Customise a GDPR-friendly cookie banner, copy one snippet of code, and paste it into your site. No account, no monthly fee to start.
Paste it just before </body> on your site.
Shopify provides a built-in customer privacy banner and a consent API that its own tracking respects. If your store is simple and you use nothing beyond Shopify’s native analytics, that may genuinely be enough.
The gap opens as soon as you add anything else — which almost every store does.
theme.liquid rather than through Shopify’s channels. These fire on page load regardless of consent.The most common Shopify compliance failure is an app installed months ago that nobody remembers, setting a tracking cookie on every page. Audit what your store actually sets rather than assuming the platform handles it.
Open your store in a private window and look at Application → Cookies in developer tools before touching anything. Every cookie present at that moment was set without consent. Compare the list against your apps — the names usually identify the culprit.
Edit your theme code and paste the snippet into theme.liquid, immediately before the closing </body> tag. Duplicate the theme first so you can roll back, and remember it will need reapplying if you switch themes or take a major theme update.
Whichever banner you use, the underlying obligation is the same: non-essential cookies must not be set until the visitor has agreed, and refusing must be as easy as accepting.
Yes, Shopify provides a customer privacy banner and a consent API that its native tracking respects. Third-party apps often do not use it.
Usually an app or a pixel added directly to theme.liquid. Those fire on page load independently of Shopify's consent API.
In theme.liquid, just before the closing body tag. Duplicate your theme first, and expect to reapply it after a theme change.
Open the store in a private window and check Application โ Cookies in developer tools before clicking anything. Anything present was set without consent.