choices, TikTok requests stopped and the _ttp and ttcsid cookies kept the same values.
In brief
On Store B, the TikTok Shopify app sent no further browser requests after every optional category was off and Confirm My Choices, and the _ttp and ttcsid cookies stayed. Before any click it had sent Pageview and LandingPageView, with those cookies already set and Shopify consent fields empty. After the confirm, marketing, analytics, and preferences were no, and sale_of_data stayed empty. One US session on October 5, 2026. This page is not legal advice.
Not legal advice
On Store B, the TikTok Shopify app sent no further browser requests after the visitor turned every optional category off and clicked Confirm My Choices, and the _ttp and ttcsid cookies kept the same values. From the US exit in Illinois, Reject All was hidden in the banner and in the preference center. Store B is a lingerie brand on Shopify with OneTrust, and the UK is the main site. It is not legal advice, not a TikTok Ads or Events Manager setup guide, and not a ruling on any store. Observation is not counsel permission.
Last updated October 5, 2026. This is the second post in the Shopify app series. The before-Accept TikTok page has no runtime capture.
Short answer
Before any click, the TikTok Shopify app pixel loaded shopify.js from analytics.tiktok.com and sent two POSTs to analytics.tiktok.com/api/v2/shopify_pixel. The events were Pageview and LandingPageView, and both returned 200. One more POST went to an IPv6 enrich endpoint and returned 200. _ttp and both ttcsid cookies were already set. Shopify.customerPrivacy.currentVisitorConsent() returned empty strings for marketing, analytics, preferences, and sale_of_data. OneTrust groups were all on, with interactionCount=0. The landing URL carried a test ttclid we added ourselves.
The visitor opened the preference center, turned every optional category off, and clicked Confirm My Choices. marketing, analytics, and preferences then read "no". sale_of_data stayed "" (empty, not "no"). OneTrust groups C0002 to C0005 were 0. The reload, the product page, and Add to Cart sent no requests to TikTok or Pangle hosts. _ttp and both ttcsid cookies kept the same values.
On Store A, OneTrust Reject All left Shopify consent at marketing and analytics yes, and the Klaviyo pixel kept loading. On Store B, Shopify consent was written as no, the TikTok requests stopped, and the identifier cookies stayed. Those are different failure modes.
What the October 5, 2026 session showed
The browser was Chrome Incognito. DevTools was open before the first navigation, with Preserve log and Disable cache on. The exit was in the United States, Illinois. There was no Accept click, no login, and no email.
The homepage loaded at 09:27:54 UTC (17:27:54 CST). TikTok's click-id article describes ttclid as a URL parameter on an ad click. This landing URL carried a test ttclid we added ourselves. The HAR has no Set-Cookie for _ttp or ttcsid. The scripts wrote them, so the cookie evidence is the Application panel.
The pixel loaded shopify.js and sent the two shopify_pixel POSTs, plus the IPv6 enrich POST, between 09:27:57 and 09:27:58 UTC.
Confirm My Choices was about 09:30:00 UTC (about 17:30 CST). C0001 stayed 1, interactionCount moved to 1, and the OneTrust cookie recorded geolocation as US, Illinois.
After the confirm, one collection page view at 09:30:09 UTC had no TikTok traffic. The homepage reload at 09:30:47 UTC, the product page at 09:31:07 UTC, and Add to Cart at 09:31:49 UTC had zero requests to TikTok or Pangle hosts. The browser side stopped.
What loaded, and what stayed
Cookie rows below come from the Application panel. The HAR did not show a Set-Cookie for _ttp or the ttcsid cookies.
| Item | What the log shows |
|---|---|
| Reject All control | Hidden in the banner and in the preference center on this US exit. |
| Before any click | shopify.js, Pageview and LandingPageView, both 200, plus one IPv6 enrich POST, 200. |
| Shopify consent before | currentVisitorConsent() returned empty strings for marketing, analytics, preferences, and sale_of_data. |
| OneTrust before | Groups all on. interactionCount=0. |
| After Confirm My Choices | marketing, analytics, and preferences were "no". sale_of_data was "" (empty, not "no"). Groups C0002 to C0005 were 0. |
| Later pages | Reload, product page, and Add to Cart: zero TikTok or Pangle requests. The collection page view had none. |
| _ttp and ttcsid | Already set before any click. Same values afterwards. No Set-Cookie in the HAR. Read from the Application panel. |
| Server paths | Events API, Advanced Matching, and Enhanced or Maximum server sharing were not in the browser log. This session did not test them. |
Check the Shopify value in DevTools
Use one fresh profile.
- Open Incognito and DevTools before the URL. In Network, turn on Preserve log and Disable cache.
- Load the store. Do not click the banner. Note shopify.js, shopify_pixel posts, and whether _ttp and ttcsid are already set.
- Open the preference center. Turn every optional category off. Click Confirm My Choices. Write down the time.
- In the console, run Shopify.customerPrivacy.currentVisitorConsent(). Record marketing, analytics, preferences, and sale_of_data.
- Read the CMP cookie. On OneTrust, read the groups in OptanonConsent, including C0002 to C0005.
- Reload, open a product page, and click Add to Cart. Filter Network for tiktok and pangle.
- In the Application panel, check _ttp and the ttcsid cookies. A script can write them with no Set-Cookie in the HAR.
What the official docs say to configure
These steps come from the official docs. We have not verified each one ourselves.
Shopify admin: Settings > Customer privacy for the banner, or a CMP that calls the Customer Privacy API. Settings > Customer events lists the TikTok pixel. Pixel Helper can show that a pixel is awaiting consent. An app pixel follows the Customer Privacy API for the purposes it declares.
TikTok's data-sharing article lists Standard as the Pixel, Enhanced as the Pixel plus Events API and Advanced Matching, and Maximum as those plus Shopify APIs and In-App Checkout, marked beta. That article does not discuss consent. The Shopify pixel article says Advanced Matching sends a hashed email and phone.
In Events Manager the first-party cookie toggle is on by default. Third-party cookies are on by default. Turning cookies off stops new cookies. Cookies already written stay until they expire. Names are _ttp, ttcsid and ttcsid_<pixel code>, and ttclid, first-party, plus third-party cookies such as _pangle, for 13 months. The article calls them advertising cookies. Shopify is on the platform list.
The how-to article says the advertiser gets consent. When a visitor refuses, the advertiser uses a tag manager, a CMP, or TikTok's pixel consent mode to turn cookies off. Those TikTok articles do not describe automatic handling by region.
After opting out, check Shopify.customerPrivacy.currentVisitorConsent(), including sale_of_data, and check whether _ttp and ttcsid remain. Clearing cookies that are already written is a separate job from stopping new requests.
What the browser cannot show
Events API, Advanced Matching, and the server side of Enhanced and Maximum data sharing do not appear in DevTools. This session did not test them.
Check the browser half
Run a fresh visit and the opt-out the store actually offers. A free US-baseline scan is not an EU or California legal conclusion. ConsentProbe records pixel rows, cookies, and requests. It does not replace TikTok's server logs, and it does not install a CMP.
FAQ
Does the TikTok Shopify app stop after you opt out?
On this Store B session, TikTok browser requests stopped after every optional category was off and Confirm My Choices. The identifier cookies stayed. Reject All was hidden on this US exit.
Did TikTok send requests after Confirm My Choices?
On the reload, the product page, and Add to Cart, the log had zero requests to TikTok or Pangle hosts. The timeline also included one collection page view, and that view had no TikTok traffic.
What did Shopify consent return after the confirm?
Before any click, marketing, analytics, preferences, and sale_of_data were empty strings. After Confirm My Choices, marketing, analytics, and preferences were "no". sale_of_data stayed "" (empty, not "no").
Did the opt-out remove _ttp and ttcsid?
No. They kept the same values. TikTok's cookie article says cookies already written stay until they expire after cookies are turned off. Read them in the Application panel. The HAR had no Set-Cookie for them.
Is this the same page as the before-Accept TikTok check?
That page is a before-Accept check and has no runtime capture. This page is one Shopify app session after the preference center opt-out.
Is this legal advice?
No. It is not legal advice. Observation is not counsel permission. ConsentProbe does not replace counsel, and it does not install a CMP.
Limits of this page
One US session on Store B, exit in Illinois. These notes do not describe Shopify stores in general or every OneTrust setup. California-specific rules were not tested. Events API, Advanced Matching, and Enhanced or Maximum server sharing were not tested. It is not legal advice. Observation is not counsel permission. ConsentProbe does not install a CMP.
Related guides
The before-Accept TikTok page has no runtime capture.
Sources
These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.
- TikTok Help: Using cookies with TikTok Pixel
- TikTok Help: How to use cookies with TikTok Pixel
- TikTok Help: Data sharing for the TikTok app on Shopify
- TikTok Help: TikTok Pixel on Shopify
- TikTok Help: TikTok click ID
- Shopify Help Center: App pixels
- Shopify.dev: Pixel privacy
- Chrome DevTools: Inspect network activity
- Chrome DevTools: Application panel
Save a US-baseline technical record
After a DIY check, run a free US-baseline audit: one browser visit outside California, with cookies, requests, and screenshots stored as evidence. That visit does not run EU reject/accept or California GPC. EU, California, and Global 2 audits can be purchased from Billing after sign-in.