Technical guide

Reject All vs Accept vs GPC: A Scenario Matrix for Shopify Stores

A comparison matrix for isolated Shopify storefront sessions: untouched first load, Reject All, Accept All, and California-facing Global Privacy Control.

In brief

Run four isolated Shopify sessions when the market mix requires them: untouched first load, verified Reject All, Accept All, and a California-facing GPC pair. Compare cookies, storage, and network requests with screenshots. Pre-consent means the banner is still untouched. GPC is a sale-or-share opt-out signal, not a CMP replacement. A US-baseline run is not a regional legal result.

Hard boundary

Keep every scenario in a new browser profile. A US-baseline visit does not support EU or California conclusions. GPC needs a California-facing path plus a verified Sec-GPC header and navigator.globalPrivacyControl value when you claim that region. This matrix is a technical checklist. It is not legal advice and does not declare a store lawful or approved.

Why isolation comes first

Reusing one profile carries cookies and storage into the next choice. Close extra private windows. Skip admin previews. If you claim an EU or California result, use a real regional network path. Browser locale is not that path.

Pre-consent observation is the first load before any banner click. Reject All is only useful after an observable preference or banner-state change. Accept All is the inventory baseline for this URL and browser. GPC is an extra California-facing pair, not a substitute for Reject All.

Scenario matrix

Use the table as a behavior checklist. Necessary cookies may still be set on the fresh load. Cookieless requests can still be sent. Matching hostnames across rows need a closer look at purpose and payload.

Observable checks by isolated scenario. This is a technical matrix, not a legal pass or fail.
ScenarioSetupExpect to recordReview further
Fresh, no clickClean profile, public URL, banner untouchedNecessary cookies; first-party functional storage; banner screenshotAnalytics, ads, or pixel identifiers set or sent before any choice
Reject AllNew profile; verified reject control; reload oncePreference or banner-state change; non-essential marketing staying offClick with no state change, or the same non-essential traffic as Accept
Accept AllNew profile; accept control; reload onceChosen vendors, cookies, and requests that appear only after acceptChosen tags never load: consent conditions, blockers, or a load failure
GPC on, California-facingMatched GPC-off and GPC-on sessions; verify header and JS propertySale-or-share-style advertising requests reduced versus the matched off runGPC never verified, or pixels sent before any layer can read the signal

How to run the four rows

Keep the storefront URL, wait time, and evidence fields stable. Change only the consent action or the GPC signal.

  1. Run the fresh visit and label cookies, Network, and screenshots as fresh.
  2. In a new profile, complete Reject All, confirm an observable change, then recapture.
  3. In a new profile, complete Accept All and mark post-consent inventory.
  4. If you claim California, add a GPC-off and GPC-on pair with IP evidence and verified Sec-GPC plus navigator.globalPrivacyControl.
  5. Sanitize query values and secrets before sharing the pack.

Where ConsentProbe sits

The free path is one US-baseline session with cookies, requests, CMP actions, and screenshots attached to findings. EU fresh, reject, and accept, and California baseline versus GPC, are listed on pricing. The sample report shows the evidence layout used after a saved run.

Related guides

Use the first-load checklist for the fresh row, the reject-all guide for verified clicks, and the GPC guide for the California pair.

Sources

These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.

保存一次美国基线技术记录

完成自行检查后,可以跑一次免费美国基线审计:在加州以外做一次浏览器访问,把 Cookie、请求和截图存成证据。这次访问不会跑欧盟拒绝/接受,也不会跑加州 GPC。欧盟、加州和 Global 2 可在登录后的账单页购买。

Reject All vs Accept vs GPC: A Scenario Matrix for Shopify Stores | ConsentProbe