ConsentPixel – Privacy · Verified

Platform Guide · WooCommerce · 2026

WooCommerce Cookie Banner: Setup & Compliance

WooCommerce runs on WordPress, so you'd think consent works the same way — but a store has more at stake. Conversion pixels, checkout tracking, and session-replay tools cluster on exactly the pages carrying the most personal data. This guide covers how to set up a WooCommerce cookie banner that blocks those trackers before consent — and why the checkout page is where the real GDPR and CIPA risk lives.

By ConsentPixel TeamUpdated August 202613 min readInformation, not legal advice
Checkout = highest risk
Conversion pixels and session-replay cluster where personal data is heaviest
Plugin-based
Consent runs through a plugin — but many notify without truly blocking
$5,000
Per-visitor CIPA exposure under Cal. Penal Code §637.2 for pre-consent tracking
Quick answer

To set up a WooCommerce cookie banner: install a prior-blocking consent solution, enable auto-blocking so conversion pixels and analytics wait for consent, connect Google Consent Mode v2, and pay special attention to the cart and checkout pages — where the most trackers fire on the most sensitive data.

  • Running Meta/Google/TikTok conversion pixels: these must hold until consent, especially on checkout — verify in DevTools.
  • Session-replay on checkout + US traffic: the single highest CIPA-risk configuration for a store.
  • Just Woo-native features: you still need a banner — Woo sets cart/session cookies and you've almost certainly added pixels.

Do you need a cookie banner on WooCommerce?

Yes — arguably more than a content site. WooCommerce sets its own cart and session cookies, and nearly every store adds Google Analytics 4, a Meta Pixel, Google Ads conversion tracking, an abandoned-cart tool, reviews widgets, and often session-replay. The EU's GDPR and ePrivacy rules require opt-in before non-essential trackers load; California's CCPA and 18 other US state laws require a clear opt-out. Because a store processes payment and contact data, the stakes on getting consent right are higher than on a brochure site.

WooCommerce is a WordPress plugin, so the mechanics resemble our WordPress cookie banner guide — but the risk profile is different, because of where a store's trackers live.

Why the checkout page is where the real risk sits

This is the WooCommerce-specific point most guides miss. On a store, the highest-value trackers deliberately cluster on the cart and checkout pages — Meta and Google conversion pixels fire on purchase, session-replay tools record the checkout flow to diagnose drop-off, and abandoned-cart scripts capture entered details. These are exactly the pages where a visitor enters name, email, address, and payment intent.

So two things compound: the pages with the most personal data also carry the most third-party tracking, and a conversion pixel firing before consent on a checkout page is both a GDPR problem and — for US traffic — a CIPA one. A banner that a shopper dismissed on the homepage doesn't help if the checkout pixel fired anyway.

⚠ The notice-vs-blocking trap applies here too

Like any WordPress site, WooCommerce consent plugins split into notice-only (shows a banner, blocks nothing) and prior-blocking (actually withholds scripts until consent). On a store this distinction is sharper: a notice-only plugin lets your checkout conversion pixels fire on decline, which is precisely the exposure you're trying to avoid.

How to set up a WooCommerce cookie banner

The correct sequence, with the store-specific steps flagged:

  1. Pick a prior-blocking consent solution (plugin or script-based) that supports Google Consent Mode v2 and honours GPC. Notice-only won't protect checkout.
  2. Install and run its cookie scanner across the whole store — including cart and checkout pages, which often load trackers the homepage doesn't.
  3. Enable auto-blocking, and register your conversion pixels (Meta, Google Ads, TikTok) so they hold until consent. Set the Consent Mode v2 default-deny state before GTM loads.
  4. Verify checkout specifically: add a test product, go to checkout in incognito with DevTools → Network open, and confirm conversion pixels and session-replay stay blocked until you consent.
  5. Add privacy-policy and cookie-policy links to the banner and save.
  6. Re-test after any plugin, theme, or WooCommerce update — store plugin stacks change often.

See which trackers fire before consent on your WooCommerce store

A banner that's showing isn't proof anything is blocked — least of all on checkout. Run a free scan to see every tracker and cookie firing before a shopper opts in, across your store pages, in about 10 seconds. No account needed.

Scan your site free →
No account needed · results in ~10 seconds · information, not legal advice

What most WooCommerce cookie-banner setups miss

  • Checkout never tested. Most setups verify the homepage and stop — but the checkout page loads the highest-risk trackers. Always test with a product in the cart.
  • Conversion pixels ungated. Meta/Google Ads pixels added via a marketing plugin or GTM often fire outside the consent plugin's control.
  • The plugin only notifies. A banner that doesn't block leaves checkout pixels firing on decline.
  • Session-replay on checkout. Recording the checkout flow before consent is the sharpest CIPA exposure a store has.
  • Plugin conflicts from the larger store plugin stack silently breaking blocking after an update.

We built the deeper, store-specific version of this — including checkout-pixel handling and a full native-vs-ConsentPixel breakdown — into our cookie consent for WooCommerce guide.

Your 3 options for a compliant WooCommerce cookie banner

Three realistic routes — honestly compared, strongest coverage first.

1. An independent consent tool (e.g. ConsentPixel)

Best for: any store running conversion pixels, GTM, or session-replay — especially with US visitors. A consent layer that blocks trackers before consent across every page including checkout, passes all four Google Consent Mode v2 parameters, detects GPC, and keeps a timestamped consent log — without depending on the store's plugin stack for its blocking. Among independent tools, ConsentPixel — Privacy · Verified is built prevention-first and blocks the checkout pixels a notice-only plugin lets through.

2. A prior-blocking WordPress/Woo plugin (Complianz, CookieYes, Real Cookie Banner)

Best for: single stores wanting an in-dashboard tool. These genuinely prior-block and integrate with WooCommerce. The difference is emphasis: confirm auto-blocking is enabled and actually holds your conversion pixels on the checkout page — test it there specifically — and watch for plugin conflicts after updates.

3. A notice-only plugin

Best for: effectively no real store. If you run any conversion pixel or session-replay, a notice-only banner lets them fire on decline — including on checkout — which defeats the purpose. Not a viable option for a live store with a marketing stack.

The US angle most WooCommerce guides skip: CIPA

Nearly every "WooCommerce cookie banner" tutorial focuses on GDPR. It matters — but if any of your shoppers are in the United States, the more urgent 2026 risk is often the California Invasion of Privacy Act (CIPA). Plaintiffs' firms have built a sustained wave of "wiretapping" lawsuits arguing that session-replay tools, tracking pixels, and chat widgets capturing a shopper's activity before consent amount to unlawful interception. Under California Penal Code §637.2, a plaintiff can seek statutory damages of $5,000 per violation — often read per affected visitor — with no proof of harm required.

Why this hits WooCommerce stores specifically: session-replay and conversion pixels on the checkout page are the exact pattern these lawsuits target — tracking that captures a shopper's activity on a data-heavy page before consent. A store running Hotjar on checkout and serving California shoppers can carry real exposure even with a banner on screen. The fix is to hard-block those scripts until consent. You can follow the trend on our CIPA Lawsuit Tracker.

🚫 The one thing to check today

If your WooCommerce store runs session-replay or conversion pixels on the checkout page and gets US traffic, confirm they do not fire before consent — on checkout specifically. It's the single highest-value privacy fix on most stores.

See exactly what fires on your WooCommerce store before consent

Run the same scan a plaintiff's firm would: every tracker and cookie loading before opt-in — checkout conversion pixels and session-replay included — in about 10 seconds. Then, if it's your store, close the gap and run ConsentPixel free for 14 days.

Scan your WooCommerce store free →
No account for the scan · then a 14-day trial, no credit card, from $8.99/domain/mo · or read the full WooCommerce setup guide

Frequently asked questions

How do I add a cookie banner to WooCommerce?

Because WooCommerce runs on WordPress, you add a cookie banner the same way: install a prior-blocking consent solution (plugin or script-based), enable auto-blocking so non-essential scripts wait for consent, connect Google Consent Mode v2, and add your privacy-policy link. The store-specific step is to test the cart and checkout pages specifically — add a product and verify in incognito that conversion pixels and session-replay stay blocked until consent, since those pages carry the most trackers and the most personal data.

Why is the checkout page the biggest compliance risk on WooCommerce?

Because the highest-value trackers cluster there. Meta and Google conversion pixels fire on purchase, session-replay tools record the checkout flow, and abandoned-cart scripts capture entered details — all on the page where a shopper enters name, email, address, and payment intent. A conversion pixel firing before consent on checkout is both a GDPR issue and, for US traffic, a CIPA one. A banner dismissed on the homepage doesn't help if the checkout pixel fired anyway. This is general information, not legal advice.

Do my WooCommerce conversion pixels need consent?

Yes, under GDPR — Meta, Google Ads, and TikTok conversion pixels are non-essential marketing trackers, so they must wait for opt-in from EU/UK shoppers and honour opt-out for US state-law regions. The common failure is that these pixels are added through a marketing plugin or GTM and fire outside the consent plugin's control. A prior-blocking consent solution that registers and gates your conversion pixels — verified on the checkout page — is what makes them compliant. This is general information, not legal advice.

Is a WooCommerce cookie banner GDPR compliant on its own?

Only if it actually blocks non-essential scripts before consent, including on checkout. GDPR requires non-essential processing to wait for consent, so a banner that merely displays while your conversion pixels and session-replay keep firing meets the notice requirement but not the consent requirement. To make a store genuinely compliant, use a prior-blocking solution that sets Google Consent Mode v2, honours GPC, and gates checkout pixels — verified in DevTools. No tool makes any website fully compliant on its own. This is general information, not legal advice.

Does my WooCommerce store have CIPA (US wiretapping) risk?

Potentially, yes — and stores are a prime target. If your store runs session-replay or heatmap tools (like Hotjar or Clarity) or conversion pixels that capture shopper activity before consent, especially on checkout, and you receive California visitors, CIPA applies. Under California Penal Code §637.2, plaintiffs can seek statutory damages of $5,000 per violation, often read per affected visitor, with no proof of harm required. Session-replay on a checkout page is the sharpest version of this exposure. The protective step is to hard-block those scripts before consent. This is general information, not legal advice.

Is WooCommerce consent different from regular WordPress?

The mechanics are the same — WooCommerce is a WordPress plugin, so you use the same prior-blocking consent tools and the same install path. What differs is the risk profile: a store adds conversion pixels, checkout tracking, and often session-replay on its most data-heavy pages, so the stakes of getting blocking right are higher and the checkout page needs specific testing. If you run other WordPress sites too, the same consent tool can cover them all — a script-based tool with flat pricing is often the most consistent choice across a mixed portfolio.

Scroll to Top