检查清单

Shopify EU storefront: Fresh vs Reject vs Accept cookie audit

开始免费审计

Label Fresh, Reject, and Accept on a Shopify EU storefront. Compare hosts and cookies. Customer Privacy settings still need a runtime match. Not legal advice.

In brief

On a Shopify EU storefront, Fresh, Reject All, and Accept All are three separate runtime paths. Theme scripts, app pixels, and Customer Privacy gating can differ on each path. Label each visit and compare Network and cookies. Customer Privacy settings stay claims until Fresh and Reject match them. ConsentProbe can store the packs. A free US-baseline scan is not an EU or California legal conclusion. This page is the Shopify vertical of the EU scenario set and not legal advice.

Not legal advice

This guide explains how to observe Fresh, Reject, and Accept cookie and network behavior on a Shopify EU storefront. It is not legal advice, not a Shopify theme or Customer Privacy API setup tutorial, and not a GDPR, ePrivacy, CPRA, or other compliance certificate. ConsentProbe reports are technical observations of what fired. They do not say what counsel would allow. Observation is not counsel permission.

Last updated September 28, 2026. The EU fresh, reject, and accept guide owns the platform-agnostic scenario set. This page does not rewrite it. The Shopify pre-consent checklist, the Customer Privacy API limits page, and the Shopify Reject All guide stay on their own topics. This page is the Shopify vertical: three labeled visits on the live storefront URL.

Short answer

Run labeled Fresh, Reject, and Accept visits on the Shopify EU storefront URL, then compare hosts and cookies per path. Theme scripts, app pixels, Customer Privacy gating, and checkout-adjacent tags can behave differently on each path.

Shopify Customer Privacy API settings are claims until Fresh and Reject evidence match them. A cookie consent audit labels each visit, captures Network, cookies, storage, and banner state, and compares the columns.

ConsentProbe can produce labeled Fresh and Reject packs with request, cookie, and screenshot links. Add an Accept capture when you need the third column. A free US-baseline scan is not an EU or California legal conclusion. ConsentProbe does not install a CMP and does not configure Shopify Customer Privacy or app pixels. This page is not a rewrite of the EU scenario guide or the Shopify cluster pages, and not legal advice. Observation is not counsel permission.

Three Shopify visits

Write the finding as a host present on Fresh, or a host that survived Reject. The EU scenario guide holds the platform-agnostic story. This table stays on the Shopify storefront.

Fresh, Reject, and Accept on a Shopify EU storefront. What to capture.
ScenarioShopify visit labelWhat to capture
FreshClean profile. Load the storefront. No Accept or RejectTheme and app pixel hosts, cookies, and a banner screenshot
RejectClean profile. Reject All on the Shopify or CMP banner. Navigate onceThe same surfaces. Note hosts that survived Reject
AcceptClean profile. Accept All. Navigate onceA control column for comparison

Shopify surfaces to watch

Watch the surfaces you already see in Network. This list is an observation pass, not an app ranking and not a theme tutorial.

Theme and Liquid-injected scripts, plus marketing pixels, on the storefront home and product templates. Record the host on the visit where it appeared.

App pixels and custom pixels can miss or misread Customer Privacy state. The Customer Privacy API limits page owns that boundary. Screenshot the admin claim if you have it, and keep the runtime columns beside it.

Shopify cookie banner Reject wiring belongs on the Shopify Reject All guide when Reject fails. Checkout-adjacent or thank-you URLs are observation targets when they load marketing hosts. This page does not turn those URLs into a checkout configuration tutorial.

The Shopify pre-consent checklist and the platform-agnostic pre-consent checklist hold the slot order. Open them when the three columns are labeled and you still need the wider pass.

Fresh, Reject, and Accept on the storefront

These steps label three clean visits on the EU-facing storefront URL. They do not install Customer Privacy, publish a theme, or configure an app pixel. The EU scenario guide holds the wider comparison. The free versus paid guide holds the line between a US-baseline format check and an EU-scoped run.

  1. Use a clean profile. Open the EU-facing storefront URL. Do not click Accept. Capture Network, cookies, storage, and the banner. Label the pack Fresh.
  2. Open a new clean profile. Click Reject All on the Shopify or CMP banner. Navigate once, to a product or a collection. Recapture. Label the pack Reject.
  3. Open a new clean profile. Click Accept All. Navigate once. Recapture. Label the pack Accept.
  4. Write one finding sentence per mismatch, such as an app pixel host on Fresh, the same host after Reject, and marketing on the Accept column.
  5. If Customer Privacy is marked configured, screenshot that claim and keep the three runtime columns beside it.
  6. Keep the storefront URL, browser, and observation window the same across the three profiles so the columns compare.

When labeling three Shopify paths gets slow

Hand-labeling Fresh, Reject, and Accept across Shopify themes and apps takes a long time. ConsentProbe runs Fresh and Reject on the storefront URL. Each finding stays tied to a request, a cookie, or a screenshot. Keep Accept as a comparison column when you need it.

Use the free US-baseline visit when you want the report format. Use paid EU or California scenarios when those regions are the claims. The free versus paid guide draws that line. A free US-baseline scan is not an EU Shopify conclusion. ConsentProbe does not install Shopify Customer Privacy or app pixels, does not install a CMP, and does not issue a certificate.

FAQ

How do I run Fresh, Reject, and Accept on a Shopify EU store?

Use three clean profiles. Label each visit. Capture Network, cookies, and the banner. Compare hosts across the columns.

Does the Shopify Customer Privacy API replace this audit?

No. Treat API settings as claims. Match them to Fresh and Reject runtime. The Customer Privacy API limits page is that boundary.

Is this a rewrite of the EU scenario page?

No. The EU fresh, reject, and accept guide owns the platform-agnostic scenarios. This page is the Shopify vertical. It does not rewrite that guide or the Shopify cluster pages.

What if Reject still shows marketing hosts?

Follow the Shopify Reject All guide and keep the evidence pack. A host after Reject is a runtime finding.

Is a free US-baseline scan an EU Shopify audit?

No. The free visit is a format check. EU conclusions need EU-scoped runs. The free versus paid guide draws that line.

Is this legal advice?

No. These are technical observations. Observation is not counsel permission. ConsentProbe does not replace counsel, and it does not install a CMP.

Limits of this page

This page tells you how to label Fresh, Reject, and Accept on a Shopify EU storefront URL, and where Customer Privacy or app claims still need a runtime match. It does not rewrite the EU scenario guide, the Shopify pre-consent checklist, the Customer Privacy API limits page, or the Shopify Reject All guide. It is not legal advice, not a theme or checkout setup tutorial, and not a certificate. Observation is not counsel permission. ConsentProbe reports stay tied to requests, cookies, and screenshots. A free US-baseline scan is not an EU or California legal conclusion.

Related guides

Open the EU scenario guide, the Shopify pre-consent checklist, the Customer Privacy API limits page, the Shopify Reject All guide, and the free versus paid guide.

Sources

These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.

保存一次美国基线技术记录

完成自行检查后,可以跑一次免费美国基线审计:在加州以外做一次浏览器访问,把 Cookie、请求和截图存成证据。这次访问不会跑欧盟拒绝/接受,也不会跑加州 GPC。欧盟、加州和 Global 2 可在登录后的账单页购买。

Shopify 欧盟三场景审计 | ConsentProbe