# Shopify cookie banner: what a Decline tells Google

What Shopify's free cookie banner covers, what reached Google when we pressed Decline on live stores, and the code that makes theme tags listen.

_Shaun Brown · October 7, 2026 · https://tagsentry.ai/blog/shopify-cookie-banner_

> **The short answer:** Shopify's cookie banner is free and governs Shopify's own cookies and pixels. Google's tags hear a visitor's answer when they come from Shopify's Google & YouTube app, which passes it on as a Consent Mode update. Tags pasted into your theme or run from Tag Manager need their own code. When we pressed Decline on four live stores, the three with the app told Google; the fourth kept sending Google requests marked as granted.

> **Not legal advice** This guide describes how Shopify's banner behaves and what we measured. What your store needs depends on where your customers are. Ask a lawyer if you need a definite answer.

## What Shopify's banner covers

Shopify's banner covers Shopify's own tools. In Shopify's words, it "governs Shopify-specific tools, including cookies and Shopify Pixels".

Anything you added yourself may need its own consent handling. Shopify's help page goes on: "If you have manually installed third-party cookies or pixels or integrated them through apps on your store, then you may need to use a third-party cookie banner or add custom logic to ensure they are honoring customer consent."

The visitor's answer lives in Shopify's Customer Privacy API, a piece of JavaScript on every storefront. The API reports the choice. Each script has to ask it, because nothing in the API stops code that never checks.

## Turning it on, and where it shows

In your Shopify admin, go to **Settings › Customer privacy › Cookie banner**, choose its look and position, then pick the regions where it appears and activate it.

New stores get it switched on for visitors in the UK and the European Economic Area (EEA), if the store has active markets there. You can add regions or show it everywhere. Visitors elsewhere don't see it, which is why a US owner can look at their own store and find no banner at all.

## What we tested

On 7 October 2026 we loaded 29 Shopify stores in a fresh browser from the US. Five had Shopify's banner script on the page, and none showed the banner to us, which fits a banner set to show in the UK and EEA.

On four of them we opened the banner with Shopify's own JavaScript (the fifth didn't draw it) and pressed **Decline**.

We read three things before the click, after it, and again on the next page load:

- what Shopify's Customer Privacy API reported;
- the consent commands sent to Google's tags through the page's `dataLayer`;
- every request to Google, with its `gcs` and `gcd` values, which carry the consent state Google received.

Before the click, all four sent Google requests with ads and analytics granted (`gcs=G111`). That's normal for a US visit, where Shopify reports marketing as allowed until a visitor says no.

## What Decline did

On all four stores, Shopify recorded the choice: marketing and analytics both flipped to `no`. What Google heard depended on the store.

| Store | Google & YouTube app | Straight after Decline | Next page |
|---|---|---|---|
| A | Yes | Consent update: all four signals denied | No Google requests |
| B | Yes | Consent update: all four signals denied | One Google Analytics request, denied (`gcs=G100`) |
| C | Yes | Consent update: all four signals denied | 9 Google requests with no consent signal (`gcd=13l3l3l3l1l1`) |
| D | No | Nothing sent to Google | 22 Google requests marked granted (`gcd=13t3t3t3t5l1`) |

Reading [the gcd value](/blog/check-consent-mode-v2-working): every `l` means a signal was never set, and `t` means granted by default with no update after. On store D, Google kept being told it could use cookies after the visitor had declined.

Store C is the odd one. Its app passed the Decline on, but on the next page its Google tags ran before anything had set a consent state, so the app on its own wasn't enough there.

## Why the app makes the difference

On stores A to C we traced the consent update to its source: the web pixel of Shopify's Google & YouTube app. Its code reads Shopify's answer and maps it straight onto Google's signals. Marketing sets `ad_storage`, `ad_user_data` and `ad_personalization`, and analytics sets `analytics_storage`.

That's what Google's help page means by "After you've enabled your consent banner, consent mode is enabled automatically." Google also says that with the Google & YouTube app, "consent mode should work automatically". It covers the tags the app runs.

A Google tag in `theme.liquid`, or one fired from Tag Manager, doesn't hear the banner unless something passes its answer on.

The four signals are explained in [Google Consent Mode v2, explained](/blog/google-consent-mode-v2-explained).

## Making theme and Tag Manager tags listen

The simplest route is to run your Google tags through the Google & YouTube app. A consent tool that reads Shopify's Customer Privacy API works too, or you can add a short script yourself.

The script goes in `layout/theme.liquid`, right after `<head>` and above Tag Manager. It tells Google everything is denied before any tag runs, then passes on Shopify's answer when the page loads and whenever the visitor changes it:

```html
<script>
  window.dataLayer = window.dataLayer || [];
  function gtag(){dataLayer.push(arguments);}
  gtag('consent', 'default', {
    ad_storage: 'denied',
    ad_user_data: 'denied',
    ad_personalization: 'denied',
    analytics_storage: 'denied',
    wait_for_update: 500
  });
  function sendShopifyConsent(marketing, analytics) {
    var ads = marketing ? 'granted' : 'denied';
    gtag('consent', 'update', {
      ad_storage: ads,
      ad_user_data: ads,
      ad_personalization: ads,
      analytics_storage: analytics ? 'granted' : 'denied'
    });
  }
  document.addEventListener('visitorConsentCollected', function (e) {
    sendShopifyConsent(e.detail.marketingAllowed, e.detail.analyticsAllowed);
  });
  document.addEventListener('DOMContentLoaded', function () {
    window.Shopify.loadFeatures(
      [{ name: 'consent-tracking-api', version: '0.1' }],
      function (error) {
        if (error) return;
        var cp = window.Shopify.customerPrivacy;
        sendShopifyConsent(cp.marketingAllowed(), cp.analyticsProcessingAllowed());
      }
    );
  });
</script>
```

We tested it on store D, the one that sent Google nothing. With the script in place, Google Ads requests read `gcd=13r3r3r3r5l1` for our US visit: denied by default, then granted by Shopify's answer. After a Decline, the script sent a denied update, and the next page made no Google requests at all.

Duplicate your theme first, and test on the copy. In Tag Manager, Google's own tags read these signals by themselves. Other tags, like Meta's or TikTok's, need consent settings or triggers of their own.

## What about checkout

Shopify runs checkout on its own code, outside your theme, and Shopify's own privacy settings cover it. Visitors usually answer the banner on your storefront before they get there. If a purchase event seems to go missing, [the Meta pixel on Shopify](/blog/meta-pixel-purchase-not-firing-shopify) is a good place to start.

## Check your own store

1. Open your store in a private window.
2. Open the browser's developer tools (F12), go to **Console**, and run `privacyBanner.showPreferences()`. That opens Shopify's choices wherever you are. Press **Decline all** (or turn everything off and save).
3. Go to **Network**, filter for `gcd=`, and reload the page.
4. Read the values. Requests with an `l` in every position, or `t` in the first ones, went out without your visitor's refusal. Requests with `p`, `q` or `u`, or no Google requests at all, mean Google heard the Decline.

Google's Tag Assistant (tagassistant.google.com) shows the same consent state if you'd rather not read query strings. The full version is in [how to check Consent Mode v2 is working](/blog/check-consent-mode-v2-working).

## Where TagSentry fits

TagSentry is one line, pasted straight after `<head>` in `theme.liquid`, above everything including Tag Manager. Before any tag runs it sets every Consent Mode signal to denied. Where visitors can opt out, it switches tracking on moments after the page loads, unless they opted out.

With our banner on, it also holds trackers pasted into the theme (Meta, Hotjar and others) once our scan has found them.

Keep Shopify's banner if you like. While it's on, it stays in charge of consent, and our line steps aside without adding a second banner. With monitoring on, our line watches the events your theme or tags send, like `add_to_cart`, once a visitor accepts analytics on that banner. Google's tags follow that banner when they come from Shopify's Google & YouTube app.

When you're ready, turn Shopify's banner off, then choose our banner in Settings › Install. Steps are in the [install guide](/docs/install-by-platform), and [TagSentry vs Shopify's banner](/compare/shopify-banner) sets the two side by side. Consent is free up to 10,000 page views a month.

## Sources

- [Shopify Help: Configuring customer privacy settings](https://help.shopify.com/en/manual/privacy-and-security/privacy/customer-privacy-settings/privacy-settings)
- [Shopify Dev: Customer Privacy API](https://shopify.dev/docs/api/customer-privacy)
- [Tag Manager Help: Set up Shopify to obtain user consent](https://support.google.com/tagmanager/answer/14563069)
- [Google for Developers: Consent mode overview](https://developers.google.com/tag-platform/security/concepts/consent-mode)
- [Google for Developers: Set up consent mode on websites](https://developers.google.com/tag-platform/security/guides/consent)
- [Simo Ahava: Consent Mode V2 for Google tags (gcd decoding)](https://www.simoahava.com/analytics/consent-mode-v2-google-tags/)
