Tracker library

Pinterest Tag: what it is, what it sets, and how to gate it.

Conversion tracking and audience building for Pinterest ads, installable directly, through a tag manager or through a platform integration.

Vendor
Pinterest
Scanner category
advertising
Consent category
Marketing
Control
Custom script or container tag

What it is

The Pinterest Tag reports events for campaign optimisation and builds audiences from site behaviour. Its enhanced match feature can hash and send customer identifiers, which raises the same questions as any hashed-identifier matching: hashing is a safeguard, not anonymisation.

On a Shopify storefront it usually arrives through the Pinterest sales channel app rather than as a snippet, which means removing it from the theme does not remove it.

What a scan matches

A verification scan drives a real browser and records the outbound requests observed during its configured journeys, so Pinterest Tag is identified by request hosts and paths rather than by source-code claims. Requests on unvisited paths, after unperformed interactions or solely on the server remain outside that observation.

  • pinterest.com and ct.pinterest.com
  • pinimg.com

Cookies are classified by name before domain because many analytics and advertising tags write first-party cookies through the page, which places a vendor-related identifier on your domain. Matching known names helps attribute those values without assuming that every first-party cookie came from your own application.

CookieWhat it is for
_pin_unauthIdentifier for a visitor not signed in to Pinterest
_pinterest_*Pinterest tag state, matched by prefix
_epik, _derived_epikEnhanced match identifiers used for attribution

Controlling it with consent

No named adapter. Gate it as a custom script attached to marketing, or as a container tag. Where it is installed by a platform app, the app is the thing that has to be configured or removed.

If enhanced match is enabled, treat the identifier flow as a separate disclosure question in the privacy notice.

No named adapter: choose the appropriate control

The product ships named adapters for Google Tag Manager, Google Analytics, the Meta and TikTok pixels, and Klaviyo. Choose the control route that fits this technology: a custom HTTPS script declaration for a browser loader, an individual consent condition inside a tag manager, a platform or app setting, or a click-to-load placeholder for a frame. Server-side integrations need their own enforcement because a browser runtime cannot stop them.

What breaks if it is refused: Pinterest campaign measurement and audiences for refusing visitors.

Verifying it

Before consent there should be no request to ct.pinterest.com and no _pin_unauth or _epik. On a storefront, check with the sales-channel app installed rather than in a clean theme.

  • Before a choice: optional tracking endpoints and optional identifiers are absent; any intentionally loaded necessary or functional surface matches the control model described above
  • After rejecting optional categories: optional activity remains absent and the refusal persists across a reload
  • After granting the relevant category: the expected loader or embed appears and the feature behaves normally
  • After withdrawing: new optional activity stops; where the vendor supports a consent signal, verify that the signal is sent as well as checking network behavior

Common questions

Does hashing an email make enhanced match consent-free?

No. A hashed identifier still identifies, which is the point of it. Hashing reduces exposure; it does not take the processing outside the rules.

Sources and verification

Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.

See what your own site is loading

A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.