Skip to main content

Manual Cookie Consent Evidence Audit for a US Ecommerce Beauty Brand

Auditzo reviewed how a US ecommerce beauty website behaved before consent, after a visitor accepted cookies, and after a visitor declined cookies.

The audit went beyond a basic cookie scan. It captured technical evidence across real browsing journeys using screenshots, cookie snapshots, HAR files, browser storage review, third-party domain analysis, timeline mapping, and evidence-linked findings.

The final output helped the client’s technical, privacy, ecommerce, marketing operations, and legal review teams understand what the website was loading, when it appeared, and which items required further purpose classification.

Request a Manual Evidence Review

By Auditzo June 19, 2026

Executive Summary

A US ecommerce beauty brand needed a clearer view of its website’s cookie consent behavior. The client did not only want to know which cookies existed. They wanted to understand what happened across different consent states and how each observation could be verified.

Auditzo performed a manual cookie consent evidence audit across three tested states:

  • Pre-consent homepage baseline before any visitor choice
  • Accepted-consent journey after the visitor selected Accept
  • Rejected-consent journey after the visitor selected Decline

The audit reviewed cookies, browser storage, HAR/network activity, third-party domains, screenshots, and checkout-stage behavior before payment submission.

The rejected-consent journey showed a materially reduced cookie footprint compared with the accepted-consent journey. However, some cookies, browser storage entries, and third-party/vendor network activity were still observed after Decline and required purpose classification.

Auditzo did not provide legal advice or a legal conclusion. The deliverable was a technical evidence package designed to support privacy, compliance, ecommerce, technical, and legal review.

Auditzo position: This case study describes technical evidence and consent-state behavior. A cookie, script, storage entry, or third-party domain observed after Decline does not automatically mean a legal violation. These items should be reviewed by technical, privacy, and legal/compliance teams based on purpose, vendor, consent category, and business necessity.

The Client

The client was a US-based ecommerce beauty brand with a modern online storefront and active marketing, analytics, checkout, payment, and vendor integrations.

The website included a cookie consent banner, product browsing journey, cart flow, checkout before payment, third-party scripts, browser storage activity, and vendor network requests.

For confidentiality, the client name is anonymized in this public case study.

The client name and identifying technical details are intentionally anonymized to protect confidentiality while preserving the audit methodology and business outcome.

The Challenge

The client needed to answer a practical question:

What does the website actually load before consent, after Accept, and after Decline?

A basic cookie scan could show a list of cookies, but it could not fully explain the journey or provide enough evidence for internal review.

The client needed clarity around:

  • Which cookies appeared before the visitor made any consent choice
  • Which cookies appeared after Accept
  • Which cookies remained or appeared after Decline
  • Which cookies appeared during ecommerce steps such as product, cart, or checkout
  • Which browser storage values remained active
  • Which third-party domains were contacted
  • Which items may create risk and should be reviewed further
  • Which evidence supported each finding

The goal was not to label every item as compliant or non-compliant. The goal was to create a structured evidence base that could support technical, privacy, and legal review.

Best For

This type of manual evidence review is best suited for teams that need more than a basic cookie list.

  • Ecommerce brands reviewing cookie consent behavior
  • Teams concerned about CCPA/CPRA or CIPA-oriented website tracking risk
  • Privacy teams that need technical evidence before legal review
  • Marketing operations teams reviewing CMP and tag firing behavior
  • Agencies supporting ecommerce clients with consent and tracking reviews
  • Legal or compliance teams that need audit-ready evidence rather than assumptions

Request a Manual Evidence Review

Automated cookie scans can be useful for initial visibility, but they often lack consent-state and journey context.

A scanner may detect a cookie, but it may not clearly show:

  • When the cookie appeared
  • Whether the visitor had accepted or declined consent
  • Whether the cookie appeared on the homepage, product page, cart, or checkout
  • Whether browser localStorage or sessionStorage was also involved
  • Whether a third-party domain was contacted without setting a cookie
  • Whether the evidence is traceable enough for legal or compliance review

Auditzo used a manual evidence-based process to compare website behavior across consent states and preserve audit-ready evidence.

For brands that need deeper review, this type of workflow can support a cookie audit, a CCPA/CPRA audit, or a CIPA Section 638.51 website audit.

Comparison of a basic cookie scan and Auditzo manual evidence based cookie consent audit
A basic cookie scan lists cookies. Auditzo’s manual evidence method compares behavior across consent states and maps findings to evidence.
Basic Cookie Scan Auditzo Manual Evidence Audit
Lists cookies Compares cookies across pre-consent, Accept, and Decline
Limited journey context Reviews homepage, product page, cart, and checkout behavior
Often lacks supporting proof Includes screenshots, HAR files, cookie CSVs, and storage evidence
May not explain timing Shows when evidence was captured during the user journey
Hard to verify Maps findings to evidence IDs and file references
Usually technical-only Explains findings in practical language for broader teams
Basic output Provides report, manifest, timeline, workbooks, and findings register

Audit Scope

Auditzo reviewed three consent-state journeys.

Session Consent State Purpose
Session A Pre-consent baseline Review homepage behavior before the visitor selected Accept or Decline
Session B Accepted consent journey Review behavior after the visitor selected Accept
Session C Rejected consent journey Review behavior after the visitor selected Decline

The tested ecommerce journey included:

  • Homepage
  • Product page
  • Cart
  • Checkout before payment submission

No payment information was submitted, and no order was placed.

Auditzo Manual Evidence Method

The Auditzo Manual Evidence Method is designed to show what happened, when it happened, and which evidence supports the observation.

Auditzo manual evidence workflow for cookie consent and third party tracking review
Auditzo converts raw browsing evidence into a structured audit-ready report and evidence package.

The methodology included:

  • Clean browser sessions
  • Incognito browsing
  • US-based test environment
  • Browser IP geolocation proof
  • Ad and tracker blocking disabled during testing
  • Browser DevTools opened before navigation
  • Network Preserve Log enabled
  • Browser cache disabled during capture
  • HAR exports with content
  • Cookie CSV snapshots
  • Browser localStorage screenshots
  • Browser sessionStorage screenshots
  • Journey screenshots
  • Session notes
  • Evidence mapping

This process helped Auditzo compare website behavior across different consent states and preserve supporting evidence for later review.

For teams that need a broader review of cookie consent rules, Auditzo also provides guidance around GDPR cookie consent requirements and practical website tracking compliance review.

Evidence Collected

Auditzo created a structured evidence package containing:

  • Environment proof screenshots
  • Homepage screenshots before consent
  • Homepage screenshots after Accept
  • Homepage screenshots after Decline
  • Product page screenshots
  • Cart screenshots
  • Checkout screenshots before payment
  • Network log screenshots
  • HAR files for each consent state
  • Cookie CSV snapshots
  • Cookie screenshots
  • localStorage screenshots
  • sessionStorage screenshots
  • Session notes
  • Cookie comparison workbook
  • Third-party domain summary workbook
  • Evidence manifest
  • Timeline workbook
  • Findings register
  • Final PDF report

Each evidence file was mapped to an evidence ID so reviewers could trace report statements back to source artifacts.

Evidence Prefix Meaning
SS Screenshot evidence
CK Cookie snapshot evidence
HAR Browser network capture or HAR export
ST Browser storage screenshot
ENV Environment proof

Teams reviewing similar issues can also compare this approach with Auditzo’s sample website privacy compliance audit report to understand how evidence-backed reporting supports internal review.

Key Findings

The audit identified several evidence-backed technical findings. These findings were written as review items, not legal conclusions.

Key Finding 1: The Pre-Consent Baseline Was Limited but Still Required Purpose Review

Before the visitor made any consent choice, Auditzo observed a limited set of cookies during the homepage baseline.

Some appeared related to ecommerce functionality, cart continuity, currency, localization, or site operation. However, not every cookie purpose could be confirmed from the cookie name alone.

Why this mattered: Cookies that appear before a visitor makes any consent choice should be carefully reviewed. Some may be strictly necessary. Others may require closer classification.

What Auditzo concluded technically: Auditzo treated the pre-consent baseline as a starting point for comparison. The recommended next step was to confirm the purpose, vendor ownership, and consent category for each pre-consent cookie.

Key Finding 2: Accepting Consent Expanded the Cookie Footprint

After the visitor selected Accept, the website’s cookie footprint expanded across the tested journey.

Additional cookies appeared during homepage, product, cart, and checkout-before-payment steps.

Several observed identifiers appeared consistent with analytics, advertising, marketing, ecommerce analytics, or measurement-style services.

Why this mattered: This showed that the consent choice affected site behavior. When a visitor accepts cookies, it may be expected that non-essential analytics or marketing systems become active, provided they are properly disclosed and configured.

What Auditzo concluded technically: Auditzo treated this as expected behavior, not as a negative finding by itself. The key review question was whether accepted-state cookies and scripts were properly categorized, disclosed, and controlled through the consent mechanism.

Key Finding 3: Decline Suppressed Many Accepted-State Identifiers

After the visitor selected Decline, many cookies observed in the accepted-consent journey were not observed in the rejected-consent journey.

This was a positive technical observation.

Why this mattered: This suggested that the consent mechanism appeared to be suppressing many analytics and marketing-style identifiers after Decline.

The rejected-consent journey showed a materially reduced cookie footprint compared with the accepted-consent journey.

What Auditzo concluded technically: Auditzo described this as a technical observation only and did not present it as legal compliance certification.

Key Finding 4: Some Cookies Appeared After Decline That Were Not Present in the Pre-Consent Baseline

During the rejected-consent journey, some cookies appeared that were not present in the original pre-consent homepage baseline.

However, these cookies were also observed during the accepted-consent journey. This distinction matters because they should not be described as “reject-only” cookies without deeper evidence.

Why this mattered: The more accurate interpretation is that these cookies were observed during the rejected-consent journey but were not present in the pre-consent homepage baseline. Their purpose should be reviewed.

Some may be required for:

  • Security
  • Bot protection
  • Cart continuity
  • Checkout
  • Payment support
  • Ecommerce functionality
  • Consent-state handling
  • Localization

Others may require closer review if they are analytics, marketing, or pixel-related.

What Auditzo concluded technically: Auditzo recommended purpose classification and CMP rule review. The finding was intentionally written without calling the cookies violations, illegal, or non-compliant.

Key Finding 5: Browser Storage Remained Active After Decline

Auditzo reviewed browser localStorage and sessionStorage in addition to cookies.

This was important because modern websites often use browser storage for more than basic page functionality.

Browser storage may hold values related to:

  • Consent state
  • Cart state
  • Checkout state
  • Session continuity
  • Vendor scripts
  • Journey history
  • Page visit behavior
  • Marketing or analytics systems

Why this mattered: Cookie review alone does not always show the full picture. Browser storage should be reviewed alongside cookies and HAR/network evidence.

What Auditzo concluded technically: Auditzo found that browser storage entries remained after Decline and recommended reviewing storage keys and purposes. Some storage may be necessary for site functionality. Other entries may require vendor-purpose classification.

Key Finding 6: Third-Party Network Activity Continued After Decline

Auditzo exported HAR files for each consent state.

A HAR file records browser network requests and helps identify which domains and vendors were contacted during a browsing session.

The rejected-consent journey still showed third-party/vendor network activity.

Why this mattered: A domain appearing in HAR evidence does not automatically mean a cookie was stored, personal information was shared, tracking occurred, or a legal issue exists.

It means the browser contacted that domain during the tested session.

What Auditzo concluded technically: Auditzo recommended reviewing each relevant domain by vendor, purpose, consent category, whether cookies were sent, whether cookies were set, and whether the domain should remain active after Decline.

This type of review can help ecommerce teams prepare for a CIPA Section 638.51 website audit or a broader CCPA/CPRA audit without making unsupported legal claims.

Key Finding 7: Checkout Required Separate Review

Checkout introduced additional operational context.

Checkout-stage activity may involve:

  • Ecommerce platform infrastructure
  • Cart continuity
  • Payment options
  • Fraud prevention
  • Security
  • Shipping or tax logic
  • Order-flow support

Why this mattered: Not every checkout-related domain, cookie, or browser storage value should be treated the same as analytics or marketing tracking.

Some checkout infrastructure may be necessary even after a visitor declines non-essential cookies.

What Auditzo concluded technically: Auditzo recommended reviewing checkout separately from general marketing and analytics behavior. This helped keep the audit accurate, useful, and fair.

Deliverables Provided

Auditzo prepared a complete evidence-backed audit package for the client.

Final PDF report

The report included an executive summary, scope, methodology, consent journey timeline, cookie evidence summary, browser storage observations, HAR/network findings, third-party domain review, findings register, recommended actions, limitations, evidence references, and a plain-English glossary.

Cookie comparison workbook

This workbook normalized cookie snapshots across consent states. It helped reviewers understand cookies observed before consent, after Accept, after Decline, and after Decline but not present in the pre-consent baseline.

Third-party domain summary workbook

This workbook summarized HAR/network activity across consent states. It helped reviewers identify domains observed before consent, after Accept, after Decline, and domains requiring closer review.

Evidence manifest

The evidence manifest mapped each evidence ID to file name, file location, evidence type, consent state, description, report use, and review status.

Timeline workbook

The timeline workbook showed the chronological sequence of environment setup, consent action, screenshots, cookie captures, storage captures, and HAR exports.

Findings register

The findings register connected each report finding to supporting evidence, interpretation, recommended action, and wording guardrails.

Business Outcome

The client received a structured technical evidence package that could be reviewed by multiple teams.

The audit helped the client understand:

  • What loaded before any consent choice
  • What changed after Accept
  • What remained after Decline
  • Which cookies needed purpose classification
  • Which third-party domains required review
  • Which storage entries remained active
  • Which checkout-stage behavior may be operationally necessary
  • Which evidence supported each finding

Instead of receiving a simple cookie list, the client received an audit-ready technical evidence package designed to support internal review and follow-up action.

What Made This Audit Different

Auditzo did not treat the audit as a simple scanner output.

The review followed a traceable evidence workflow:

  1. Controlled browser setup
  2. Consent-state separation
  3. Real ecommerce journey testing
  4. Screenshot-backed documentation
  5. Cookie CSV capture
  6. HAR/network capture
  7. Browser storage review
  8. Normalized comparison workbooks
  9. Evidence manifest
  10. Findings register
  11. Plain-English final report

This made the output usable by technical teams, privacy teams, legal teams, ecommerce teams, marketing operations teams, consent management platform owners, and vendor management teams.

If your team needs evidence-backed documentation for privacy review, see Auditzo’s digital evidence for compliance approach.

Based on this type of audit, ecommerce brands should review:

  1. Cookies observed before any consent choice
  2. Cookies enabled after Accept
  3. Cookies observed after Decline
  4. Cookies observed after Decline but not present in the pre-consent baseline
  5. Third-party domains active after Decline
  6. Browser localStorage and sessionStorage entries
  7. Checkout, payment, and fraud-prevention infrastructure
  8. Consent management platform category mapping
  9. Tag firing rules
  10. Vendor-purpose classification

A cookie, storage item, or domain observed after Decline should not automatically be treated as a compliance issue.

The correct next step is to confirm whether it is strictly necessary, functional, security-related, checkout-related, analytics-related, or marketing-related.

How Auditzo Helps Teams Move From Assumption to Evidence

A basic cookie scan tells you what cookies may exist.

An Auditzo manual evidence audit can help show:

  • When cookies appeared
  • Under which consent state they appeared
  • Which journey step triggered them
  • Whether they appeared before consent, after Accept, or after Decline
  • Whether browser storage was involved
  • Whether third-party network activity occurred
  • Which evidence supports each observation

This helps ecommerce, privacy, and legal teams move from assumption to evidence.

To see how this applies to your website, request a manual evidence review.

Auditzo provides technical evidence and compliance-oriented observations.

Auditzo does not provide legal advice, legal certification, or a final determination of compliance or non-compliance with CCPA/CPRA, CIPA, GDPR/ePrivacy, or any other law.

Any legal interpretation should be reviewed by qualified legal counsel.

FAQ

What is a manual cookie consent evidence audit?

A manual cookie consent evidence audit reviews how a website behaves before consent, after Accept, and after Decline. It collects screenshots, cookie snapshots, HAR files, browser storage evidence, and comparison workbooks so technical, privacy, and legal teams can trace findings back to source evidence.

How is this different from a basic cookie scan?

A basic cookie scan usually lists cookies. A manual evidence audit compares behavior across consent states and user journeys, then maps each finding back to screenshots, HAR files, cookie CSVs, browser storage evidence, and supporting workbooks.

Does a cookie after Decline automatically mean non-compliance?

No. A cookie observed after Decline is not automatically a compliance issue. Some cookies may be required for security, checkout, cart continuity, localization, payment support, fraud prevention, or site functionality. Each cookie should be classified by purpose, vendor, and consent category.

Why does HAR evidence matter in a cookie consent audit?

HAR evidence shows which domains and vendors the browser contacted during a tested session. It helps reviewers understand third-party network activity, but it should be interpreted together with cookie snapshots and browser storage evidence.

Why should browser storage be reviewed?

Modern websites may use localStorage and sessionStorage in addition to cookies. Browser storage can hold consent state, cart state, checkout state, vendor values, or journey-related data, so it should be reviewed as part of a complete tracking evidence audit.

Can Auditzo audit ecommerce checkout behavior?

Yes. Auditzo can review checkout-stage behavior before payment submission to identify cookies, browser storage, and third-party network activity that may be operational, security-related, payment-related, or non-essential.

Does Auditzo provide legal advice?

No. Auditzo provides technical evidence and compliance-oriented observations. Legal interpretation should be reviewed by qualified legal counsel.

What evidence is included in an Auditzo manual evidence review?

Depending on scope, Auditzo may provide screenshots, HAR files, cookie CSVs, browser storage evidence, third-party domain summaries, timeline workbooks, evidence manifests, findings registers, and a final report.

Need to Know What Your Website Loads After Cookie Consent?

Auditzo helps ecommerce and digital brands understand what their websites load before consent, after Accept, and after Decline.

Our manual evidence reviews can support cookie consent testing, CCPA/CPRA-oriented cookie review, CIPA-oriented website tracking review, HAR/network evidence capture, browser storage review, third-party domain analysis, screenshot-backed evidence, evidence manifests, and audit-ready reports.

Request a Manual Evidence Review

You can also explore Auditzo’s cookie audit tool, website tracking compliance resources, or Auditzo pricing.

Share: