Pre-consent tracker report
The verdict
Critical
Your consent banner is not blocking anything
Consentmo is installed on this store. On 6 pages, 9 tracking tools sent data before the banner was answered. After the reject control was pressed, 7 of 9 continued on the next page load.
You should do this: 1. turn on blocking in your consent app. 2. remove the Meta Pixel hard-coded in your theme. 3. set Google Consent Mode defaults. 4. remove or gate Hotjar on product pages. 5. re-scan and retain the report.
- 7tracking tools sent data before consent
- 9non-essential cookies planted
- 7 of 9executed after consent was refused
- 1tracker outside the consent app's control
Section 1
Required changes
In order. Each step names the location and the action.
-
Turn on blocking in your consent app
Fixes 5 of 77 trackers continued after the reject control was pressed. Consentmo is set to notice only, which displays the banner and blocks nothing. In the Shopify admin open Consentmo, go to Cookie blocking, change Notice only to Block before consent, and add every tracker listed in section 4 to the block list.
-
Remove the Meta Pixel that is hard-coded in your theme
Theme edit requiredTwo copies of the Meta Pixel were recorded. One loads through the consent app. The second is inline in theme.liquid and is outside the consent app's control. Search the theme for fbq( and remove that block. Re-add the pixel through the consent app or through Shopify Customer events.
-
Set Google Consent Mode defaults
Also affects EU conversion reportingGoogle tags are present with no declared default consent state, so they execute on load. In Google Tag Manager add a Consent Initialization trigger that sets ad_storage and analytics_storage to denied, and grant them from the consent app after the visitor agrees.
-
Remove or gate Hotjar on product pages
Session recorderHotjar records pointer movement, scrolling, and keystrokes. It was recorded on the product page at 1120ms. Add Hotjar to the consent app's block list, or remove it from pages that contain input fields.
-
Re-scan and retain the report
VerificationRun the scan again after the changes above are live. Retain the dated report as a record of the date the configuration changed.
Section 2
Requests recorded before consent, by page
Each bar starts at the first byte of the page and ends at the request to that company. No element was clicked, scrolled, or typed into during any of these recordings.
Homepage /
Product page /products/ethiopia-guji-natural
Cart /cart
Checkout /checkouts/…
Section 3
Behaviour after consent was refused
The homepage was loaded, Reject All was pressed, and the page was loaded again in the same browser so the stored choice applied. The table records what executed on that second load.
| Tracker | What it is | After Reject All |
|---|---|---|
| Meta Pixel | Advertising pixel | Still running |
| TikTok Pixel | Advertising pixel | Still running |
| Hotjar | Session replay | Still running |
| Klaviyo | Email identity | Still running |
| Attentive | SMS identity | Still running |
| Pinterest Tag | Advertising pixel | Still running |
| DoubleClick | Advertising pixel | Still running |
| Google Analytics | Analytics | Stopped |
| Google Tag Manager | Tag loader | Stopped |
7 of 9 executed after consent was refused. The 2 that stopped are the 2 present in the consent app's block list.
Section 4
Cookies set before consent
Recorded on first load, before consent. The 2 marked Necessary are permitted before consent. The other 9 are not.
| Cookie | Purpose | Category | Set by | Lasts |
|---|---|---|---|---|
_fbp.northlightcoffee.com |
Identifies the visitor to Meta for advertising measurement. | Marketing | Meta | 90d |
_ttp.northlightcoffee.com |
Identifies the visitor to TikTok for advertising measurement. | Marketing | TikTok | 395d |
__kla_idnorthlightcoffee.com |
Identifies the visitor across visits and can hold personal data once known. | Marketing | Klaviyo | 730d |
_gcl_au.northlightcoffee.com |
Attributes conversions to a Google advertisement. | Marketing | 90d | |
_hjSessionUser_18….northlightcoffee.com |
Identifies the visitor across Hotjar screen recordings. | Analytics | Hotjar | 365d |
_ga.northlightcoffee.com |
Distinguishes one visitor from another for Google Analytics. | Analytics | 730d | |
_ga_7QK2M4H1PZ.northlightcoffee.com |
Holds the Google Analytics session state. | Analytics | 730d | |
_shopify_y.northlightcoffee.com |
Shopify storefront analytics. | Analytics | Shopify | 365d |
_shopify_essentialnorthlightcoffee.com |
Maintains cart and checkout. Permitted before consent. | Necessary | Shopify | 365d |
cart_currencynorthlightcoffee.com |
Stores the selected checkout currency. Permitted before consent. | Necessary | Shopify | 14d |
Section 5
Method and limitations
- Each page was opened in a browser with no cookies and no history, from a California address. Each page used its own browser context.
- Each page was observed for four seconds. Every outbound request was recorded. No element was clicked, scrolled, or typed into.
- For the refusal test the homepage was loaded again, the reject control was pressed, and the page was reloaded in the same browser.
- Cookie descriptions are taken from the Open Cookie Database. Requests to unidentified hosts are reported as unrecognised and are excluded from all counts and from the verdict.
- This report records observations from one browser on one date. It is not legal advice.
Snitch · report SN-2026-0304-NLC · 2026-03-04 · run your own scan