Platform guide

Cookie consent on Shopify, including the apps you forgot about.

Shopify’s theme is only one source of storefront code. Trackers can also arrive from sales-channel and other apps, so removing a theme snippet does not remove app-managed integrations.

Install
Theme app extension
Alternative
Script tag with shopify-lite
Integrates with
Customer Privacy API
Hard part
App-injected pixels

How the installation works

The app installs a theme app extension, which loads the shared consent runtime and synchronises decisions with Shopify’s Customer Privacy API. That synchronisation is the part that matters beyond your own tags: Shopify surfaces and apps that consult the Customer Privacy API see the same answer the visitor gave your banner.

  1. 1

    Install the app

    Connect the store and claim the installation against a workspace.

  2. 2

    Enable the app embed

    Turn on the StrongPrivacy block in the theme editor so the runtime loads on the storefront.

  3. 3

    Configure categories and technologies

    Map what the store loads to categories, entering identifiers for the pixels that have a named adapter.

  4. 4

    Publish and verify

    Run a scan of the live storefront in each consent state, with apps active.

No app install? There is a lighter path

The same runtime can be added directly to theme.liquid near the start of <head>, before any optional script it is expected to control, carrying data-platform="shopify-lite". It can still send choices through Shopify Customer Privacy without an app install; verify that app-managed and checkout surfaces honour that state.

The apps are the real work

Storefront apps and sales channels can inject scripts independently of theme code. Advertising integrations may add pixels, while reviews, chat and upsell apps may add widgets or measurement. A theme-only audit can therefore miss technologies present on the live storefront.

  • Scan the live storefront, not a development theme, and not a theme preview with apps disabled
  • Check a product page and the cart, not only the homepage: app scripts are often route-scoped
  • Where an app injects a pixel you also configured here, remove one of them; two installations means two identifiers
  • Apps that do not consult the Customer Privacy API need their own handling, which may mean removing the app

Checkout is a different surface

Shopify controls the checkout, and what can run there is constrained by the platform rather than by your theme. Treat it as a separate surface in your audit: scan it, see what is present, and be clear in your declaration about which cookies belong to Shopify’s own checkout rather than to anything you added.

Common questions

Does this replace Shopify’s own cookie banner?

Only after you verify that the replacement presents the choice, records it, synchronises with Shopify’s Customer Privacy API and controls every relevant theme, app and platform surface. Do not run two independent banners, but do not disable Shopify’s banner merely because another banner renders.

Will it slow the storefront down?

The runtime is loaded with defer as one request. Gating optional third-party scripts can reduce pre-consent network and execution work, but the actual performance effect depends on the store and should be measured.

What about the Shop app and Shop Pay?

Those are Shopify platform surfaces with their own cookies, several of which are necessary. Your declaration should name them and say which are necessary rather than leaving them unattributed.

Sources and verification

Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.

See what your own site is loading

A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.