One status everywhere
Theme, apps, pixels and checkout read the same consent state instead of conflicting signals.
No consent, no data - but a bad consent setup gets you no data either. We connect CMP, Consent Mode v2 and Shopify so both actually work.
Theme, apps, pixels and checkout read the same consent state instead of conflicting signals.
Consent mode and tracking are wired so permitted data remains fully usable.
Services, recipients and legal bases are documented transparently and ready for review.
Selecting the consent platform against your requirements, embedding it in the theme and connecting it to Shopify's customer privacy interface - so apps and pixels read the same state as the banner.
Setting the four signals for analytics, advertising, user data and personalisation correctly, defining the default state and aligning it with tag manager, GA4 and your ad channels. Without that, ad accounts lose audiences and modelling.
Which services run in the store, which data leaves it, on what legal basis and to which recipient. Your privacy policy needs that overview anyway - and so does your data protection officer.
What matters is what happens afterwards. If scripts load before consent or apps ignore the state, the nicest banner changes nothing about the actual data processing.
Reviews, chat, personalisation, ad pixels: every app can bring its own scripts and cookies. Shopify offers a customer privacy interface apps can query - but they also have to actually use it.
No freely embedded scripts run in the checkout. Marketing and analytics services are added through the pixel environment, which respects consent. Your tracking concept has to account for that.
We build and document the technical side: what loads when, which state is passed where, what happens without consent. The legal assessment of your setup belongs with your legal counsel.
A setup that only works on consent is incomplete. Server-side events, aggregated measurement and modelling make sure refused sessions do not leave you completely blind.
Hidden reject buttons and pre-ticked boxes lift the consent rate short term and the risk long term. A clearly designed banner is no disadvantage from a conversion perspective either.
Theme, apps, tag manager and checkout pixels have to use the same consent state. Two parallel truths are the most common reason for data gaps nobody can explain.
What actually loads without consent is only visible in a network trace. We test every state - refused, partial, full - and document the result.
We record every script, pixel, app and cookie in the store - including the services loaded through apps that appear in no documentation.
Each service gets a category and a decision on whether it may run without consent. Your privacy function makes that call; we implement it technically.
Embedding the banner, mapping categories, passing the state to Shopify's customer privacy interface and to the tag manager. Only then are tags released.
Defining the default state, triggering the update after the user's choice, verifying signals in GA4 and Google Ads. The ad accounts have to see the signals too, not just the website.
Refused, partial, full - each with a network trace and cookie list. Plus checkout and thank-you page, where different rules apply than in the theme.
Services, purposes, recipients and retention periods in one overview. That keeps privacy policy and processing records maintainable.
A script hard-wired into the theme ignores any consent. The most common finding in stores grown over years.
The default state is set but the update after the user's decision is missing. Result: permanently denied signals despite consent.
Apps that never query the privacy interface set cookies regardless of the banner. That only shows up in a trace.
Shopify's own consent feature and an additional CMP both active - with contradictory states and a double prompt.
Google, Meta and other channels pull data from the same store - the consent state then decides what reaches the ad accounts at all.
Nobody on the team can still say which scripts and apps are live. That is exactly when taking stock beats buying another banner.
Differing rules per country only work if categories, default state and banner logic are steered centrally instead of improvised market by market.
GA4 and the ad accounts disagree and no one finds the reason. The cause often sits in the consent state, not in the measurement code.
Whether your setup holds up legally is for your legal counsel or data protection officer to judge. We supply the technical facts for it, not the verdict.
Talk to us about the technical sideWithout GA4, a tag manager and defined events there is nothing a consent state would need to govern. The measurement build comes first.
Go to tracking setupsAs long as old scripts hang in order completion, consent logic only reaches as far as the cart. Moving to the pixel environment belongs first.
Go to Shopify checkoutThree formats - depending on whether you first want to know what actually happens, or want it changed straight away.
For stores with a banner in place where nobody can prove what really loads before and after consent.
Ends with a list of findings, ranked by risk, that your legal counsel can read without us in the room.
For stores introducing a consent platform or moving from Shopify's built-in feature to a dedicated CMP.
Ends with a setup where theme, apps and checkout read the same state - evidenced in a network trace.
For stores where apps, pixels and theme versions change regularly and the documented state would otherwise quietly go stale.
Every round produces a service inventory that matches the store as it is, not as it was at rollout.
Brands with €950M+ GMV trust us
From migration to scale, NICCOS combines bold design, robust technology and data-driven growth on Shopify.
An interface through which your website tells Google what a user consented to. Four signals control analytics, ad storage, user data and personalisation. Without those signals, Google noticeably limits audience building and conversion modelling for visitors from the European Economic Area.
For simple setups, often yes. It provides the banner and the customer privacy state. As soon as several ad channels, a tag manager, international markets with differing rules or many apps come together, a dedicated CMP is usually more maintainable. Two banners in parallel is never right.
A share of sessions drops out of measurement; there is no arguing that away. Server-side events, sound conversion modelling and aggregated measurement recover part of it. What matters more is that the remaining data stays consistent - incomplete and stable beats complete and wrong.
Consent is the precondition, tracking is what gets built on top. This page is about consent, legal bases and data flows. The measurement itself - GA4, tag manager, server-side tracking, channel connections and quality assurance - is described on our tracking setups page.
No freely embedded scripts run there. Analytics and marketing services are added through the pixel environment, which exposes events in a sandboxed form and respects consent. Anyone who wants to measure completed purchases has to take that route - theme scripts do not reach it.
No. We document reliably what happens technically: which services load, when, with which data and to which recipient. That factual basis is what your legal counsel or data protection officer needs for their assessment - it does not replace their advice.
We record scripts, apps and pixels and show you in a network trace what really happens - in every consent state.
Last updated:
Project start
Usually a response within 24 hours
Talk directly to a strategy or tech senior
No agency slide deck, just clear next steps
NICCOS
The page could not be loaded.
Please reload the page. If an update has just gone live, this will load the latest version.