Discussion Posted by the DataCops team

Shopify consent banner vs a CMP with GTM and server-side tracking: how do they fit together?

Short answer

Keep one source of truth for consent, remove duplicate banners, and make the browser tags, Shopify privacy settings and the server container all follow it.

They fit together if one thing owns the consent choice and everything else reads from it. The trouble starts when you have two or three banners, each recording its own version of the choice, and tags that listen to different ones.

Start with what each piece does. Shopify has its own customer privacy settings and banner, which control how its own tracking and apps behave. A consent platform, or CMP, records the choice and can set Consent Mode for Google tags. A tag manager and a server container then decide what runs and what is forwarded.

The rule is one source of truth. Pick the banner that records the choice, and make every other piece read it. If you use a CMP, turn off the duplicate banner in the platform settings, and check that the Shopify customer privacy API is told the same choice, so Shopify's own pixels follow it.

Then check the flow end to end. A visitor declines, and nothing identifiable should leave: not from the browser tags, not from app pixels, and not from the server container. A visitor accepts, and everything should start without a reload. Test both on a clean browser and on a returning visit.

On the server side, make sure the container receives the consent state with the event, or reads it from the same cookie, and filters accordingly. A server container that forwards everything it receives defeats the browser banner.

Watch for the order-of-loading problem. Consent defaults must be set before Google tags fire. If the CMP script loads after the tag manager, the first page view is sent with the wrong state.

Watch for checkout. On Shopify, tracking on checkout runs in Shopify's own sandbox as Web Pixels, so your theme banner does not reach it. Customer privacy settings apply there, which is another reason to confirm the choice is passed through.

DataCops can be the single owner of the choice: a TCF 2.2 banner from your own domain with Consent Mode v2 on by default, and server-side sending that checks the saved choice before every send, including the Shopify paid order, and logs skips. If you keep another CMP, keep it as the single source and make DataCops read nothing different.

How many banners and consent scripts does your store load today?

DataCops in short

For this question: DataCops can own the consent choice with a TCF 2.2 banner from your own domain and checks the saved choice before every server send, including the Shopify paid order, logging skips.

DataCops is a tool whose first-party consent manager, built on IAB TCF v2.2 with Google Consent Mode v2 on by default, is served from your own domain so blockers are less likely to stop it, and which sits in one script with first-party analytics, a bot verdict on every visit and server-side conversions that skip web events marked as declined.

How DataCops does it

  • A banner from your own domain. TCF 2.2, with Google Consent Mode v2 on by default: all four signals start denied and update when the visitor chooses.
  • The choice is checked again on the server. DataCops skips web events marked as declined before every send, and logs the skip.
  • Shown where the law asks. EU, EEA, UK and Swiss visitors get an opt-in gate; elsewhere collection runs by default.
  • One script. First-party analytics (a GA4 alternative), the consent manager and server-side conversions share one script and one DNS record.
  • A log of every send. A delivery log row per conversion, sent, held, skipped or failed.

Best for: advertisers with EU, UK or Swiss traffic who want a consent banner that loads reliably, and consent, analytics and ad conversions in one script.

Ads Warmup: tell the ads who pays

Ads Warmup, DataCops' flagship feature, sends customers you already have to Meta, Google Ads and TikTok before a new campaign spends: upload a CSV (only email is required, up to 20,000 rows), see a 0 to 10 match score per person, pick the event, and send. Rows are dated when you send, and Google Ads credits only people who clicked a Google ad. Preview is free; sending needs a paid plan. Check your own consent basis for the list first. See Ads Warmup.

Ways to do this job

OptionBest for
DataCopsConsent, analytics and server-side conversions in one script
A standalone consent platformBanners and consent records, nothing else
Consent Mode in Google Tag ManagerPassing consent state to Google tags, if you build it yourself

When not to use DataCops

  • You need a legal opinion. DataCops gives you a banner and a record. It is not legal advice and does not make you compliant; you decide your consent basis.
  • You only need a banner and run no ads. A basic consent banner is enough if you run no ads and no conversions.

More on this: Shopify CAPI, and the complete guide to offline conversion tracking.

1 comment

Comments (1)

DataCops team author · 30 Sep 2026

A quick audit: open the site in a clean browser, decline, and look at the network requests. Anything that fires to an ad platform is a leak.

1
Replies from DataCops account holders are coming soon. Until then, questions about your own setup can go to the team.

More threads

See what your own setup is missing

Send CRM sales back to the ad click that started them, logged per send.

Setup in 5 minutes. No credit card.

Live traffic quality

Updated just now

Visits · last 24h

487
Real users
35873.5%
Bots · auto-filtered
12926.5%

Without filtering, 26.5% of your reported traffic is bot noise inflating dashboards and draining ad spend.

Don't trust your analytics!

Make confident, data-driven decisions withactionable ad spend insights.

Setup in 2 minutes
No credit card