How we workHow do we bring consent and tracking together?
01Take stock
We record every script, pixel, app and cookie in the store - including the services loaded through apps that appear in no documentation.
02Define categories
Each service gets a category and a decision on whether it may run without consent. Your privacy function makes that call; we implement it technically.
03Wire the CMP
Embedding the banner, mapping categories, passing the state to Shopify's customer privacy interface and to the tag manager. Only then are tags released.
04Set Consent Mode
Defining the default state, triggering the update after the user's choice, verifying signals in GA4 and Google Ads. The ad accounts have to see the signals too, not just the website.
05Test the states
Refused, partial, full - each with a network trace and cookie list. Plus checkout and thank-you page, where different rules apply than in the theme.
06Document
Services, purposes, recipients and retention periods in one overview. That keeps privacy policy and processing records maintainable.
FAQFrequently asked questions about consent and privacy on Shopify
What is Google Consent Mode v2?
An interface through which your website tells Google what a user consented to. Four signals control analytics, ad storage, user data and personalisation. Without those signals, Google noticeably limits audience building and conversion modelling for visitors from the European Economic Area.
Is Shopify's own consent feature enough?
For simple setups, often yes. It provides the banner and the customer privacy state. As soon as several ad channels, a tag manager, international markets with differing rules or many apps come together, a dedicated CMP is usually more maintainable. Two banners in parallel is never right.
Do we lose a lot of data through consent?
A share of sessions drops out of measurement; there is no arguing that away. Server-side events, sound conversion modelling and aggregated measurement recover part of it. What matters more is that the remaining data stays consistent - incomplete and stable beats complete and wrong.
How does this relate to your tracking setups?
Consent is the precondition, tracking is what gets built on top. This page is about consent, legal bases and data flows. The measurement itself - GA4, tag manager, server-side tracking, channel connections and quality assurance - is described on our tracking setups page.
What applies in the checkout and on the thank-you page?
No freely embedded scripts run there. Analytics and marketing services are added through the pixel environment, which exposes events in a sandboxed form and respects consent. Anyone who wants to measure completed purchases has to take that route - theme scripts do not reach it.
Do you assess whether our setup is legally compliant?
No. We document reliably what happens technically: which services load, when, with which data and to which recipient. That factual basis is what your legal counsel or data protection officer needs for their assessment - it does not replace their advice.
Do you know what loads in your store without consent?
We record scripts, apps and pixels and show you in a network trace what really happens - in every consent state.