检查清单

First-party vs third-party cookies before consent: what should you check?

开始免费审计

Audit first-party and third-party cookies before Accept on Shopify and DTC storefronts, with a DIY checklist and evidence pack that treats first-party storage as reviewable, not automatically allowed.

In brief

Before Accept, inventory both first-party and third-party cookies plus the requests that set them. First-party hostnames are not automatically allowed: analytics, ads, and replay identifiers on your own domain still need a consent story. Capture Application and Network in a clean profile, label every cookie by name, domain, and party, and keep screenshots of the untouched banner as evidence.

Hard boundary

This page is a pre-consent technical checklist. It is not a legal classification of every cookie as necessary or non-essential, and it does not issue a pass or fail legal verdict. Party labels help engineering triage; they are not a substitute for counsel.

Why both parties matter before Accept

Third-party cookies and pixels are the obvious tracking surface. First-party cookies set by your shop domain, a first-party CDN, or a CNAME-cloaked vendor can carry the same analytics or ads identifiers without leaving your hostname.

If you only export third-party rows, you miss first-party `_ga`-style keys, Meta or TikTok identifiers written on your domain, and storage that appears only after a same-site redirect. Audit both before anyone clicks Accept.

DIY checklist before Accept

Use a fresh profile. Do not click the banner. Keep the public HTTPS URL stable. Record Application and Network together so a Set-Cookie can be tied to a request.

  1. Open the storefront and wait for the banner or CMP surface without interacting.
  2. In Application, list cookies for the first-party host and every third-party origin that appears.
  3. In Network, note requests that set cookies or load known analytics, ads, or replay scripts.
  4. Label each cookie: name, domain, path, party (first or third), and whether it appeared before any Accept click.
  5. Screenshot the untouched banner plus the cookie and request tables. Sanitize query values and secrets.
  6. Optional paired run: repeat after Reject All or Accept All in new profiles when you need post-choice diffs.

What to record in the evidence pack

Reviewers should be able to answer three questions from the pack: which cookies existed before Accept, which party set them, and which request or script introduced them.

Pre-consent cookie evidence fields. Technical inventory, not a legal pass or fail.
FieldWhy it mattersCommon miss
Cookie name + domainIdentifies the key and the host that holds itExporting names without domains or party labels
Party (first vs third)Separates shop-host storage from cross-site vendorsTreating every first-party cookie as automatically allowed
Setting request or scriptLinks the cookie to a network or tag eventCookie list without Network context
Banner screenshotProves the visit was still pre-AcceptClicking Accept before the inventory

Soft CTA

ConsentProbe’s free US-baseline visit can save a pre-choice technical record for a non-California path. It does not replace an EU reject pack or a California GPC pack when those are the claims under review. See the free versus paid scope guide before you stretch a baseline report.

FAQ

Are first-party cookies automatically allowed before consent?

No. First-party only describes the host. Analytics, ads, and replay identifiers on your domain still need review against your consent design.

Should I ignore third-party cookies if the CMP looks fine?

No. Inventory third-party cookies and the requests that set them before Accept, then compare after Reject or Accept in separate profiles.

What if a vendor uses a first-party CNAME?

Treat it as first-party host storage in the inventory, then note the vendor identity from the request or script that set it. Do not drop it because the hostname matches the shop.

Does a cookie list alone prove pixels are gated?

No. Pair cookies with Network hosts and scripts. Request-only or cookieless pings can still fire before Accept.

Which ConsentProbe product matches this checklist?

Start with the pre-consent checklist mindset on a free US-baseline visit for format and wiring. Use paid EU or California products when the claim needs reject/accept or GPC scenarios.

Related guides

Read the pre-consent storefront checklist, the Reject All leftovers page, and the free versus paid scope page together so party labels stay attached to the right product.

Sources

These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.

保存一次美国基线技术记录

完成自行检查后,可以跑一次免费美国基线审计:在加州以外做一次浏览器访问,把 Cookie、请求和截图存成证据。这次访问不会跑欧盟拒绝/接受,也不会跑加州 GPC。欧盟、加州和 Global 2 可在登录后的账单页购买。

同意前的第一方与第三方 Cookie | ConsentProbe