ConsentPixel – Privacy · Verified

Shopify Markets · Multi-Region ⚡ Pairs with Shopify

Region-Aware Consent for
Shopify Markets That
Blocks Every Pixel.

Shopify Markets lets you sell into many regions from one store — each with its own privacy rules. Shopify's Customer Privacy API and consent banner cover Shopify's own tracking, but custom pixels, scripts in theme.liquid, and many app pixels are not gated by it. Different markets demand different defaults, and a single banner rarely gets all of them right. ConsentPixel — Privacy · Verified adds region-aware blocking for every script across every market.

Region-aware defaults per market
GDPR · CCPA · CIPA · 19 US state laws
Google Consent Mode v2 built in
Gates custom, theme & app pixels
150+
Regions a single Shopify Markets store can sell into
$5,000
Per-visitor CIPA exposure from session-replay on California traffic
€20M
Max GDPR fine — or 4% of global annual revenue
2 min
To layer ConsentPixel over Shopify Markets

The Gap: One Banner, Many Regions, Uncovered Pixels

Shopify Markets is built for selling across borders — multiple regions, currencies, and languages from a single store. That cross-border reach is exactly what makes consent hard: the EU expects opt-in, much of the US expects opt-out, and several US states now require GPC and a “Do Not Sell or Share” signal. One default banner cannot satisfy all of those at once.

Shopify provides a Customer Privacy API and a native consent banner, and they do gate Shopify's own first-party tracking and Consent Mode signalling. But custom pixels you add, scripts hardcoded into theme.liquid, and many third-party app pixels are not automatically gated by that API — they fire across every market on load.

⚠ Native Scope Across Markets What Shopify's Customer Privacy API covers — and doesn't

Shopify's Customer Privacy API and banner handle Shopify-managed tracking and Consent Mode signalling, and they can vary the banner by region. They do not automatically gate custom pixels, scripts you add to theme.liquid, or every app pixel — those depend on each pixel respecting the consent API, which many do not.

Across markets this compounds: a shopper in Germany and a shopper in California need different defaults, and any pixel that ignores Shopify's consent API fires for both regardless of their region's rules.

✗ Custom pixels fire across markets

Custom JavaScript pixels you add fire on load in every region unless they explicitly honour Shopify's consent API — many do not.

✗ theme.liquid scripts run on load

Tags hardcoded into theme.liquid execute on render in all markets, outside the Customer Privacy API's control.

✗ App pixels vary in compliance

Third-party app pixels differ widely in whether they respect the consent API — some fire regardless of region or choice.

✗ One default rarely fits all regions

A single banner default cannot be simultaneously opt-in for the EU and opt-out with GPC for US states.

The more markets you open, the more regulatory regimes you take on at once. Without region-aware gating that covers custom, theme, and app pixels — not just Shopify's own tags — a Shopify Markets store can be compliant in one region and exposed in several others simultaneously.

Trackers Commonly Running Across Shopify Markets

A cross-border Shopify store typically runs a full advertising and analytics stack plus several apps, each firing across every market. These are the integrations most commonly found, and the exposure each creates region by region.

📊
Google Analytics 4
GDPR · CCPA · GCM v2
The most common tracker on Shopify Markets sites. Sets _ga cookies and transmits to Google on page load. Needs Google Consent Mode v2 default-deny set before GA4 initialises.
🔖
Google Tag Manager
GDPR · GCM v2 Required
Every tag inside a GTM container fires on load — conversion pixels, remarketing, analytics. The GCM v2 default state must be set before GTM loads, not after.
📘
Meta Pixel
GDPR · CCPA · CIPA
Loads from Facebook's CDN and fires on load, sharing browsing behaviour and conversions with Meta's ad network regardless of any banner shown.
🔥
Hotjar / Microsoft Clarity
GDPR · CIPA
Session-replay and heatmap apps record across every market on load — $5,000/visitor CIPA exposure for California traffic with no region-aware gate.
🎯
LinkedIn / TikTok Pixels
GDPR · CCPA
External pixels that set identifiers and fire on load. Common on B2B, agency, and creator sites and frequently missed in consent configurations.
📹
YouTube / Vimeo Embeds
GDPR
Embedded players set third-party cookies and load tracking when the page renders — not when the visitor presses play. Must be consent-gated for GDPR.
💬
Live Chat (Intercom, Drift, Crisp)
GDPR · CCPA
Chat widgets set persistent identifiers and load before consent. Common on SaaS, service, and agency sites.
🛒
Shopify App Pixels
GDPR · CCPA
Third-party Shopify apps frequently inject their own pixels. Whether each respects Shopify's Customer Privacy API varies — non-compliant app pixels fire across all markets regardless of region.

Shopify Native Consent vs. ConsentPixel

Shopify's Customer Privacy API gates Shopify's own tracking and can vary the banner by region. ConsentPixel adds region-aware blocking for the custom, theme, and app pixels the native API does not cover — layered alongside Shopify, not replacing it.

CapabilityShopify Customer Privacy APIConsentPixel
Gates Shopify-managed tracking✓ Yes✓ Yes — plus everything else
Gates custom & theme.liquid pixels✗ Not automatic✓ All registered scripts
Gates non-compliant app pixels⚠ Depends on the app✓ Yes — by network call
Region-aware defaults per market⚠ Banner only✓ Full per-region logic
Google Consent Mode v2 (all 4 params)⚠ Shopify scope✓ All scripts, all plans
Global Privacy Control (GPC) detection⚠ Partial✓ Auto-detected
CIPA session-replay blocking⚠ If app complies✓ Yes — always
Timestamped consent audit log⚠ Basic✓ Full log, exportable
Single consent record across markets✗ Fragmented✓ Unified, per-region
🚫
Selling into a region means inheriting its consent rules — even for the pixels Shopify's API doesn't gate. GDPR, CCPA, and 19 US state laws apply based on where your shopper is, not where you are. If custom or app pixels fire across all markets regardless of region, your store is compliant in some markets and exposed in others at the same time — a pattern enforcement increasingly targets.

See which pixels fire across your markets before consent

ConsentPixel scans your Shopify Markets store across regions in a fresh session — no cache, no prior consent — and shows every custom, theme, and app pixel transmitting data on load.

Scan My Shopify Markets Store →

How to Install ConsentPixel on Shopify Markets

ConsentPixel layers over your existing Shopify Markets setup as a single script in theme.liquid, working alongside Shopify's Customer Privacy API. It must load first so pre-consent blocking and region-aware defaults work across every market.

1

Create your ConsentPixel account and scan your store

Sign up at consentpixel.com, add your store domain, and run the auto-scanner across your markets. ConsentPixel maps every tracker by region — including custom pixels, theme.liquid scripts, and app pixels. Copy your unique pixel snippet from the dashboard.

2

Add the snippet to theme.liquid

In your Shopify admin, open Online Store → Themes → Edit code → layout/theme.liquid. Paste the ConsentPixel snippet immediately after the opening <head> tag, before any custom pixels or app-injected scripts.

layout/theme.liquid — top of <head>
<head>
  <!-- ConsentPixel — must be first -->
  <script
    src="https://pixel.consentpixel.com/YOUR-SITE-ID.js"
    async></script>

This covers every market your store serves, because all regions render from the same theme.

3

Configure region-aware defaults

In the ConsentPixel dashboard, set per-region behaviour: opt-in for the EU/UK, opt-out with GPC and “Do Not Sell or Share” for US states, and your chosen defaults for other markets. ConsentPixel detects each visitor's region and applies the right rules automatically.

4

Register your pixels and configure GCM v2

Register each tool by consent category — Marketing (Meta, Google Ads, TikTok), Analytics (GA4), Functional (chat), Session Recording (Hotjar, Clarity) — including app pixels that do not respect Shopify's API. Enable Google Consent Mode v2 so all four parameters fire before your Google tags, in every market.

5

Keep Shopify's API for native tracking

Leave Shopify's Customer Privacy API enabled for Shopify-managed tracking and let ConsentPixel handle everything it does not cover. The two work together — ConsentPixel can read Shopify's consent state so the experience stays consistent.

💡
Selling in the US and EU from one store? This is exactly where a single default banner fails. Test as a visitor from each region (use a VPN or ConsentPixel's region preview) and confirm the EU sees opt-in while California sees opt-out with GPC honoured — and that no custom or app pixel fires before consent in either. Pair this page with our main Shopify guide for store-wide setup.

What ConsentPixel Does for Your Shopify Markets Store

🌐

Region-aware consent defaults

Detects each shopper's region and applies the right rules — opt-in for the EU, opt-out with GPC for US states — instead of one default that fits no market perfectly.

🛡️

Gates custom, theme & app pixels

Intercepts the custom JavaScript pixels, theme.liquid scripts, and non-compliant app pixels Shopify's Customer Privacy API does not automatically gate.

📡

Google Consent Mode v2 — every market

Injects all four GCM v2 parameters before your Google tags fire, in every region. Protects Ads conversion measurement for EU and UK shoppers.

🔥

CIPA session-replay protection

Blocks Hotjar, Clarity, and replay apps before consent across all markets — eliminating the $5,000/visitor CIPA exposure your California traffic creates.

📊

Unified audit log across regions

Maintains one timestamped, exportable consent record across every market — with each region's rules captured — instead of fragmented per-app logging.

⚙️

Layers with Shopify, not against it

Works alongside Shopify's Customer Privacy API rather than replacing it, reading Shopify's consent state so native and custom tracking stay consistent.

Shopify Markets Privacy Compliance Checklist (2026)

📋 Shopify Markets Compliance Checklist — 2026 11 items
Audit every external script loading on your Shopify Markets siteCheck GTM tags, embedded code, app/plugin scripts, and any integration that calls a third-party domain
Verify external JavaScript is blocked before consent — not just first-party cookiesTest in your browser's DevTools Network tab in a private/incognito window before accepting anything
Add ConsentPixel first in theme.liquid and set region-aware defaults per markettheme.liquid renders for every market — placing ConsentPixel first plus per-region defaults ensures correct behaviour in each region
Configure Google Consent Mode v2 with all four parametersRequired for EEA/UK Google Ads — the default-deny state must fire before GTM or GA4 loads
Block session-replay tools before consent$5,000/visitor CIPA exposure — Hotjar, Clarity, Lucky Orange must never run before explicit consent
Implement GPC browser signal recognitionMandatory in California, Colorado, Virginia, and Connecticut — most native banners do not provide this
Add a "Do Not Sell or Share" opt-out for US visitorsRequired across California and all 19 active US state privacy laws in 2026
Consent-gate all embedded third-party content — maps, video, social widgetsYouTube, Google Maps, and X/Twitter embeds set third-party cookies and must be gated for GDPR
Update your privacy policy to disclose all external integrationsName GA4, GTM, Meta, LinkedIn, Hotjar, and any automation platform as third-party data recipients
Maintain a full timestamped consent audit logRequired under GDPR Article 5(2) accountability — keep an exportable record of every consent choice
Re-test after any Shopify Markets template, theme, or app changeUpdates can change script load order — confirm ConsentPixel still loads first after any change

Frequently Asked Questions

Not fully. Shopify's Customer Privacy API and banner gate Shopify-managed tracking and can vary the banner by region, but they do not automatically gate custom pixels, theme.liquid scripts, or every app pixel. A single default banner also cannot be simultaneously opt-in for the EU and opt-out with GPC for US states. ConsentPixel adds region-aware gating for everything the native API does not cover.
No — it layers alongside it. Keep Shopify's API enabled for Shopify-managed tracking; ConsentPixel handles the custom, theme, and app pixels it does not cover, and can read Shopify's consent state so the two stay consistent. Together they give full coverage across markets.
ConsentPixel detects each visitor's region and applies the defaults you configure — opt-in for the EU/UK, opt-out with GPC and a “Do Not Sell or Share” signal for US states, and your chosen behaviour elsewhere. This is set once in the dashboard and applies automatically across every market.
If your store runs session-replay or heatmap apps and receives California visitors — which a multi-region store almost certainly does — CIPA applies. California's wiretapping statute carries statutory damages of up to $5,000 per affected visitor. ConsentPixel blocks all session-replay scripts before consent in every market.
Yes — register each app's pixel in ConsentPixel and it gates the network calls those apps make, including app pixels that do not respect Shopify's Customer Privacy API. The scanner flags which app pixels fire pre-consent so you know exactly what to register.
Use both. This page focuses on the multi-region challenge specific to Shopify Markets; our main Shopify guide covers store-wide installation and theme details. If you sell into multiple regions, the region-aware setup here is what closes the cross-border gap.
Shopify Markets — Compliant in Every Region

One script in theme.liquid.
Every market, every pixel covered.

ConsentPixel — Privacy · Verified adds region-aware blocking for the custom, theme, and app pixels Shopify's Customer Privacy API does not gate — with per-region defaults, all four GCM v2 parameters, and GPC honoured across every market. Layers with Shopify, not against it.

Scroll to Top