AccountCraft Journal
Shopify Customer Consent: Test Pixels, Add Account Consent Without Code
Set up Shopify consent, link banner choices to the Customer Privacy API, test pixels and checkout, and surface consent in New Customer Accounts without code.

Turn on your cookie banner and data sharing opt-out page in Settings > Customer privacy, then confirm that your banner or consent platform actually writes those choices back to Shopify using setTrackingConsent or applyTrackingConsentChange. Collect marketing opt-in at checkout or inside New Customer Accounts, and use double opt-in for your email list where your market requires or rewards it.
TL;DR:
- Configure banner behavior by region in Settings > Customer privacy; opt outs reduce the sessions Shopify uses for Network Intelligence and related processing.
- Headless calls require checkoutRootDomain, storefrontRootDomain, storefrontAccessToken, and headlessStorefront; extensions using applyTrackingConsentChange also need collect_buyer_consent or consent may not work.
- Subscribe to visitorConsentCollected because consent can change after page load, and verify declined categories stop pixel requests in the browser network panel.
- Map marketing, analytics, preferences, and data sale choices to matching Shopify fields; server side data sale opt outs also require the dataSaleOptOut GraphQL call.
Table of Contents
- Where to configure Shopify customer privacy settings in your admin
- What the Customer Privacy API actually gives you
- Collecting marketing consent at checkout and in customer accounts
- Connecting a consent platform to Shopify without breaking anything
- Testing consent enforcement across pixels, apps, and custom code
- Practical priorities for merchants setting this up
- Where merchants get consent wrong
- AccountCraft: surface consent inside New Customer Accounts without code
- FAQ
- Sources
- Authoritative docs and helpful links to bookmark
Where to configure Shopify customer privacy settings in your admin
Everything starts in one place: Settings > Customer privacy in your Shopify admin. This is where you enable the cookie banner, turn on the data sharing opt-out page, and generate a starting privacy policy, according to the Shopify Help Center.
A few things matter more than merchants expect once you’re in this screen:
- The regions picker controls where your banner and opt-out page appear, so you can show a cookie banner to visitors in the European Union while showing a data sale opt-out link to visitors in California.
- Each region can carry its own banner behavior, which matters if you sell into multiple countries with different consent laws.
- Turning on these settings changes what you can measure. When a visitor opts out, Shopify marks that activity so it isn’t used for Network Intelligence advertising and related processing, which means your attribution and personalization data shrinks for opted-out sessions.
That tradeoff is the point, not a bug. A banner that properly restricts tracking will reduce your visible analytics. A banner that doesn’t reduce anything probably isn’t wired up correctly, and that’s a sign to check your consent integration rather than celebrate clean numbers.
What the Customer Privacy API actually gives you
The Shopify Customer Privacy API is the browser-based JavaScript layer that reads a visitor’s current consent state and lets you set or update it. It’s documented in full in Shopify’s developer docs, and it’s the piece that connects your banner, your pixels, and your customer records.
You access it through the Shopify.customerPrivacy object once Shopify’s scripts have loaded on the page. Methods and flags you’ll use constantly include:
shouldShowBanner: tells you whether a banner needs to display for the current visitor based on their region and prior choices.currentVisitorConsentandvisitorConsent: read back what a visitor has already agreed to.analyticsProcessingAllowedandmarketingAllowed: boolean checks you run before firing any tracking or marketing script.saleOfDataRegion: tells you whether the current visitor falls under a jurisdiction with sale-of-data opt-out rules.setTrackingConsentandapplyTrackingConsentChange: the two methods that actually write a visitor’s choice back to Shopify.
One detail changes how this works in headless and custom storefronts: according to Shopify’s documentation, calls to setTrackingConsent in custom setups need additional parameters, including checkoutRootDomain, storefrontRootDomain, storefrontAccessToken, and a headlessStorefront flag, so that consent ties correctly across domains that aren’t a standard Shopify theme.
Capability requirements trip up a lot of app developers. applyTrackingConsentChange requires the collect_buyer_consent capability on your app or extension, and certain CustomerPrivacyRegion properties require level 1 protected customer data access, per Shopify’s account UI extensions documentation. Skip either requirement and your extension will silently fail to read or write consent correctly, which is a common cause of banners that display fine but don’t actually gate anything.
One more detail worth building into your integration from day one: the API publishes a visitorConsentCollected event asynchronously. If your scripts only check consent once on page load, you’ll miss updates that arrive after a visitor interacts with your banner later in the session.
Collecting marketing consent at checkout and in customer accounts
You have three practical places to collect marketing consent, and each one feeds a different part of your customer data.
- Turn on marketing opt-in at checkout through Settings > Checkout, where you can also control whether the opt-in checkbox is preselected by region, since several markets prohibit a preselected box.
- Use New Customer Accounts to let shoppers manage their own subscription preferences after the point of purchase, so their consent choice is saved directly to their customer record rather than captured once and forgotten.
- Turn on double opt-in through Settings > Notifications for your email signups. This sends a confirmation message before someone is added to your list, which improves deliverability and is required by law in some countries, according to Shopify’s guidance on collecting customer contact information.
Checkout captures the moment of highest intent. New Customer Accounts captures the ongoing relationship, which matters because consent isn’t a one-time checkbox. A shopper who opts in during checkout should have a clear, easy way to change their mind later without emailing your support inbox.
Connecting a consent platform to Shopify without breaking anything
If you run a dedicated cookie banner or consent management platform, the work is mostly mapping and verification rather than custom code.
- Confirm your consent platform’s Shopify integration toggle is switched on in its own dashboard. Most CMPs built for Shopify, including tools like CookieHub’s Shopify integration, have a dedicated setting that connects to the Customer Privacy API.
- Map your platform’s consent categories to Shopify’s fields directly: marketing to marketing, analytics to analytics, preferences to preferences, and sale of data to sale of data. A mismatch here is the most common reason a banner looks correct but doesn’t restrict the right scripts.
- Check your store with the browser console open. Accept and decline different categories and confirm each choice triggers
setTrackingConsentorapplyTrackingConsentChange, and that your installed apps and pixels actually change behavior in response.
Pro Tip: Test your consent mapping in an incognito window for each region you sell into, since cached consent choices from a previous session can hide a broken integration.
If you’re also working on measurement and search visibility while you tighten consent, tools like BabyLoveGrowth’s Shopify SEO support can help you understand how reduced tracking from opted-out visitors affects the analytics you use for optimization decisions.
Testing consent enforcement across pixels, apps, and custom code
A banner that displays correctly means nothing if your pixels fire anyway. Treat consent enforcement as a release you test, not a setting you flip once.
- Grant
collect_buyer_consentand any required protected customer data access to every app or extension you build or install that touches tracking or customer data. - Gate every tracking call behind
analyticsProcessingAllowedormarketingAllowed, and subscribe to thevisitorConsentCollectedevent so late consent updates are caught, not missed. - Run through the full matrix of test cases: banner visible versus hidden,
visitorConsentundefined versus true versus false,saleOfDataRegionbehavior for applicable visitors, a browser sending a Global Privacy Control signal, and a customer requesting data deletion. - Verify server-side flows too. A sale-of-data opt-out needs the
dataSaleOptOutGraphQL call on the server side in addition to the client-sidesetTrackingConsentflow, since one without the other leaves a compliance gap in your back-end processing. - Keep a QA checklist that runs on both staging and production before every theme or app update, since a theme change can silently remove the script tag that loads your consent layer.
Pro Tip: Open your browser’s network tab and confirm pixel requests stop firing the moment you decline a category. If a request still fires, the gate is cosmetic.
Practical priorities for merchants setting this up
Work in this order: configure the admin settings first, then surface consent choices inside your customer accounts, then test your pixels and scripts. Each layer depends on the one before it, and skipping ahead usually means redoing work later.
![]()
Tools like AccountCraft can help you collect and record preferences through Shopify’s customer privacy APIs, but compliance with GDPR, CCPA, or any other privacy law stays your responsibility as the merchant, confirmed with your own legal counsel where it matters.
Where merchants get consent wrong
The conventional advice treats consent as a banner problem: pick a cookie popup, turn it on, move on. That misses the actual failure point, which is almost never the banner itself. It’s the gap between a banner that displays and a script that respects it.

Most merchants I’d expect to audit have at least one third-party pixel installed years ago that never checks analyticsProcessingAllowed before firing. The banner looks compliant. The behavior underneath it isn’t. That gap is invisible unless you open your console and test it, which is exactly why a test plan matters more than a banner style choice.
The other underrated point: consent isn’t static. A customer who opts in today should be able to see and change that choice later without friction, inside their own account rather than through a support ticket. Treating consent as a one-time checkbox at checkout, rather than an ongoing setting a customer can revisit, is the gap between technically compliant and actually respectful of what a customer agreed to.
— Ivan Signorile
AccountCraft: surface consent inside New Customer Accounts without code
Once your admin settings and Customer Privacy API integration are working, the next question is where customers actually see and manage their preferences. We built AccountCraft to answer that inside New Customer Accounts, using a Block Builder that adds consent options to your account pages without touching code or your theme.

Our privacy consent and SMS consent blocks sit alongside customer fields bound to customer metafields, repeatable record lists, and a built-in wishlist, all rendered conditionally by customer tag, metafield, market, B2B status, or account age, and available in multiple languages. Customer data stays inside Shopify; there is no separate database.
| What you get | How it helps with consent |
|---|---|
| Privacy consent block | Lets customers view and update their consent choices in their account |
| SMS consent block | Captures a separate, explicit opt-in for text messaging |
| Customer fields on metafields | Stores preferences directly on the customer record in Shopify |
| Conditional rendering | Shows the right consent options by market, tag, or account type |
We offer a free plan to get started, with paid plans (Pro, Plus) billed through Shopify for stores that need more block types or customization. For current pricing, see the Shopify App Store listing. Install AccountCraft free from the Shopify App Store and check current plan details there.
FAQ
What is the Shopify Customer Privacy API used for?
The Customer Privacy API is a browser-based tool that reads a visitor’s consent choices and lets your store write updates back to Shopify through methods like setTrackingConsent, according to Shopify’s developer documentation. Every pixel or script on your store should check this state before firing.
How do I turn on the cookie banner in Shopify?
Go to Settings > Customer privacy in your Shopify admin and enable the cookie banner and data sharing opt-out page for the regions you sell into, as described in the Shopify Help Center. You can configure different banner behavior for different regions from the same screen.
Does enabling a cookie banner reduce my Shopify analytics?
Yes. When a visitor opts out through your banner, Shopify marks that session so it isn’t used for Network Intelligence advertising and related processing, which reduces the data available for analytics and personalization on opted-out traffic.
Does AccountCraft make my store GDPR compliant?
AccountCraft helps you collect, record, and honor customer consent through Shopify’s customer privacy APIs by surfacing consent options inside New Customer Accounts. Compliance with GDPR or any other privacy law is the merchant’s own responsibility, and consulting legal counsel is recommended.
What is double opt-in and do I need it on Shopify?
Double opt-in sends a confirmation message before a new subscriber is added to your email list, which improves list quality and is required by law in some countries, according to Shopify’s guidance on customer contact information. You can turn it on through Settings > Notifications.
Sources
- Customer privacy — Shopify developer docs
- Customer privacy settings — Shopify Help Center
- Collect and manage customer contact information — Shopify Help Center
Authoritative docs and helpful links to bookmark
- Customer privacy API documentation, Shopify developer docs
- Customer privacy settings, Shopify Help Center
- Collecting customer contact information and marketing consent, Shopify Help Center
- Shopify Network Intelligence requirements, Shopify Help Center
- AccountCraft product page, for implementation details