Poliogo

A Shopify cookie banner that blocks trackers before consent

Poliogo scans your Shopify project, classifies every cookie and tracking tag it finds, and gives you one script tag and hosts the policy pages for you. A store is a payment product before it is a website: Shopify sets its own session and analytics cookies, and the apps merchants install add advertising pixels that a consent banner has to hold back without breaking checkout.

One script tagBlocks before consentConsent Mode v2 · TCF 2.3
Shopify — first paint
Needed to run the siteAlways allowed
Login sessionSecurity checkLoad balancing
Measurement and advertisingHeld until consent
Shopify AnalyticsMeta PixelGoogle AdsTikTok Pixel
Lanes below the line stay held until a visitor chooses. Nothing above it ever waits.
16
frameworks and platforms covered
50+
tracking services classified
<5 min
signup to finished documents

Why most Shopify consent banners do not work

Marketing apps inject their pixels through the theme or through Shopify's script tag API. Meta, TikTok and Google Ads all end up firing on the product page, which is the exact moment an EU visitor has consented to nothing. A banner that renders after that has recorded a decision, not enforced one — and the enforcement is the part the ePrivacy Directive and the GDPR are actually about.

  • ✓Poliogo's banner intercepts the tracking scripts rather than sitting beside them, so a tag that has not been consented to never executes.
  • ✓Strictly necessary cookies — session, security, cart — are never held, so nothing about your product breaks while a visitor is deciding.
  • ✓Every choice is written to a consent record with a timestamp and what was on screen at the time, which is the evidence a regulator asks for.

Installing it in Shopify

Shopify has no repository to open a pull request against, so the install is one script tag and a link. The scan runs against your published site, which for a hosted platform is the only honest source of what your pages actually set.

  • ✓Essential commerce cookies — the cart, the session, the fraud check — are classified as strictly necessary and never blocked, so consent never costs you a sale.
  • ✓Advertising pixels installed by apps are held until a visitor agrees, and Google Consent Mode v2 signals go out either way so your ad reporting keeps modelling conversions.
  • ✓The policy pages live as normal Shopify pages, which is what the checkout footer links to, so nothing about the storefront changes shape.
1
Add your site

Point Poliogo at your published Shopify site. It loads the pages the way a visitor does and records every cookie and tag they actually set.

2
Review the cookie table

Each cookie is classified as strictly necessary, analytics or advertising, with its purpose and lifespan. Adjust anything you disagree with.

3
Paste one tag into layout/theme.liquid

It has to sit above the other tracking scripts — that ordering is the blocking mechanism, not a preference.

4
Link the policy pages

Poliogo hosts your privacy, cookie and terms pages and keeps them current. Put the links in your footer once and they never need republishing.

What you get on a Shopify project

The banner is one part of it. The scan underneath is what keeps the rest true.

It finds the trackers itself

Automatic

One scan of your Shopify project spots Shopify Analytics, Meta Pixel, Google Ads, TikTok Pixel and around fifty more — and sorts each into strictly necessary, analytics or advertising without being told.

It holds them until people agree

Most banners record a choice and let the scripts run regardless. This one gates execution, which is the behaviour the ePrivacy Directive describes and the one an auditor can actually observe.

Policy pages, not just a banner

Privacy, cookie and terms pages hosted for you and linked from your footer at /pages/privacy-policy — always the current version, with nothing to republish.

Geo-aware without a country list

European visitors get a consent gate, Californians an opt-out with Global Privacy Control honoured, Israeli visitors their own regime. GDPR is on every plan; CCPA and Israeli law from Starter.

It notices when you add something

Drift

A re-scan of your live site is diffed against the snapshot your documents were generated from, so a new tag becomes an update you approve rather than a quiet inaccuracy.

Consent Mode v2 and TCF 2.3

Google Consent Mode v2 signals go out on every plan, so your ad reporting keeps modelling conversions for visitors who decline. IAB TCF 2.3, which many EU ad networks require, is included from Pro Builder.

Questions people ask

Will the banner slow down my Shopify site?

No. The banner is a small async script that loads in the background and paints in one frame — it is not a framework, a UI library or a tag manager. Your Core Web Vitals do not move, which matters because for most sites the consent banner is the only third-party script on a page that has any reason to be there.

Does it actually block Shopify Analytics before someone agrees?

Yes, and that is the difference worth paying attention to. Marketing apps inject their pixels through the theme or through Shopify's script tag API. Meta, TikTok and Google Ads all end up firing on the product page, which is the exact moment an EU visitor has consented to nothing. Poliogo holds the non-essential scripts back until a visitor chooses, rather than asking politely while they run anyway — which is the part regulators look at.

Where does the privacy policy page end up in a Shopify project?

At /pages/privacy-policy. Poliogo hosts the page and keeps it current, so a policy change does not need a republish; you can also paste the generated HTML into a page under Online Store → Pages if you would rather own the file.

Do I need to know which cookies my site sets?

No — that is the scan's job. It finds the tracking your project actually uses (Shopify Analytics, Meta Pixel, Google Ads and around fifty more), sorts each one into strictly necessary, analytics or advertising, and writes the cookie table for you. You confirm the list rather than compiling it.

Is this free?

The Free plan covers one project with a privacy policy, a cookie policy, the banner and unlimited manual re-scans — no credit card, and not a trial. Paid plans add Terms of Service, automatic background monitoring, more projects and the MCP server for Cursor and Claude Code.

What happens when I add a new tracker later?

Poliogo re-scans your live site and flags the new tag, updates the cookie classification and the policy text, and shows you exactly what changed in plain English before anything is published. On Free you run that scan whenever you like; paid plans watch for it in the background.

Put a working consent banner on your Shopify site

Connect the project and see what the scan finds in under 60 seconds. Free plan, no credit card, and nothing is written or published until you approve it. Poliogo is a compliance management technology platform, not a law firm, and this page is not legal advice.

Start free — no credit card

Poliogo is an automated code analysis and document display tool, not a law firm. Poliogo does not provide legal advice, representation, or guarantees of statutory compliance, ADA/WCAG certification, or legal immunity. Visual banners and generated documents are advisory tools and do not substitute for professional legal review.