Consent & privacy

    Consent done properly. Tracking stays measurable.

    Start a Project

    No consent, no data - but a bad consent setup gets you no data either. We connect CMP, Consent Mode v2 and Shopify so both actually work.

    Key facts
    4Signals in Google Consent Mode v2
    § 25German TDDDG governs consent for end devices
    1One consent state for theme, apps and checkout
    • Since 2019
    • 150+ Migrations and Relaunches
    • Official Shopify Plus Partner
    Scope

    What belongs in a clean consent setup?

    Choosing and wiring a CMP

    Selecting the consent platform against your requirements, embedding it in the theme and connecting it to Shopify's customer privacy interface - so apps and pixels read the same state as the banner.

    Wiring up Consent Mode v2

    Setting the four signals for analytics, advertising, user data and personalisation correctly, defining the default state and aligning it with tag manager, GA4 and your ad channels. Without that, ad accounts lose audiences and modelling.

    Documenting data flows

    Which services run in the store, which data leaves it, on what legal basis and to which recipient. Your privacy policy needs that overview anyway - and so does your data protection officer.

    The frame

    Why isn't a cookie banner on its own enough?

    The banner is only the surface

    What matters is what happens afterwards. If scripts load before consent or apps ignore the state, the nicest banner changes nothing about the actual data processing.

    Apps are participants

    Reviews, chat, personalisation, ad pixels: every app can bring its own scripts and cookies. Shopify offers a customer privacy interface apps can query - but they also have to actually use it.

    The checkout has its own rules

    No freely embedded scripts run in the checkout. Marketing and analytics services are added through the pixel environment, which respects consent. Your tracking concept has to account for that.

    Not legal advice

    We build and document the technical side: what loads when, which state is passed where, what happens without consent. The legal assessment of your setup belongs with your legal counsel.

    A refusal is a result

    A setup that only works on consent is incomplete. Server-side events, aggregated measurement and modelling make sure refused sessions do not leave you completely blind.

    Dark patterns cost more than they earn

    Hidden reject buttons and pre-ticked boxes lift the consent rate short term and the risk long term. A clearly designed banner is no disadvantage from a conversion perspective either.

    One state, read everywhere

    Theme, apps, tag manager and checkout pixels have to use the same consent state. Two parallel truths are the most common reason for data gaps nobody can explain.

    Verify instead of assume

    What actually loads without consent is only visible in a network trace. We test every state - refused, partial, full - and document the result.

    How we work

    How do we bring consent and tracking together?

    01

    Take stock

    We record every script, pixel, app and cookie in the store - including the services loaded through apps that appear in no documentation.

    02

    Define categories

    Each service gets a category and a decision on whether it may run without consent. Your privacy function makes that call; we implement it technically.

    03

    Wire the CMP

    Embedding the banner, mapping categories, passing the state to Shopify's customer privacy interface and to the tag manager. Only then are tags released.

    04

    Set Consent Mode

    Defining the default state, triggering the update after the user's choice, verifying signals in GA4 and Google Ads. The ad accounts have to see the signals too, not just the website.

    05

    Test the states

    Refused, partial, full - each with a network trace and cookie list. Plus checkout and thank-you page, where different rules apply than in the theme.

    06

    Document

    Services, purposes, recipients and retention periods in one overview. That keeps privacy policy and processing records maintainable.

    Common failures

    Where do consent setups fall apart in practice?

    Tags firing before the banner

    A script hard-wired into the theme ignores any consent. The most common finding in stores grown over years.

    Consent Mode without the update

    The default state is set but the update after the user's decision is missing. Result: permanently denied signals despite consent.

    Apps with a mind of their own

    Apps that never query the privacy interface set cookies regardless of the banner. That only shows up in a trace.

    Two banners

    Shopify's own consent feature and an additional CMP both active - with contradictory states and a double prompt.

    Fit

    When is a dedicated consent project worth it?

    Then the timing is right

    Several ad channels running

    Google, Meta and other channels pull data from the same store - the consent state then decides what reaches the ad accounts at all.

    A store grown over years

    Nobody on the team can still say which scripts and apps are live. That is exactly when taking stock beats buying another banner.

    Several markets, one storefront

    Differing rules per country only work if categories, default state and banner logic are steered centrally instead of improvised market by market.

    Data gaps nobody can explain

    GA4 and the ad accounts disagree and no one finds the reason. The cause often sits in the consent state, not in the measurement code.

    Then something else comes first

    You need a legal assessment

    Whether your setup holds up legally is for your legal counsel or data protection officer to judge. We supply the technical facts for it, not the verdict.

    Talk to us about the technical side

    There is no measurement yet

    Without GA4, a tag manager and defined events there is nothing a consent state would need to govern. The measurement build comes first.

    Go to tracking setups

    The checkout is still open

    As long as old scripts hang in order completion, consent logic only reaches as far as the cart. Moving to the pixel environment belongs first.

    Go to Shopify checkout
    Working together

    How do we get started on consent?

    Three formats - depending on whether you first want to know what actually happens, or want it changed straight away.

    Consent audit

    Who it is for

    For stores with a banner in place where nobody can prove what really loads before and after consent.

    What is included
    • Network trace per consent state
    • Cookie and service inventory
    • Consent Mode v2 cross-check
    How it ends

    Ends with a list of findings, ranked by risk, that your legal counsel can read without us in the room.

    CMP rollout

    Who it is for

    For stores introducing a consent platform or moving from Shopify's built-in feature to a dedicated CMP.

    What is included
    • Select the CMP and embed it in the theme
    • Wire categories and customer privacy state
    • Pass Consent Mode v2 to the ad accounts
    How it ends

    Ends with a setup where theme, apps and checkout read the same state - evidenced in a network trace.

    Ongoing consent care

    Who it is for

    For stores where apps, pixels and theme versions change regularly and the documented state would otherwise quietly go stale.

    What is included
    • Classify new apps and pixels
    • Re-check after theme and app updates
    • Keep the service inventory current
    How it ends

    Every round produces a service inventory that matches the store as it is, not as it was at rollout.

    Brands with €950M+ GMV trust NICCOS

    Groundies logo
    MYCR7 logo
    Gusti Leder logo
    Smilodox logo
    Bikemailorder logo
    O'Neal logo
    Freiluftkind logo
    Sirocco logo
    Olakala logo
    CAT logo
    Deputy logo
    Heel logo
    Bloomingloft logo
    FRITZ! logo
    Prepmymeal logo
    Mintkind logo
    FAQ

    Frequently asked questions about consent and privacy on Shopify

    What is Google Consent Mode v2?

    An interface through which your website tells Google what a user consented to. Four signals control analytics, ad storage, user data and personalisation. Without those signals, Google noticeably limits audience building and conversion modelling for visitors from the European Economic Area.

    Is Shopify's own consent feature enough?

    For simple setups, often yes. It provides the banner and the customer privacy state. As soon as several ad channels, a tag manager, international markets with differing rules or many apps come together, a dedicated CMP is usually more maintainable. Two banners in parallel is never right.

    Do we lose a lot of data through consent?

    A share of sessions drops out of measurement; there is no arguing that away. Server-side events, sound conversion modelling and aggregated measurement recover part of it. What matters more is that the remaining data stays consistent - incomplete and stable beats complete and wrong.

    How does this relate to your tracking setups?

    Consent is the precondition, tracking is what gets built on top. This page is about consent, legal bases and data flows. The measurement itself - GA4, tag manager, server-side tracking, channel connections and quality assurance - is described on our tracking setups page.

    What applies in the checkout and on the thank-you page?

    No freely embedded scripts run there. Analytics and marketing services are added through the pixel environment, which exposes events in a sandboxed form and respects consent. Anyone who wants to measure completed purchases has to take that route - theme scripts do not reach it.

    Do you assess whether our setup is legally compliant?

    No. We document reliably what happens technically: which services load, when, with which data and to which recipient. That factual basis is what your legal counsel or data protection officer needs for their assessment - it does not replace their advice.

    Do you know what loads in your store without consent?

    We record scripts, apps and pixels and show you in a network trace what really happens - in every consent state.

    Last updated:

    Project start

    Let's grow together.

    Usually a response within 24 hours

    Talk directly to a strategy or tech senior

    No agency slide deck, just clear next steps

    Shopify Plus Partner certification

    When you submit, your request goes directly into the NICCOS process. No newsletter opt-in, no resale of contact data.

    NICCOS

    Die Seite konnte nicht geladen werden.

    Bitte lade die Seite neu. Falls gerade ein Update live gegangen ist, wird damit die aktuelle Version geladen.