Shopify's Customer Privacy API expects your banner to report consent, or analytics and marketing pixels can be blocked or fire incorrectly. ConsentStack is built for Shopify: it reports consent to Shopify natively and blocks third-party trackers until the shopper opts in.
Does Shopify's built-in cookie banner block third-party trackers?
No. Shopify says so itself: its help center describes the built-in banner as governing Shopify-specific tools, and a Shopify Community answer is blunter: the banner only controls the first-party cookies Shopify sets. It does not manage or block tags like Google Tag Manager or the Meta Pixel.
In practice that is exactly where store tracking lives: the Meta Pixel, TikTok, Klaviyo, affiliate and heatmap tools, pasted into the theme or added by apps. ConsentStack blocks those scripts in the browser until the shopper consents, with no per-tag wiring. Read how script blocking works for the mechanics.
What is Shopify's Customer Privacy API?
It is Shopify's browser JavaScript API for recording what a visitor consented to, and it is how a third-party banner is supposed to plug in. Shopify's help center tells merchants who bring their own cookie banner to integrate it with customer privacy settings, because that record is what gates Shopify Analytics and web pixels.
ConsentStack does that integration automatically. On a Shopify storefront the SDK reports every explicit decision to the API, mapping analytics, marketing, and preferences one to one and recording the sale-of-data signal as denied when a Global Privacy Control opt-out applies. The full mechanics, including the exact category mapping, are in the Shopify integration docs.
How do you check what fires before consent on your store?
Test it rather than trusting any banner, ours included. Open your storefront in a private window, decline the banner, and watch the network tab for requests to domains like connect.facebook.net or analytics.tiktok.com. Requests that appear after a decline mean tracking is running without consent. Our free compliance scanner runs the same check for you in a real browser.
The scanner loads your store, interacts with the banner, and reports which trackers fired before and after consent, with the evidence attached. If you would rather check by hand, our testing and verification guide walks through it step by step.
Why ConsentStack on Shopify
- Reports consent to Shopify's Customer Privacy API, so pixels and analytics behave correctly instead of silently dropping.
- Meta, TikTok, Google, and Klaviyo tags stop on decline, and attribution stays intact for shoppers who accept.
- Covers GDPR, CCPA, and 70+ regulations from one install, across every market you sell into.
- Pixel-perfect brand matching, so the banner looks built into your Shopify site, never bolted on.
Add ConsentStack to Shopify
Add the tags to the <head> of your theme.liquid file, or through your theme's custom-code settings.
<link rel="preconnect" href="https://cdn.consentstack.io" />
<script src="https://cdn.consentstack.io/consent.js?k=YOUR_SITE_KEY"></script>
<script src="https://cdn.consentstack.io/consent-core.js?k=YOUR_SITE_KEY"></script>Replace YOUR_SITE_KEY with the site key from your ConsentStack dashboard.
ConsentStack signals consent to Shopify's Customer Privacy API automatically, so Shopify's analytics, marketing, preferences, and sale-of-data settings stay in sync with the banner.
Common questions
Yes. ConsentStack reports consent to Shopify's Customer Privacy API on every decision, mapping banner categories to Shopify's analytics, marketing, preferences, and sale-of-data signals. That keeps Shopify's native tracking in sync with the banner.
No. Shopify and app pixels keep working for shoppers who accept and stop for shoppers who decline. Because consent is reported natively, you avoid the session and attribution drops that happen when a banner does not talk to Shopify.
Add the three tags to the <head> of theme.liquid, or through your theme's custom-code area. No app install is required.
100+ happy customers
Ship consent on Shopify. In minutes.
Scan your site free to see what is firing before consent, then turn on real blocking from one install.