How the installation works
The app installs a theme app extension, which loads the shared consent runtime and synchronises decisions with Shopify’s Customer Privacy API. That synchronisation is the part that matters beyond your own tags: Shopify surfaces and apps that consult the Customer Privacy API see the same answer the visitor gave your banner.
- 1
Install the app
Connect the store and claim the installation against a workspace.
- 2
Enable the app embed
Turn on the StrongPrivacy block in the theme editor so the runtime loads on the storefront.
- 3
Configure categories and technologies
Map what the store loads to categories, entering identifiers for the pixels that have a named adapter.
- 4
Publish and verify
Run a scan of the live storefront in each consent state, with apps active.
No app install? There is a lighter path
The same runtime can be added directly to theme.liquid near the start of <head>, before any optional script it is expected to control, carrying data-platform="shopify-lite". It can still send choices through Shopify Customer Privacy without an app install; verify that app-managed and checkout surfaces honour that state.
The apps are the real work
Storefront apps and sales channels can inject scripts independently of theme code. Advertising integrations may add pixels, while reviews, chat and upsell apps may add widgets or measurement. A theme-only audit can therefore miss technologies present on the live storefront.
- Scan the live storefront, not a development theme, and not a theme preview with apps disabled
- Check a product page and the cart, not only the homepage: app scripts are often route-scoped
- Where an app injects a pixel you also configured here, remove one of them; two installations means two identifiers
- Apps that do not consult the Customer Privacy API need their own handling, which may mean removing the app
Checkout is a different surface
Shopify controls the checkout, and what can run there is constrained by the platform rather than by your theme. Treat it as a separate surface in your audit: scan it, see what is present, and be clear in your declaration about which cookies belong to Shopify’s own checkout rather than to anything you added.
Common questions
Does this replace Shopify’s own cookie banner?
Only after you verify that the replacement presents the choice, records it, synchronises with Shopify’s Customer Privacy API and controls every relevant theme, app and platform surface. Do not run two independent banners, but do not disable Shopify’s banner merely because another banner renders.
Will it slow the storefront down?
The runtime is loaded with defer as one request. Gating optional third-party scripts can reduce pre-consent network and execution work, but the actual performance effect depends on the store and should be measured.
What about the Shop app and Shop Pay?
Those are Shopify platform surfaces with their own cookies, several of which are necessary. Your declaration should name them and say which are necessary rather than leaving them unattributed.
Sources and verification
Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.
- Shopify Customer Privacy API
Vendor documentation
Checked
- Shopify Cookie Policy
Vendor documentation
Checked
- Shopify changelog: _shopify_y and _shopify_s retirement notice
Vendor documentation
Checked
- StrongPrivacy documentation
Product documentation
Checked
See what your own site is loading
A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.