检查清单

Shopify pre-consent checklist: what to check before Accept

开始免费审计

On a Shopify storefront, load a clean profile and check pixels, theme embeds, apps, and cookies before Accept. Admin CMP settings still need a live visit.

In brief

On a Shopify storefront, a pre-consent check is a clean browser load with no Accept click, plus a record of pixels, cookies, and the apps that set them. Customer events, theme app embeds, and third-party apps can each fire before a choice. List first-party and third-party cookies, capture key requests, then compare Reject All and Accept All in fresh profiles. An installed CMP app still needs that live visit. Use the pre-consent audit checklist as the shared pass order.

Not legal advice

This checklist is for Shopify and DTC storefront wiring. It is not legal advice, not an official Shopify document, and not a click-path for one CMP brand. Admin labels change. Describe the capability you checked, such as customer events, theme app embeds, or app pixels. Shopify Customer Privacy settings can gate many pixels. Theme scripts and hard-coded tags still need a storefront check. A first-party shop-host cookie still needs a name, a domain, and a reason.

Short answer

Load the public HTTPS shop URL in a fresh profile. Do not click Accept. Record cookies, storage, and network requests. Then, in separate profiles, click Reject All and navigate once, and click Accept All as the baseline for expected vendors.

The pre-consent audit checklist is the hub for that pass order. This page adds the Shopify surfaces that usually explain a miss: pixels, theme embeds, and apps. Confirm the checks on the public storefront URL customers open. An installed CMP app in the admin leaves those checks undone.

Why a Shopify shop needs its own list

A Shopify shop can load tags from the customer privacy banner, app pixels, custom pixels, theme app embeds, and apps such as chat, reviews, or upsell. Those owners are different. A setting that delays app pixel callbacks can leave a theme script running.

The Customer Privacy API records consent and exposes that state. It does not itself block a script. Read the limits page, then keep this table on the live URL. The Shopify pixel testing guide covers the three consent states in more detail. This page is the merchant pass you can finish in one sitting and send to a developer.

Prep

Use a clean profile with no leftover cookies or storage. Cover the homepage and one product URL. Write down the banner name and the exact Reject label you will click. Prefer the public storefront customers hit, whether that host is a custom domain or a myshopify.com host. A password-protected preview can miss apps that load only on the published theme.

State the region you actually tested. A free US-baseline visit is a format and wiring record outside California. It does not produce an EU reject conclusion or a California GPC conclusion. Read the free versus paid guide before you extend the pack.

Checklist

Fill one row per pass. A row with no file is not done. Pass means the wire matches the choice on that URL. Fail means the wire does not. About 15 minutes is enough for the homepage and one product URL when the profiles are already clean.

Shopify pre-consent checks. Technical checklist, not a legal pass or fail.
CheckPass signalFail signal
Fresh load, no clickNo ads or marketing pixels before a choiceMeta, Google Ads, TikTok, or similar pixels before Accept
Cookies before AcceptNo marketing or analytics IDs beyond storage you can justify for that load_ga, ads IDs, or similar identifiers already present
Reject All, then one navigationMarketing stays off on the next pageThe next page matches the Accept baseline
Accept All, new profileExpected vendors appear after the choiceThe accept visit still looks like the fresh baseline
Apps and embedsOptional chat, review, and upsell scripts waitThose apps inject trackers on the fresh load
EvidenceURLs, tables, and screenshots labeled by stepBanner-only screenshot

How to run the passes

Isolation matters more than a long export. One reused profile can carry an earlier accept into the fresh row.

  1. Note the banner state without interacting. If you cannot find a Reject control, write that down. Do not invent a click.
  2. In Application, list cookies for the shop host and every third-party origin. Note the name, the domain, and the request or script that set the key. Read the first-party versus third-party guide before you drop a shop-domain cookie because the hostname matches the shop.
  3. In Network, capture pixel, analytics, ads, and replay requests, including cookieless pings. Separate app pixels, custom pixels, and theme scripts in your notes so the owner is clear.
  4. In a new profile, click Reject All, confirm the banner or preference state changed, navigate once, and recapture the same layers. The Reject All leftovers guide is the deeper pass when marketing remains.
  5. In a third profile, Accept and recapture. This row shows what expected vendors look like after a choice. If the reject row matches this row, reject did not change the wire.
  6. Screenshot the untouched banner plus the cookie and request tables. Remove query values that carry identifiers before you share the pack.

What to send a developer or agency

Tie each cookie or pixel to a request or script and a pre-Accept screenshot. Name the surface: customer events, theme app embed, or app. Send the filled table with the URL and the region you tested.

ConsentProbe can store that pack for the public shop URL. A free US-baseline visit matches a pre-consent technical record outside California. Use pricing when the next claim needs EU reject and accept, or California GPC. The report stays a technical record.

FAQ

Does the Customer Privacy API or a CMP app replace this checklist?

Only when the storefront runtime matches the banner. Walk this table and the pre-consent audit checklist on the public URL.

Can theme app embeds fire before Accept?

Yes. Include them in the fresh-load network list. Admin pixel settings can miss a script the theme injects.

Is a password-protected preview enough?

Prefer the public storefront URL customers open. A preview can omit apps that load only on the published theme.

Does a free US scan answer an EU shopper question?

An EU reject or accept claim needs the EU scenarios. Read the free versus paid guide before you extend a US-baseline file.

Are first-party Shopify cookies allowed before consent?

First-party describes the host. Analytics and ads identifiers on the shop domain still need review.

Where do custom pixels show up?

In the admin customer events list and in the storefront Network list. Confirm both. Settings alone are not the runtime record.

Related guides

Pair this table with the pre-consent audit checklist, the Customer Privacy API limits page, the pixel testing guide, and the first-party inventory.

Sources

These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.

保存一次美国基线技术记录

完成自行检查后,可以跑一次免费美国基线审计:在加州以外做一次浏览器访问,把 Cookie、请求和截图存成证据。这次访问不会跑欧盟拒绝/接受,也不会跑加州 GPC。欧盟、加州和 Global 2 可在登录后的账单页购买。

Shopify 同意前检查清单 | ConsentProbe