The shape of the problem
Storefronts often accumulate marketing technology because apps and sales channels can add it without a theme-code change. Common examples include advertising pixels, conversion tags, behavioural email tooling, reviews widgets and chat, but the actual inventory must come from the live store rather than this example list.
Many arrive through platform apps rather than theme code, so a source-only audit can miss what the live store loads. Browser observation with apps active is essential runtime evidence; reconcile it with app settings, tag-manager configuration, platform pixel controls, server-side integrations and vendor consoles.
Draw the necessary line carefully
| Cookie | Category | Why |
|---|---|---|
| Cart contents | Necessary | Strictly necessary for a service the visitor requested |
| Checkout session | Necessary | The transaction cannot complete without it |
| Payment fraud identifiers | Assess on payment paths | May be necessary for secure payment; scope and configuration matter |
| Storefront analytics identifiers | Analytics | Measurement, not function |
| Conversion and remarketing tags | Marketing | Profiling and targeting |
| Reviews and chat widgets | Functional | A feature, not a requirement |
Do not gate a basket function that is actually necessary
Storage genuinely required to provide the shopping flow the visitor requested should remain available; analytics and advertising attached to the same platform do not inherit that status. Test a complete purchase with every optional category refused before publishing.
The conversion tag is the one to verify
Purchase conversion tags fire once, on the order-received page, after a real order. A scan of the homepage and a product page misses the single highest-value tracking event on the store. Include the checkout flow in verification, or capture it as a HAR file from a test order.
Expect the reporting to change once consent is enforced. Attribution for refusing visitors disappears, which is the correct outcome and still deserves a conversation with whoever owns the revenue dashboard before it happens rather than after.
Common questions
Will consent hurt conversion rates?
Measured attribution can fall when refusing visitors are no longer tracked. The effect on actual purchases depends on audience, design, offer and implementation, and this page does not claim a universal uplift or loss. Establish a lawful measurement plan and compare revenue and attribution separately rather than treating missing tracking as missing sales.
How many sites does a store need?
One property per storefront domain. Starter covers one, Growth covers five, Agency covers twenty-five, which is the usual answer for a multi-region store running separate domains.
Sources and verification
Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.
- StrongPrivacy product capabilities
Product documentation
Checked
- Shopify Customer Privacy API
Vendor documentation
Checked
- Shopify Cookie Policy
Vendor documentation
Checked
- ICO: guidance on storage and access technologies
Regulator guidance
Checked
See what your own site is loading
A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.