Consent management for Shopify
A cookie banner for your Shopify store that Shopify itself understands. Consent Studio talks to the Customer Privacy API, so Shopify and the apps that read it act on what the shopper chose instead of being trusted to. It keeps working in checkout, where Shopify runs sandboxed and most banners stop.
- Works through checkout
- Customer Privacy API
- No app required
From โฌ10 a month. No credit card, no per-visitor billing.
A cookie banner that works with Shopify
Enabling the Shopify integration turns each banner decision into a tracking-consent signal Shopify itself enforces, rather than something your tags are trusted to honour.
Customer Privacy API
The banner calls setTrackingConsent on every decision, so Shopify records the choice natively. Your functional, analytics and marketing categories map onto preferences, analytics and marketing.
- Built in
- No code
Checkout stays governed
Shopify checkout runs in a sandbox that cannot read your storefront consent state. A Custom Pixel carries the decision across, so consent survives the one page where the money is.
- Custom Pixel
- Recommended
Opt-in or opt-out per category
Set the default state for preferences, analytics and marketing independently. Stores selling into both the EU and California need different answers, and this is where you give them.
- Per-region defaults
Selling into California as well as the EU?
The GDPR and CCPA ask for opposite defaults, and Shopify carries a flag for the American half that most banners never set.
Sale of data
Under CCPA and CPRA, handing data to an ad network can count as a sale or a share even when no money changes hands. Shopifyโs Customer Privacy API has a sale-of-data flag for exactly that, and Consent Studio sets it from your marketing category on every decision.
Opposite defaults, one banner
The GDPR wants marketing denied until a shopper agrees. CCPA runs the other way, as an opt-out. Preferences, analytics and marketing each take their own default, so one store can answer both regimes without a second banner for the US.
The same record either way
Whichever default a region gets, the decision goes back through the same setTrackingConsent call and into the same consent log. There is no separate American install to keep in step, and nothing to reconcile when an auditor asks for one history.
One answer controls every tool on your site
A banner that only governs the platform leaves everything you added on top of it running. Consent Studio speaks to the tools around it as well, and by default holds anything it does not recognise until the visitor says otherwise.
Discover All IntegrationsChoose how to install the cookie banner
Every route ends with the same banner and the same consent record. Pick the one that fits how your site is built.
Direct code
Recommended RoutePaste the snippet into theme.liquid, ahead of your other scripts, so the banner loads before anything it has to govern. This is the route we recommend on Shopify and the one with the fewest moving parts.
- Full control
- No dependencies
Google Tag Manager
Already running GTM on the store? Add our official tag from the Community Gallery on the Consent Initialization trigger and skip the theme edit entirely.
- Official tag template
- No site deploy
How to set up cookie consent for Shopify
Roughly ten minutes, and nothing here needs a developer. The first three steps are the same on any site. The fourth is the one that is specific to Shopify, and it is the one worth not skipping.
Add your store domain
Create the site in Consent Studio and the banner is generated for that exact domain, with your categories, languages and styling already in it. It is served from consent.studio rather than a third-party CDN, so your storefront loads nothing from an external tracker before a shopper has agreed to anything.
Install the snippet
Paste it into your theme so the banner loads ahead of every other script, or add our tag in Google Tag Manager if that is where your tags already live. Load order is the part worth getting right: a banner that runs after your analytics has already fired records a choice it cannot enforce. The dashboard shows the exact code for your store, so there is nothing to assemble by hand.
Switch on the Shopify integration
Open Web CMP, go to Integrations and enable Shopify Customer Privacy API. From then on every decision is written back with setTrackingConsent, so Shopify holds the record itself and its own apps and pixels read the same answer your tags do. Without it, a banner governs only the tags it knows about, and a store usually runs several it does not.
Add the checkout pixel
In Shopify Admin, go to Settings, Customer events and add a custom pixel. Shopify checkout runs in a sandbox that cannot read the consent state from the rest of your store, so without this step the highest-intent pages in the funnel sit outside the banner entirely. The pixel carries the shopper decision across that boundary and keeps it enforced through to the thank-you page.
A cookie banner alone is not enough
Most sites are leaking before anyone notices. Not through malice, but through a tag somebody added in a hurry, a vendor that changed its script, a plugin that phones home.
- Unconsented tracking
- Unwanted overseas transfers
- Consent records you cannot produce
- Scripts you never approved
The Full Consent Stack.
Three products, one consent record. What a visitor agreed to in the banner is what every downstream tag sees.
Which plan Shopify needs, and why
Essential runs everything on this page. Professional is what a busy shop grows into, not the price of getting started.
Essential is enough
โฌ10/month
- The Shopify integration and the checkout pixel
- Google and Microsoft Consent Mode
- Unlimited pages, 200,000 consent actions a month
What Professional adds
โฌ36/month
A shop hits these sooner than a brochure site does.
- More depth: HTTP consent cookies, accessibility, re-prompting
- Returning shoppers are not asked again
- Re-prompt when a new app adds a tracker
- Sitemap and on-demand scans, for a growing catalogue
Every plan includes
Trusted by organisations that care about privacy
Frequently asked questions about Shopify
Does Shopify set cookies before consent?
Yes. A Shopify storefront sets first-party cookies before a visitor has chosen anything, and Shopify treats those as strictly necessary for the store to function. They are not the part a banner governs. The analytics and marketing tags you add yourself are, and those have to be held until a shopper agrees.
Does the Shopify cookie banner make my store GDPR compliant?
Not on its own. Shopify's built-in banner records a choice but does not block third-party tags you install through your theme or a tag manager, and it offers limited control over categories and appearance. A CMP that signals the Customer Privacy API and gates your own tags is what closes that gap.
Does the cookie banner work on Shopify checkout?
Yes, with the checkout pixel. Shopify checkout runs in a sandboxed environment that cannot read the consent state from the rest of your store, so consent has to be passed in deliberately. Consent Studio provides a Custom Pixel that syncs the decision during checkout.
Is the Shopify integration included, or does it need a higher plan?
It is included on every plan, including Essential at โฌ10 a month. Integrations are counted rather than gated: Essential covers three and further ones are โฌ2 a month each, while Professional and Enterprise carry unlimited. The checkout pixel is not an integration at all, so it never counts toward that total.
Do I need an app to add a cookie banner to Shopify?
No. Consent Studio installs as a script in your theme, or as a tag in Google Tag Manager if you already use one. There is no app to authorise and nothing added to your Shopify admin beyond the checkout pixel.
Does Consent Studio handle "Do Not Sell or Share My Personal Information" on Shopify?
Yes, through Shopifyโs Customer Privacy API. Consent Studio sets the sale-of-data flag from your marketing category on every decision, so a shopper who declines marketing is recorded as having opted out of the sale and sharing of their personal information. The same call carries preferences and analytics, so one banner answers CCPA and the GDPR.
Does Consent Studio support the Shopify Customer Privacy API?
Yes, as a built-in integration you switch on in the dashboard. Consent Studio loads the consent-tracking-api feature and calls setTrackingConsent whenever a shopper makes or changes a choice, so Shopify holds the record rather than only your banner.
Get Started with the Full Consent Stack
Everything you need in one bundle. Consent Studio provides you with a consent banner, scanner and client-side tag manager that guarantees no data ever gets transferred overseas.
Read the documentation
Our help center walks through every integration, plugin and template step by step, with screenshots. It is written and kept current by the people who build Consent Studio.










