ConsentPixel – Privacy · Verified

Tracking Pixel · CIPA & Legal Risk

You Installed the Pixel App. You May Own the Compliance Problem.

Agencies buy pixel management apps through Shopify partner accounts and roll them out across dozens of client stores simultaneously. The clients assume the agency handled compliance. The agency assumes the app handles compliance. Nobody installs the CMP. The CIPA demand letter arrives at the client's door — but under California's aiding-and-abetting clause, the agency that deployed the configuration may be in the chain of liability too. Here's the exposure and what to do about it across your entire Shopify portfolio.

By the ConsentPixel — Privacy · Verified team June 2026 14 min read For agencies managing Shopify client portfolios
§631(a) Clause 4
CIPA's aiding-and-abetting provision — reaches anyone who aids an unlawful interception, including agencies that deployed the config
Portfolio scale
One agency installing unconsented pixels across 30 client stores = 30 separate CIPA exposure points simultaneously
Retail #1
Retail and eCommerce is the most-targeted CIPA sector in 2026 — your Shopify client portfolio is the bullseye

Here's the scenario playing out across hundreds of agencies managing Shopify client portfolios right now. The agency buys a pixel management app through their Shopify partner account. They roll it out across their client portfolio — 10, 20, 30 stores — because that's what a good agency does with a useful tool that improves ad performance. The clients are happy. The pixels are firing. The campaigns are running.

What nobody did: install the CMP that gates those pixels behind consent before they fire on California visitors. What nobody told the client: a pixel app and a consent management platform are completely different categories of software, and you need both. What nobody noticed: the plaintiff-side scanners that generate CIPA demand letters are looking for exactly this pattern — a Shopify store with Meta Pixel and TikTok Pixel firing before consent, California visitors, no prior consent mechanism in place.

When the demand letter arrives at the client's address, the first call is to the agency. This article covers what that call looks like, where the agency's specific legal exposure sits, and the portfolio-wide steps that convert this risk into a documented, defensible position — and a new service your agency can offer. Not legal advice throughout; consult qualified counsel for specific situations.

The compliance gap no one owns

The accountability gap in the Shopify pixel ecosystem exists because of how the tools are categorised. Pixel management apps — Trackify, Omega, CAPI-based apps, multi-pixel dashboards — live in the "advertising" or "marketing" category of the Shopify App Store. Consent management platforms live in "privacy" or "compliance." Agencies buy from the first category as a standard part of every client onboarding. The second category is treated as optional, or as something the client handles themselves.

The result is an assumption chain where nobody takes responsibility: the pixel app developer assumes the merchant has a CMP. The merchant assumes the agency handled compliance when they set up the tracking. The agency assumes the app's "Built for Shopify" certification means it's compliant. Shopify's platform provides the Customer Privacy API for pixel apps to integrate with, but doesn't mandate that they do, and doesn't require a CMP as a prerequisite for installing a pixel app.

The CIPA demand letter doesn't care about the assumption chain. It cares about one thing: did the pixel fire before the California-resident visitor consented? If yes — regardless of who is responsible for that configuration gap — there is a viable claim.

How agency CIPA aiding-and-abetting exposure works

Under California Penal Code § 631(a), liability for wiretapping extends beyond the direct interceptor to anyone who "aids, agrees with, employs, or conspires with" another to accomplish an unlawful interception. This is the fourth clause of § 631(a) — the aiding-and-abetting provision — and it is the clause that has been most frequently used to reach website operators who deploy third-party tracking tools without consent. As Debevoise's June 2025 analysis confirms: "Plaintiffs have used CIPA to target both the technology providers and the companies that utilize them."

The question for agencies is whether that liability chain can extend one step further — from the merchant who uses the pixel to the agency that deployed and configured it. The legal analysis is fact-specific, and there is no published case as of writing that has found an agency liable under this theory for a client site's pixel deployment. But the elements of the theory map onto the typical agency engagement clearly:

  • The agency installed the pixel app — through the Shopify partner account, with access to the client's admin
  • The agency configured the pixel — setting up events, connecting to ad accounts, determining which pages it fires on
  • The agency managed the integration — typically the only party with technical understanding of what the pixel does and when
  • The agency may have known CIPA applied — especially for agencies that have read any privacy coverage in the past two years
  • The agency did not install a consent gate — and did not inform the client that one was needed

The aiding-and-abetting theory requires knowledge and purpose. An agency that deployed an unconsented pixel configuration knowing CIPA existed and knowing consent was expected is in a different position than one that genuinely had no awareness of the legal landscape. That said, "I didn't know CIPA applied to Shopify" is becoming an increasingly hard argument to make in 2026 — the litigation wave is widely covered, the demand letters are arriving in volume, and any agency managing Shopify stores for clients with California traffic is expected to be aware of the legal environment in which those stores operate.

The contract doesn't automatically protect you

Many agencies include language in their service agreements placing compliance responsibility on the client. This is useful — it establishes the client's awareness of the obligation. But it doesn't insulate the agency from third-party CIPA claims under the aiding-and-abetting theory, which flows from the agency's own conduct in deploying the configuration, not from the agency-client contractual allocation of responsibility. The contract protects the agency in a dispute with the client. It doesn't address a CIPA plaintiff's claims against the agency directly. Not legal advice.

The client conversation when a demand letter arrives

When a client receives a CIPA demand letter, the immediate practical issue for the agency is usually the client's first question: "You set all this up — why is it creating legal problems?" That question arrives before any lawsuit is filed, in an emotionally charged context where the client is looking at a letter demanding $25,000–$75,000 and doesn't fully understand why.

The agencies that handle this call well are the ones that have answers ready — and ideally, the answers are "here's what we changed six months ago and here's the documentation showing your site was consent-gated before this claim." The agencies that handle it poorly are the ones who haven't done the audit and have to scramble to figure out what was actually running, when, and whether a consent mechanism was in place.

The practical steps when a client receives a demand letter:

  1. Preserve everything first. Before changing any site configuration, capture the current state — screenshot every page with DevTools network tab open, export the pixel app configuration, document what's running. Changing the configuration before preserving evidence is a spoliation risk.
  2. Do not respond directly to the demand. CIPA demand letters have specific response windows. Anything said in response is on the record. Refer the client to CIPA-experienced counsel immediately.
  3. Gather your agency's documentation. When did the pixel app get installed? Was there any CMP in place at the time? Did the agency brief the client on CIPA consent requirements? Written documentation of any compliance conversations you had with the client becomes important.
  4. Implement the consent gate — after preserving evidence. Once the current state is documented, implement a CMP across the affected store. This doesn't undo historical exposure but demonstrates current remediation.

Why Briskin v. Shopify makes every client store in scope

The Ninth Circuit's en banc ruling in Briskin v. Shopify, Inc. (April 2025) eliminated the "differential targeting" requirement for CIPA jurisdiction. Under prior precedent, a defendant had to specifically target California for California courts to have jurisdiction. After Briskin, collecting data from California residents as part of normal platform operations — which any Shopify store does — is sufficient. There's no geographic shield for out-of-state merchants.

For agencies, this means that "my client isn't in California" is no longer a reason to deprioritise consent compliance on their Shopify store. Every client store accessible to California residents — which is every client store on the open internet — is in scope for CIPA after Briskin. An agency managing 25 Shopify stores for clients in London, Sydney, Toronto, and Dallas has 25 stores with California CIPA exposure if pixels are firing before consent on any of them.

Agency bulk pixel installs: one action, portfolio-wide exposure Your agency Partner account installs pixel app Client store 1 · exposed Client store 2 · exposed Client store 3 · exposed … × 30 stores vs Your agency Installs pixel app + CMP always Store 1 ✓ Store 2 ✓ Store 3 ✓ × 30 stores
A single agency decision — install pixel apps without CMPs — creates CIPA exposure across every client store simultaneously. Adding CMP to the standard onboarding workflow closes the gap at the same scale.

What pixel apps don't do that you think they do

The specific false assumptions that create the gap:

"The pixel app integrates with Shopify's Customer Privacy API, so consent is handled."

Some pixel apps integrate with Shopify's Customer Privacy API and check for consent before firing. Many don't, or implement it incorrectly. And even for apps that do integrate correctly, the API only has a consent state to read if a CMP has written one. Without a CMP generating a genuine visitor consent event, the Customer Privacy API may default to "allow all processing" — the pixel fires regardless. The API is a pipe, not a gate. Something must fill it with real consent data.

"The Shopify store has a cookie banner, so it's covered."

Shopify's built-in cookie banner activates by default only for UK and EEA visitors. California visitors get no banner unless you've specifically configured it to appear for US regions. And even when configured, the Shopify banner requires individual pixel apps to respect it — which depends on their Customer Privacy API integration. A banner that displays but doesn't technically block a pixel that isn't integrated with the API doesn't satisfy CIPA's prior-consent standard. As Kukie.io's March 2026 compliance guide confirmed: "Shopify's default banner only activates for UK and EEA visitors. Every other region requires either a third-party CMP or a custom implementation using the Customer Privacy API."

"CAPI (server-side) means we don't have browser-side pixel exposure."

Conversions API (CAPI) is a server-side alternative to browser pixels that sends event data from your server to Meta, Google, or TikTok rather than from the visitor's browser. It's meaningfully better for both data accuracy and privacy — but it doesn't automatically eliminate browser-side pixel exposure. Many agencies run CAPI alongside browser pixels ("redundant tracking"), and the browser pixel still fires before consent even when CAPI is the primary signal. If your pixel management app is running browser-side pixels alongside CAPI, the browser-side pixels still need consent gating.

The portfolio audit: finding your highest-risk client stores

The immediate practical step for any agency managing Shopify clients is a portfolio-level audit. This doesn't require sophisticated tools — it requires systematically running the network tab test on each client store and documenting what you find.

Risk factorLow riskMedium riskHigh risk
California visitor volumeUnder 1,000/mo1,000–10,000/mo10,000+/mo
Pixel configurationServer-side CAPI only, no browser pixelBrowser pixel + CAPIBrowser pixel only, default fire
Consent mechanism in placeCMP with California coverage + opt-inBanner but not blocking pixelsNo banner for US visitors
Sensitive page pixelsPixel excluded from checkout and accountPixel on most pagesPixel on checkout + Advanced Matching on
Class period exposureCMP installed from day oneCMP added recentlyNo CMP ever installed; pixel app running for years
GPC handlingGPC suppresses all pixelsGPC not testedGPC not honored

Any client store scoring "High risk" on three or more factors should be the immediate priority for CMP implementation. Any store with Advanced Matching enabled and pixels firing on checkout pages without consent is your most urgent remediation target — that specific combination generates the largest demand amounts.

The compliance service opportunity agencies are missing

Agency opportunity — not just risk management

Privacy compliance as a billable service line

Every Shopify store in your portfolio needs a CMP. Most of them don't have one. Implementing, configuring, and maintaining consent management for Shopify stores is a service that requires exactly the kind of technical expertise agencies have — GTM configuration, Shopify Customer Privacy API integration, consent mode wiring, GPC testing. It's also recurring: consent logs need monitoring, configurations need updating as the law evolves, new pixel apps added to the stack need to be wired into the consent architecture.

The agencies that lead with "we protect your store from CIPA demand letters" as a service offering — not just a risk mitigation step — are positioning themselves with a genuine differentiator that most clients urgently need and most competitors aren't systematically providing. The 1,919 pixel apps in the Shopify App Store all need a compliance partner. None of them are providing it. That's your opening.

Concretely: for every new Shopify client onboarding, the standard workflow becomes "install pixel app + install CMP + connect them together + document the configuration." That's an additional setup fee, a recurring maintenance retainer, and a client relationship where you're the entity that kept them out of a demand letter rather than the entity that unknowingly created their exposure.

Per-client Shopify compliance checklist

Agency Shopify CIPA Compliance Checklist

Per-client · run on every Shopify store in your portfolio · not legal advice

Discovery — what's actually running?

Network tab test — California visitor simulation. Load the store in a clean browser (no cookies, no extensions). Filter network requests for Facebook, TikTok, analytics, Bing. Document every third-party request that fires before any consent interaction.
Check Shopify's consent banner configuration. In Shopify Admin → Settings → Customer privacy, confirm whether the consent banner is configured to appear for California/US visitors, not just EU/UK. Confirm the banner type (opt-in required for CIPA).
Audit pixel apps installed. List every pixel app in the Shopify Admin → Apps. Identify which ones use the Shopify Customer Privacy API and which fire independently of consent state.
Check for browser-side pixels alongside CAPI. If the client runs Conversions API, confirm whether browser-side pixels are also active. Both need consent gating if browser pixels are present.
Identify Advanced Matching / AutoMatching status. For each pixel platform, check whether hashed identifier transmission is enabled and whether it fires on form/checkout pages before consent.

Configuration fixes

Install a CMP with Shopify Customer Privacy API integration. The CMP must write consent choices to Shopify's Customer Privacy API, not just display a banner. Verify API integration is active and functional.
Configure California/US consent coverage. The CMP must display a consent banner for California-resident visitors, not just EU visitors. Set up geotargeting for US states requiring prior consent.
Set banner type to opt-in for California visitors. Pixels must not fire until the visitor has affirmatively accepted. Opt-out type fires pixels by default — that's CIPA exposure even with a banner present.
Wire CMP consent signals to all pixel apps. Each pixel app that respects the Customer Privacy API will honor the consent state the CMP writes. For apps that don't integrate with the API, the CMP must separately block their scripts before consent via script-tag blocking.
Exclude pixels from checkout and high-sensitivity pages. Remove pixel triggers from checkout, payment, account login, and any page with sensitive personal data inputs. Do this regardless of consent configuration.
Verify GPC propagation. Load the store with Brave browser (GPC on by default). No pixel should fire. Confirm CMP detects and honors the GPC signal before any ad tech loads.

Documentation

Document the configuration for each client. What CMP is installed, what banner type, what pages have pixels excluded, what the consent API integration status is. Keep this as a dated record.
Brief the client in writing. Confirm to the client in a written message (email is fine) what you've implemented, what it covers, and that prior consent is now required before pixels fire. This creates a record that the client was informed.
Retain GTM/pixel app configuration snapshots quarterly. Export the pixel app and GTM container configuration periodically. If a demand letter arrives citing a historical period, you need to demonstrate what was running at that time.

The bottom line

The Shopify App Store has 1,919 pixel apps and not one of them installs a consent management platform. The standard agency workflow — install pixel app, connect to ad accounts, move to the next client — creates a portfolio-wide compliance gap that the Briskin ruling, the CIPA litigation wave, and the demand letter machine are actively exploiting. Agencies that have deployed pixel apps across dozens of Shopify stores without corresponding CMP installations are in a specific kind of exposure: the clients receive the demand letters, but the agencies may be in the chain of liability under CIPA's aiding-and-abetting clause for having configured the unconsented tracking. The fix is adding CMP installation as a standard step in every Shopify client onboarding — not as a compliance afterthought but as the technical prerequisite for the pixel configuration to be legally defensible. That change also converts a liability into a service: privacy compliance infrastructure is work that needs doing, that agencies are positioned to do, and that most clients don't know how to procure on their own. This is informational, not legal advice; consult qualified counsel for specific situations.

Audit your Shopify portfolio for pre-consent pixel exposure

ConsentPixel — Privacy · Verified scans any Shopify store and shows exactly which pixels fire before consent — across your entire client portfolio. Free scan, no card required.

Scan a client store free

Frequently asked questions

Can an agency be held liable under CIPA for a client's Shopify pixel configuration?

Potentially. CIPA's aiding-and-abetting provision under § 631(a) Clause 4 can reach anyone who knowingly assists in an unlawful interception — including an agency that installed and configured tracking pixels on a client's Shopify store without implementing consent gating. The agency is typically not the primary defendant (the client is), but if the agency deployed the configuration, knew CIPA applied, and did not install a CMP, the aiding-and-abetting theory creates exposure. This is fact-specific and unsettled — no published case as of writing has specifically held an agency liable in this position. Not legal advice; consult counsel.

Does a service agreement placing compliance responsibility on the client protect the agency?

It protects the agency in a dispute with the client about who bears compliance costs or indemnification. It does not insulate the agency from CIPA claims brought directly against the agency by third-party plaintiffs, whose claims rest on the agency's own conduct in deploying the configuration, not on the contract between agency and client. The contract is useful for client relationship protection but doesn't address third-party CIPA liability. Not legal advice.

Does CAPI (server-side tracking) eliminate the need for consent gating on Shopify?

Not if browser-side pixels are also running alongside CAPI. Many agencies run "redundant tracking" with both browser pixels and CAPI. The browser-side pixels still fire on page load before consent, creating CIPA exposure regardless of whether CAPI is the primary measurement signal. If you're running CAPI only with no browser-side pixels, that eliminates the browser-side CIPA exposure for those platforms — but you must verify that no browser pixel is loading at all, including from third-party pixel apps that may fire independently of your CAPI implementation.

What's the fastest way to close the gap across an existing client portfolio?

Prioritise by risk: identify stores with the highest California visitor volumes, Advanced Matching enabled, pixels on checkout pages, and no US-facing consent banner. Those are your most urgent remediation targets. For each store: install a CMP with Shopify Customer Privacy API integration, configure it for California opt-in consent (not just EU), connect it to all pixel apps, exclude pixels from checkout pages, and document the configuration. Then run the five-minute network tab test to verify. Work through the portfolio systematically — the highest-risk stores first, then the rest. Not legal advice.

ConsentPixel — Privacy · Verified
We build CIPA-first consent enforcement for agencies and their Shopify clients. This article is informational and not legal advice. Consult qualified counsel for specific situations involving your agency's liability or specific client circumstances.
Scroll to Top