Technical guide
Runtime Audit vs CMP: What Each One Measures
Separate the consent banner and preference layer from a browser runtime audit of cookies, requests, and scripts on a Shopify storefront.
In brief
A CMP shows the banner and stores a preference. A runtime audit records cookies, storage, network requests, scripts, and screenshots from a real browser visit. Shopify can gate app and custom pixels through Customer Privacy settings. Theme scripts and request-only pixels still need a storefront check. A US-baseline audit is not a regional result and is not legal advice.
Hard boundary
US-baseline means one non-California United States visit profile. Locale, timezone, and Shopify market settings do not replace regional IP evidence. A CMP admin export is not runtime evidence. This page describes measurement boundaries. It is not legal advice and does not name a preferred CMP.
What the CMP measures
The consent management platform is the banner, preference center, and the storage or API that records Accept, Reject, or a purpose-level choice. Shopify Customer Privacy settings can delay app and custom pixel callbacks until a recorded state allows them.
A CMP admin screen can show that a category is off. That screen does not show whether a theme script, a hardcoded pixel, or a tag manager still sent a request.
- Visible controls and whether reject is as available as accept.
- Stored preference keys or CMP cookies after a verified click.
- Documented APIs such as Shopify customerPrivacy or a vendor consent API.
- Which pixel callbacks the platform claims to gate.
What a runtime audit measures
A runtime audit opens the public storefront in a controlled browser and records what that visit actually set and sent. ConsentProbe methodology lists cookies, storage, requests, CMP actions, screenshots, and vendor detections as evidence layers.
The audit can verify that a reject control produced an observable state change. It cannot see private admin toggles, contracts, or server-to-server Conversion API traffic.
Shopify storefront boundaries
App pixels and custom pixels that honor Customer Privacy can stay quiet until the recorded consent state changes. Theme.liquid scripts, app embeds that inject tags outside that gate, and third-party chat or review widgets often sit outside that path.
Treat each installation source separately: Shopify app, Customer Events, theme code, tag manager, or embedded service. After a CMP or pixel change, rerun the same fresh, reject, and accept sessions.
How the two fit together
Use the CMP to set and store the choice. Use the runtime audit to test whether marketing and ads traffic waited, stopped, or continued, including cookieless pings. The sample report shows how findings attach to screenshots and request records. Listed regional products on pricing add EU or California scenarios when you need those visit profiles.
Related guides
The first-load checklist and the Consent Mode network checklist sit on the audit side of this split.
Sources
These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.
保存一次美国基线技术记录
完成自行检查后,可以跑一次免费美国基线审计:在加州以外做一次浏览器访问,把 Cookie、请求和截图存成证据。这次访问不会跑欧盟拒绝/接受,也不会跑加州 GPC。欧盟、加州和 Global 2 可在登录后的账单页购买。