Skip to main content

How Auditzo Helped a Shopify Brand Identify and Fix Tracking and Consent Issues

Installing a consent banner is one thing. Knowing whether every tracking integration actually respects a visitor's choice is another.

That was the challenge for a US-based Shopify ecommerce business with multiple advertising, analytics, and attribution integrations. The business needed more than a list of cookies or an automated scan. It needed to know which technologies were active, where they came from, what happened when a visitor opted out, and how to address the issues the investigation uncovered.

Auditzo took the engagement from technical evidence collection through production remediation and controlled retesting. The business then retained the team for ongoing technical work.

By Auditzo October 08, 2026

Project at a glance

  • Client: US-based Shopify ecommerce business
  • Business concern: Tracking and consent behavior across a complex storefront
  • Technical work: Tracking inventory, consent-state testing, source investigation, and remediation
  • Test coverage: Cold, Accept All, Reject All, and GPC-only sessions
  • Delivery: Live Shopify fixes followed by controlled retesting
  • Relationship: The engagement continued into ongoing monthly technical services

Have a similar concern about your own Shopify store? Explore Auditzo's Shopify Privacy and Consent Audit or talk to our team.

The Client's Challenge

The business relied on Shopify and a collection of tools that supported advertising, analytics, attribution, and customer engagement. Some tracking was configured through familiar tag-management tools. Other activity could come from Shopify Customer Events, app pixels, custom pixels, or application embeds.

The client wanted answers to practical questions:

  • What reaches third parties before a new visitor makes a consent choice?
  • When someone selects Reject All, which tracking paths actually stop?
  • Does the store recognize Global Privacy Control (GPC) without requiring a banner click?
  • Could some tracking come from apps or server-side integrations that are not visible in Google Tag Manager?
  • Could the identified issues be fixed and then tested on the production store?

The difficulty was not that Shopify had one broken switch. The tracking setup had several control points. A change in one place would not necessarily affect an integration running somewhere else.

Diagram showing multiple Shopify tracking paths including Customer Events, custom pixels, app embeds, theme scripts, GTM, and server or platform integrations.
A Shopify store may send data through Customer Events, custom pixels, app embeds, theme scripts, GTM, and server-side or platform integrations. That is why a tag manager review alone is often not enough.

What We Found

Our initial investigation showed why a simple cookie scan or GTM review would not have answered the client's questions.

Tracking was spread across different parts of Shopify

We identified relevant tracking through Shopify's customer-event framework, connected applications, embeds, and tag-management configuration. The location of each integration mattered because it determined where its behavior could be investigated and corrected.

Consent behavior was not consistent across all browser-side integrations

Controlled testing showed mixed results after the visitor opted out. Some browser-side tracking paths stopped as expected. Other paths continued to generate activity after the recorded rejection point, creating specific engineering items to investigate.

Not every request received the same classification. Some measurement requests carried restricted consent indicators, so we reviewed their technical context rather than treating every post-opt-out request as the same type of problem.

GPC needed a separate assessment

The initial testing established that the browser could send a GPC signal and that the site's consent process could reflect that preference without the visitor clicking the banner. We also reviewed whether that state was clearly communicated to the visitor and how relevant integrations behaved.

Server-side questions required a different level of proof

Some connected platforms had server-side or platform-side event capabilities. We documented those paths separately. A browser request disappearing after Reject All is useful browser-side evidence, but it cannot prove that a separate server-to-server event was suppressed.

These findings gave the team a concrete engineering plan rather than a vague instruction to "fix the cookies."

How We Investigated the Problem

We approached the work as a tracking architecture problem, not just a banner configuration problem.

First, we compared what was installed or enabled with what actually ran in the browser. We reviewed material tracking sources, network activity, relevant browser storage, and consent-related state. When a request needed attribution, we examined its runtime path instead of assuming the vendor's GTM tag had caused it.

Then we used four separate visitor states:

TestVisitor conditionWhat we wanted to understand
ColdFresh browser, GPC off, no banner interactionWhat happened before a choice
Accept AllGPC off, consent acceptedWhich tracking paths operated when permitted
Reject AllGPC off, visitor rejected trackingWhat continued after the opt-out checkpoint
GPC-onlyGPC on, no banner interactionWhether the browser signal was recognized and processed

We kept Reject All and GPC-only separate because they are not the same journey. One involves a deliberate banner action. The other begins with a browser-level signal.

We also followed representative shopping activity beyond the homepage, including product and cart interactions and checkout before payment. That mattered because an app or advertising integration may behave differently once a shopper moves deeper into the storefront.

Infographic showing four Shopify consent testing states: Cold, Accept All, Reject All, and GPC Only, with fresh profile, California VPN, network review, and consent check.
Auditzo tested the storefront under four different conditions: Cold, Accept All, Reject All, and GPC Only. Each state answered a different technical question and helped verify how tracking and consent behavior changed.

How We Addressed the Issues

After the audit, the project moved into engineering remediation. The team worked on the tracking and consent issues identified during the investigation and deployed changes to the live Shopify store.

The most important decision was to address behavior at its actual source. If an event originated in a Shopify pixel or app-managed integration, changing an unrelated GTM definition would not necessarily solve the problem. The team used the architecture review and browser observations to guide where remediation work belonged.

The goal was not to turn off every marketing tool. It was to address the identified consent-handling issues while preserving a clear distinction between activity that should run under an accepted state and activity that needed attention after an opt-out.

This is the difference between producing a list of findings and owning the engineering follow-through: understanding the execution path, making the relevant changes, and checking the resulting behavior.

How We Retested the Fixes

The team did not treat a saved configuration or successful deployment as the finish line.

After production changes, the engineering lead retested the relevant behavior using new browser profiles, the same California VPN approach, and explicit GPC-on or GPC-off settings for each scenario. Cold, Accept All, Reject All, and GPC-only conditions were revisited rather than mixed together.

That discipline matters on Shopify stores. Cookies, local storage, and persisted consent state can make a later test behave differently from a true first visit. Reusing a browser profile can hide a problem or make a correct implementation appear inconsistent.

Retesting under controlled conditions helped the team evaluate the changes in the context of the original technical questions. The work was completed on the production storefront, not left as a recommendation in a PDF.

The Outcome

The engagement started with uncertainty about how a complicated collection of Shopify tracking tools responded to visitor privacy choices.

It progressed into a practical engineering project. Auditzo documented the relevant tracking architecture, identified browser-side behavior that required attention, supported production remediation, and carried out controlled retesting after the fixes were deployed.

Following that work, the business retained the team for ongoing monthly technical services.

What the engagement delivered

  • A clearer picture of tracking paths across Shopify, apps, and tag management
  • Evidence-based findings from four distinct privacy states
  • Targeted engineering work on the issues identified
  • Production deployment and fresh-session retesting
  • A continuing technical relationship beyond the initial audit

The project was a technical audit and remediation engagement. It was not a legal compliance certification, and browser-side results were not presented as proof of every separate server-side event path.

What Other Shopify Owners Can Learn

A working banner does not answer every tracking question

Your consent interface may store the visitor's choice correctly while one or more integrated tools respond differently. Testing the actual requests matters.

Look beyond Google Tag Manager

Shopify apps, Customer Events, and custom pixels can introduce independent tracking paths. A GTM-only review may miss them.

Ask where the request originates before asking for a fix

Knowing which integration actually sent the request helps avoid changes to the wrong component and unnecessary disruption to your store.

Test both manual opt-out and GPC

Reject All and GPC-only should be tested as separate visitor scenarios. A successful banner test alone does not answer how an automatic browser preference is handled.

Retest production behavior, not just settings

The real question is what the storefront does after a change. Fresh sessions and consistent test conditions make that answer more useful.

Need Help With Shopify Tracking and Consent?

If your Shopify store uses multiple advertising pixels, analytics tools, attribution apps, or custom tracking, it can be difficult to know whether each integration behaves as intended when a visitor opts out.

Auditzo can help you understand the tracking architecture, identify what actually fires, investigate consent-state behavior, and scope technical remediation and verification work where needed.

Explore our Shopify Privacy and Consent Audit or contact Auditzo to discuss your store.

Frequently Asked Questions

Can Shopify apps run tracking outside Google Tag Manager?

Yes. Shopify Customer Events, app pixels, custom pixels, and app embeds can create tracking paths that do not depend on GTM.

How do you check whether tracking stops after Reject All?

We use a controlled browser session, record the rejection checkpoint, and review relevant requests and stored state after that point. Each vendor's behavior is assessed in context.

Why do you test Global Privacy Control separately?

GPC is a browser-level privacy preference that may be present before any banner interaction. It needs its own test to check transmission, processing, and resulting site behavior.

Can a HAR file prove server-side tracking has stopped?

No. HAR files are evidence of browser-visible network activity. Separate server-originated events may need vendor or platform-side evidence.

Can Auditzo help fix problems found during an audit?

Auditzo can support separately scoped technical remediation and verification work. The exact work depends on the integrations, access, and findings involved.

Does a tracking audit or remediation guarantee CIPA compliance?

No. Auditzo provides technical evidence and engineering support. Legal interpretation and compliance decisions belong to qualified legal counsel.

Client identity and identifying technical details have been omitted. This case study describes technical investigation, remediation, and testing. It does not offer a legal opinion or compliance certification.

Share: