Manual Cookie Consent Evidence Audit for a US Ecommerce Beauty Brand
Auditzo reviewed how a US ecommerce beauty website behaved before consent, after a visitor accepted cookies, and after a visitor declined cookies.
The audit went beyond a basic cookie scan. It captured technical evidence across real browsing journeys using screenshots, cookie snapshots, HAR files, browser storage review, third-party domain analysis, timeline mapping, and evidence-linked findings.
The final output helped the client’s technical, privacy, ecommerce, marketing operations, and legal review teams understand what the website was loading, when it appeared, and which items required further purpose classification.
Executive Summary
A US ecommerce beauty brand needed a clearer view of its website’s cookie consent behavior. The client did not only want to know which cookies existed. They wanted to understand what happened across different consent states and how each observation could be verified.
Auditzo performed a manual cookie consent evidence audit across three tested states:
- Pre-consent homepage baseline before any visitor choice
- Accepted-consent journey after the visitor selected Accept
- Rejected-consent journey after the visitor selected Decline
The audit reviewed cookies, browser storage, HAR/network activity, third-party domains, screenshots, and checkout-stage behavior before payment submission.
The rejected-consent journey showed a materially reduced cookie footprint compared with the accepted-consent journey. However, some cookies, browser storage entries, and third-party/vendor network activity were still observed after Decline and required purpose classification.
Auditzo did not provide legal advice or a legal conclusion. The deliverable was a technical evidence package designed to support privacy, compliance, ecommerce, technical, and legal review.
Auditzo position: This case study describes technical evidence and consent-state behavior. A cookie, script, storage entry, or third-party domain observed after Decline does not automatically mean a legal violation. These items should be reviewed by technical, privacy, and legal/compliance teams based on purpose, vendor, consent category, and business necessity.
The Client
The client was a US-based ecommerce beauty brand with a modern online storefront and active marketing, analytics, checkout, payment, and vendor integrations.
The website included a cookie consent banner, product browsing journey, cart flow, checkout before payment, third-party scripts, browser storage activity, and vendor network requests.
For confidentiality, the client name is anonymized in this public case study.
The client name and identifying technical details are intentionally anonymized to protect confidentiality while preserving the audit methodology and business outcome.
The Challenge
The client needed to answer a practical question:
What does the website actually load before consent, after Accept, and after Decline?
A basic cookie scan could show a list of cookies, but it could not fully explain the journey or provide enough evidence for internal review.
The client needed clarity around:
- Which cookies appeared before the visitor made any consent choice
- Which cookies appeared after Accept
- Which cookies remained or appeared after Decline
- Which cookies appeared during ecommerce steps such as product, cart, or checkout
- Which browser storage values remained active
- Which third-party domains were contacted
- Which items may create risk and should be reviewed further
- Which evidence supported each finding
The goal was not to label every item as compliant or non-compliant. The goal was to create a structured evidence base that could support technical, privacy, and legal review.
Best For
This type of manual evidence review is best suited for teams that need more than a basic cookie list.
- Ecommerce brands reviewing cookie consent behavior
- Teams concerned about CCPA/CPRA or CIPA-oriented website tracking risk
- Privacy teams that need technical evidence before legal review
- Marketing operations teams reviewing CMP and tag firing behavior
- Agencies supporting ecommerce clients with consent and tracking reviews
- Legal or compliance teams that need audit-ready evidence rather than assumptions
Request a Manual Evidence Review
Why a Manual Cookie Consent Audit Was Needed
Automated cookie scans can be useful for initial visibility, but they often lack consent-state and journey context.
A scanner may detect a cookie, but it may not clearly show:
- When the cookie appeared
- Whether the visitor had accepted or declined consent
- Whether the cookie appeared on the homepage, product page, cart, or checkout
- Whether browser localStorage or sessionStorage was also involved
- Whether a third-party domain was contacted without setting a cookie
- Whether the evidence is traceable enough for legal or compliance review
Auditzo used a manual evidence-based process to compare website behavior across consent states and preserve audit-ready evidence.
For brands that need deeper review, this type of workflow can support a cookie audit, a CCPA/CPRA audit, or a CIPA Section 638.51 website audit.
Basic Cookie Scan vs Auditzo Manual Evidence Audit
| Basic Cookie Scan | Auditzo Manual Evidence Audit |
|---|---|
| Lists cookies | Compares cookies across pre-consent, Accept, and Decline |
| Limited journey context | Reviews homepage, product page, cart, and checkout behavior |
| Often lacks supporting proof | Includes screenshots, HAR files, cookie CSVs, and storage evidence |
| May not explain timing | Shows when evidence was captured during the user journey |
| Hard to verify | Maps findings to evidence IDs and file references |
| Usually technical-only | Explains findings in practical language for broader teams |
| Basic output | Provides report, manifest, timeline, workbooks, and findings register |
Audit Scope
Auditzo reviewed three consent-state journeys.
| Session | Consent State | Purpose |
|---|---|---|
| Session A | Pre-consent baseline | Review homepage behavior before the visitor selected Accept or Decline |
| Session B | Accepted consent journey | Review behavior after the visitor selected Accept |
| Session C | Rejected consent journey | Review behavior after the visitor selected Decline |
The tested ecommerce journey included:
- Homepage
- Product page
- Cart
- Checkout before payment submission
No payment information was submitted, and no order was placed.
Auditzo Manual Evidence Method
The Auditzo Manual Evidence Method is designed to show what happened, when it happened, and which evidence supports the observation.
The methodology included:
- Clean browser sessions
- Incognito browsing
- US-based test environment
- Browser IP geolocation proof
- Ad and tracker blocking disabled during testing
- Browser DevTools opened before navigation
- Network Preserve Log enabled
- Browser cache disabled during capture
- HAR exports with content
- Cookie CSV snapshots
- Browser localStorage screenshots
- Browser sessionStorage screenshots
- Journey screenshots
- Session notes
- Evidence mapping
This process helped Auditzo compare website behavior across different consent states and preserve supporting evidence for later review.
For teams that need a broader review of cookie consent rules, Auditzo also provides guidance around GDPR cookie consent requirements and practical website tracking compliance review.
Evidence Collected
Auditzo created a structured evidence package containing:
- Environment proof screenshots
- Homepage screenshots before consent
- Homepage screenshots after Accept
- Homepage screenshots after Decline
- Product page screenshots
- Cart screenshots
- Checkout screenshots before payment
- Network log screenshots
- HAR files for each consent state
- Cookie CSV snapshots
- Cookie screenshots
- localStorage screenshots
- sessionStorage screenshots
- Session notes
- Cookie comparison workbook
- Third-party domain summary workbook
- Evidence manifest
- Timeline workbook
- Findings register
- Final PDF report
Each evidence file was mapped to an evidence ID so reviewers could trace report statements back to source artifacts.
| Evidence Prefix | Meaning |
|---|---|
| SS | Screenshot evidence |
| CK | Cookie snapshot evidence |
| HAR | Browser network capture or HAR export |
| ST | Browser storage screenshot |
| ENV | Environment proof |
Teams reviewing similar issues can also compare this approach with Auditzo’s sample website privacy compliance audit report to understand how evidence-backed reporting supports internal review.
Key Findings
The audit identified several evidence-backed technical findings. These findings were written as review items, not legal conclusions.
Key Finding 1: The Pre-Consent Baseline Was Limited but Still Required Purpose Review
Before the visitor made any consent choice, Auditzo observed a limited set of cookies during the homepage baseline.
Some appeared related to ecommerce functionality, cart continuity, currency, localization, or site operation. However, not every cookie purpose could be confirmed from the cookie name alone.
Why this mattered: Cookies that appear before a visitor makes any consent choice should be carefully reviewed. Some may be strictly necessary. Others may require closer classification.
What Auditzo concluded technically: Auditzo treated the pre-consent baseline as a starting point for comparison. The recommended next step was to confirm the purpose, vendor ownership, and consent category for each pre-consent cookie.
Key Finding 2: Accepting Consent Expanded the Cookie Footprint
After the visitor selected Accept, the website’s cookie footprint expanded across the tested journey.
Additional cookies appeared during homepage, product, cart, and checkout-before-payment steps.
Several observed identifiers appeared consistent with analytics, advertising, marketing, ecommerce analytics, or measurement-style services.
Why this mattered: This showed that the consent choice affected site behavior. When a visitor accepts cookies, it may be expected that non-essential analytics or marketing systems become active, provided they are properly disclosed and configured.
What Auditzo concluded technically: Auditzo treated this as expected behavior, not as a negative finding by itself. The key review question was whether accepted-state cookies and scripts were properly categorized, disclosed, and controlled through the consent mechanism.
Key Finding 3: Decline Suppressed Many Accepted-State Identifiers
After the visitor selected Decline, many cookies observed in the accepted-consent journey were not observed in the rejected-consent journey.
This was a positive technical observation.
Why this mattered: This suggested that the consent mechanism appeared to be suppressing many analytics and marketing-style identifiers after Decline.
The rejected-consent journey showed a materially reduced cookie footprint compared with the accepted-consent journey.
What Auditzo concluded technically: Auditzo described this as a technical observation only and did not present it as legal compliance certification.
Key Finding 4: Some Cookies Appeared After Decline That Were Not Present in the Pre-Consent Baseline
During the rejected-consent journey, some cookies appeared that were not present in the original pre-consent homepage baseline.
However, these cookies were also observed during the accepted-consent journey. This distinction matters because they should not be described as “reject-only” cookies without deeper evidence.
Why this mattered: The more accurate interpretation is that these cookies were observed during the rejected-consent journey but were not present in the pre-consent homepage baseline. Their purpose should be reviewed.
Some may be required for:
- Security
- Bot protection
- Cart continuity
- Checkout
- Payment support
- Ecommerce functionality
- Consent-state handling
- Localization
Others may require closer review if they are analytics, marketing, or pixel-related.
What Auditzo concluded technically: Auditzo recommended purpose classification and CMP rule review. The finding was intentionally written without calling the cookies violations, illegal, or non-compliant.
Key Finding 5: Browser Storage Remained Active After Decline
Auditzo reviewed browser localStorage and sessionStorage in addition to cookies.
This was important because modern websites often use browser storage for more than basic page functionality.
Browser storage may hold values related to:
- Consent state
- Cart state
- Checkout state
- Session continuity
- Vendor scripts
- Journey history
- Page visit behavior
- Marketing or analytics systems
Why this mattered: Cookie review alone does not always show the full picture. Browser storage should be reviewed alongside cookies and HAR/network evidence.
What Auditzo concluded technically: Auditzo found that browser storage entries remained after Decline and recommended reviewing storage keys and purposes. Some storage may be necessary for site functionality. Other entries may require vendor-purpose classification.
Key Finding 6: Third-Party Network Activity Continued After Decline
Auditzo exported HAR files for each consent state.
A HAR file records browser network requests and helps identify which domains and vendors were contacted during a browsing session.
The rejected-consent journey still showed third-party/vendor network activity.
Why this mattered: A domain appearing in HAR evidence does not automatically mean a cookie was stored, personal information was shared, tracking occurred, or a legal issue exists.
It means the browser contacted that domain during the tested session.
What Auditzo concluded technically: Auditzo recommended reviewing each relevant domain by vendor, purpose, consent category, whether cookies were sent, whether cookies were set, and whether the domain should remain active after Decline.
This type of review can help ecommerce teams prepare for a CIPA Section 638.51 website audit or a broader CCPA/CPRA audit without making unsupported legal claims.
Key Finding 7: Checkout Required Separate Review
Checkout introduced additional operational context.
Checkout-stage activity may involve:
- Ecommerce platform infrastructure
- Cart continuity
- Payment options
- Fraud prevention
- Security
- Shipping or tax logic
- Order-flow support
Why this mattered: Not every checkout-related domain, cookie, or browser storage value should be treated the same as analytics or marketing tracking.
Some checkout infrastructure may be necessary even after a visitor declines non-essential cookies.
What Auditzo concluded technically: Auditzo recommended reviewing checkout separately from general marketing and analytics behavior. This helped keep the audit accurate, useful, and fair.
Deliverables Provided
Auditzo prepared a complete evidence-backed audit package for the client.
Final PDF report
The report included an executive summary, scope, methodology, consent journey timeline, cookie evidence summary, browser storage observations, HAR/network findings, third-party domain review, findings register, recommended actions, limitations, evidence references, and a plain-English glossary.
Cookie comparison workbook
This workbook normalized cookie snapshots across consent states. It helped reviewers understand cookies observed before consent, after Accept, after Decline, and after Decline but not present in the pre-consent baseline.
Third-party domain summary workbook
This workbook summarized HAR/network activity across consent states. It helped reviewers identify domains observed before consent, after Accept, after Decline, and domains requiring closer review.
Evidence manifest
The evidence manifest mapped each evidence ID to file name, file location, evidence type, consent state, description, report use, and review status.
Timeline workbook
The timeline workbook showed the chronological sequence of environment setup, consent action, screenshots, cookie captures, storage captures, and HAR exports.
Findings register
The findings register connected each report finding to supporting evidence, interpretation, recommended action, and wording guardrails.
Business Outcome
The client received a structured technical evidence package that could be reviewed by multiple teams.
The audit helped the client understand:
- What loaded before any consent choice
- What changed after Accept
- What remained after Decline
- Which cookies needed purpose classification
- Which third-party domains required review
- Which storage entries remained active
- Which checkout-stage behavior may be operationally necessary
- Which evidence supported each finding
Instead of receiving a simple cookie list, the client received an audit-ready technical evidence package designed to support internal review and follow-up action.
What Made This Audit Different
Auditzo did not treat the audit as a simple scanner output.
The review followed a traceable evidence workflow:
- Controlled browser setup
- Consent-state separation
- Real ecommerce journey testing
- Screenshot-backed documentation
- Cookie CSV capture
- HAR/network capture
- Browser storage review
- Normalized comparison workbooks
- Evidence manifest
- Findings register
- Plain-English final report
This made the output usable by technical teams, privacy teams, legal teams, ecommerce teams, marketing operations teams, consent management platform owners, and vendor management teams.
If your team needs evidence-backed documentation for privacy review, see Auditzo’s digital evidence for compliance approach.
Recommended Next Steps for Ecommerce Brands
Based on this type of audit, ecommerce brands should review:
- Cookies observed before any consent choice
- Cookies enabled after Accept
- Cookies observed after Decline
- Cookies observed after Decline but not present in the pre-consent baseline
- Third-party domains active after Decline
- Browser localStorage and sessionStorage entries
- Checkout, payment, and fraud-prevention infrastructure
- Consent management platform category mapping
- Tag firing rules
- Vendor-purpose classification
A cookie, storage item, or domain observed after Decline should not automatically be treated as a compliance issue.
The correct next step is to confirm whether it is strictly necessary, functional, security-related, checkout-related, analytics-related, or marketing-related.
How Auditzo Helps Teams Move From Assumption to Evidence
A basic cookie scan tells you what cookies may exist.
An Auditzo manual evidence audit can help show:
- When cookies appeared
- Under which consent state they appeared
- Which journey step triggered them
- Whether they appeared before consent, after Accept, or after Decline
- Whether browser storage was involved
- Whether third-party network activity occurred
- Which evidence supports each observation
This helps ecommerce, privacy, and legal teams move from assumption to evidence.
To see how this applies to your website, request a manual evidence review.
Important Legal Boundary
Auditzo provides technical evidence and compliance-oriented observations.
Auditzo does not provide legal advice, legal certification, or a final determination of compliance or non-compliance with CCPA/CPRA, CIPA, GDPR/ePrivacy, or any other law.
Any legal interpretation should be reviewed by qualified legal counsel.
FAQ
What is a manual cookie consent evidence audit?
A manual cookie consent evidence audit reviews how a website behaves before consent, after Accept, and after Decline. It collects screenshots, cookie snapshots, HAR files, browser storage evidence, and comparison workbooks so technical, privacy, and legal teams can trace findings back to source evidence.
How is this different from a basic cookie scan?
A basic cookie scan usually lists cookies. A manual evidence audit compares behavior across consent states and user journeys, then maps each finding back to screenshots, HAR files, cookie CSVs, browser storage evidence, and supporting workbooks.
Does a cookie after Decline automatically mean non-compliance?
No. A cookie observed after Decline is not automatically a compliance issue. Some cookies may be required for security, checkout, cart continuity, localization, payment support, fraud prevention, or site functionality. Each cookie should be classified by purpose, vendor, and consent category.
Why does HAR evidence matter in a cookie consent audit?
HAR evidence shows which domains and vendors the browser contacted during a tested session. It helps reviewers understand third-party network activity, but it should be interpreted together with cookie snapshots and browser storage evidence.
Why should browser storage be reviewed?
Modern websites may use localStorage and sessionStorage in addition to cookies. Browser storage can hold consent state, cart state, checkout state, vendor values, or journey-related data, so it should be reviewed as part of a complete tracking evidence audit.
Can Auditzo audit ecommerce checkout behavior?
Yes. Auditzo can review checkout-stage behavior before payment submission to identify cookies, browser storage, and third-party network activity that may be operational, security-related, payment-related, or non-essential.
Does Auditzo provide legal advice?
No. Auditzo provides technical evidence and compliance-oriented observations. Legal interpretation should be reviewed by qualified legal counsel.
What evidence is included in an Auditzo manual evidence review?
Depending on scope, Auditzo may provide screenshots, HAR files, cookie CSVs, browser storage evidence, third-party domain summaries, timeline workbooks, evidence manifests, findings registers, and a final report.
Need to Know What Your Website Loads After Cookie Consent?
Auditzo helps ecommerce and digital brands understand what their websites load before consent, after Accept, and after Decline.
Our manual evidence reviews can support cookie consent testing, CCPA/CPRA-oriented cookie review, CIPA-oriented website tracking review, HAR/network evidence capture, browser storage review, third-party domain analysis, screenshot-backed evidence, evidence manifests, and audit-ready reports.
Request a Manual Evidence Review
You can also explore Auditzo’s cookie audit tool, website tracking compliance resources, or Auditzo pricing.
Table of Contents
- Executive Summary
- The Client
- The Challenge
- Best For
- Why a Manual Cookie Consent Audit Was Needed
- Basic Cookie Scan vs Auditzo Manual Evidence Audit
- Audit Scope
- Auditzo Manual Evidence Method
- Evidence Collected
- Key Findings
- Deliverables Provided
- Business Outcome
- What Made This Audit Different
- Recommended Next Steps for Ecommerce Brands
- Important Legal Boundary
- FAQ
- Request a Manual Evidence Review