Technical guide
Reject All Still Tracking: What to Check After You Say No
Prove whether Reject All actually blocks non-essential cookies and pixels: clean profiles, fresh versus reject versus accept, and scenario-labeled evidence for Shopify and DTC storefronts.
In brief
If Reject All still sets non-essential cookies or fires pixels, the banner UI is not enforcing consent. In a clean browser profile, click Reject All, reload or navigate once, then compare cookies and third-party requests to a fresh visit and to Accept All. Marketing, ads, and analytics should stay off after reject; if the network looks like Accept, the CMP is not wired to the tags. Keep screenshots and request lists labeled by scenario as evidence.
Hard boundary
This page is a technical checklist for storefront wiring. It is not a CMP vendor comparison, not legal advice, and not a fine estimate. Locale and timezone do not replace a real EU visit path when you claim an EU result. A free US-baseline audit is one technical record outside California. It does not produce EU reject conclusions.
The failure mode: banner is not a block
A Reject All control can sit on the page while tags still load through a tag manager, hard-coded scripts, theme embeds, or server Set-Cookie. Equal non-essential traffic after Reject and after Accept is a technical observation that the choice did not change the wire.
Frame that observation carefully. Matching hostnames alone do not prove every request is marketing, and they do not establish a compliance verdict. They do tell engineering which domains to inspect next.
Prep
Use a fresh browser profile or true isolation. Skip tracker extensions. Open the public HTTPS storefront URL only. Note the exact reject control label: Reject All, Decline, Essential only, or the local equivalent.
Claim EU results only with an EU-context visit. ConsentProbe lists paid EU fresh, reject-all, and accept-all scenarios on pricing. The free path remains a US-baseline visit for report format, not GDPR reject proof.
DIY proof in four isolated runs
Keep the URL and wait time stable. Change only the consent action. Label every screenshot and export by scenario.
- A — Fresh, no click: inventory cookies and third-party requests before any banner interaction.
- B — Reject All: in a new profile, click reject, confirm an observable preference or banner-state change, then reload or navigate once and recapture Application plus Network.
- C — Accept All: in another new profile, accept and inventory post-consent vendors.
- D — Diff: list domains and cookies present after Reject that also appear after Accept, or that are clearly analytics or ads.
What good looks like on the wire
Use the table as an observable checklist. Strictly necessary cookies may remain after reject. Cookieless or redacted pings still count as network evidence and need their own column.
| State | Expect | Red flag |
|---|---|---|
| After Reject All | Non-essential cookies and pixels absent | _ga, Meta or TikTok pixels, or ad IDs still set |
| After Reject + navigation | Block holds on the next page | Tags reappear on product, cart, or checkout |
| After Accept All | Chosen vendors appear as the inventory baseline | Use only to compare against Reject, not as a verdict |
Evidence pack
Every claim should cite a cookie name and domain, a request URL, a timestamp, and a screenshot of the reject control plus Network. Sanitize query values and secrets before sharing.
ConsentProbe maps findings to request, cookie, and screenshot IDs after a saved run. The sample report shows that layout. Soft path: when you need the same check as an evidence-linked EU reject scenario, use the regional EU product on pricing. Free US-baseline remains format only.
FAQ
Can Reject All still allow some cookies?
Strictly necessary cookies may remain. Analytics, ads, and marketing cookies should not appear after reject in opt-in setups you are testing. Record what stayed and why you classified it as necessary.
Why do pixels still fire after reject?
Common causes include tags not gated by the CMP signal, hard-coded scripts, cached consent from a reused profile, and server-side cookies. Confirm the reject action changed observable state before you escalate wiring.
Is Consent Mode enough?
No. Consent Mode signals are not proof of zero collection. Always verify Network and cookies, including cookieless or redacted pings.
What should I send engineering?
Scenario-labeled screenshots plus cookie and request lists for fresh, reject, and accept. Include timestamps and whether the reject click produced a verified preference change.
Does a US scan prove EU reject works?
No. You need an EU-context reject scenario with regional IP evidence. A free US-baseline audit does not claim EU reject conclusions.
Related guides
Pair this diagnosis with the pre-consent checklist, the GPC versus CMP claims page, and the runtime-audit versus CMP split.
- Pre-Consent Cookie Audit: A Storefront Checklist
- GPC vs CMP Claims: How to Spot a Mismatch
- What does a free US-baseline cookie audit prove vs paid EU or California scans?
- Runtime Audit vs CMP: What Each One Measures
- Testing “Reject All” on a Cookie Banner
- Consent Mode vs Raw Pixel Requests: A Storefront Checklist
- Reject All vs Accept vs GPC: A Scenario Matrix for Shopify Stores
- ConsentProbe methodology
- Sample report
- Pricing and listed regional products
Sources
These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.
保存一次美国基线技术记录
完成自行检查后,可以跑一次免费美国基线审计:在加州以外做一次浏览器访问,把 Cookie、请求和截图存成证据。这次访问不会跑欧盟拒绝/接受,也不会跑加州 GPC。欧盟、加州和 Global 2 可在登录后的账单页购买。