App reviews, troubleshooting, and recommendations
Shopify, this question is for you...
If we have a website with European users, 'unambiguous, affirmative consent' to cookies is not optional. It's the law as per EU GDPR, with huge fines for non-compliance (or at best lots of time-wasting admin work if challenged on it).
Just like we can't run an online store without payment processing functionality, we can't run an online store selling to Europeans without a GDPR-compliant cookie consent mechanism.
So why does Shopify fob-off GDPR-compliant cookie consent to 3rd party developers?? This is core, non-optional functionality.
I've spent a lot of time looking at the 3rd party 'cookie bar/banner' offerings on the Shopify App Store:
Robust cookie consent should not be functionality that shop owners need to waste time searching Apps for. Or worse installing Apps that might be dangerously complacent, and indeed making their GDPR problems worse.
When is Shopify going to offer GDPR-compliant cookie consent as part of its core functionality?
You can create one for free using google optimize.
Thank you for posting the link to the app you are using. I hope Shopify will have a solution. it must be part of the out of the box store setup. i wish you much success with your Store.👍
I'm chiming in here to keep the attention of the Shopify staff on this point. It definitely needs to be a core feature!
Has anyone found an app that truly integrates with the Shopify Consent Tracking API? (https://shopify.dev/docs/themes/consent-tracking-api)
I’ve not been able to find any.
EDIT: Shopify seems to have their own app https://apps.shopify.com/customer-privacy-banner and from the description it seems they do integrate with the Consent Tracking API. Gonna give this a try
The Customer Privacy Banner works with Shopify’s Customer Privacy settings, allowing you to prevent customer tracking if a customer in the EU does not agree to it.
I took the time to compare several third-party apps. I only found one that tracks consent and offers the ability to disable scripts. They claim to be Customer Privacy API compliant.
But according to Cookiebot, we are still not compliant.
What I can gather from Shopify's own app, based on the reviews, is that it still has some issues to work out. But I am very glad they are working on a native solution.
I also just discovered the Customer Privacy options under Online Store > Preferences.
I took the time to compare several third-party apps. I only found one that tracks consent and offers the ability to disable scripts. They claim to be Customer Privacy API compliant.
But according to Cookiebot, we are still not compliant.
What I can gather from Shopify's own app, based on the reviews, is that it still has some issues to work out. But I am very glad they are working on a native solution.
I also just discovered the Customer Privacy options under Online Store > Preferences.
I’ve set up the one provided by Shopify and it seems to be working correctly. There is a problem with not being able to change the title of the Privacy Policy link.
The app mentioned above: GDPR/CCPA + Cookie Management does not prevent Google Analytics and Facebook JavaScript code from being downloaded before the consent is given so that’s not gonna fly for me.
Now there’s another app that claims to be using the Customer Privacy API
But their example store does not have google analytics or facebook pixel set up at all so I cannot confirm it is working as expected.
Hello
Do you have more info on this? I´m considering trying the GDPR/CCPA+Cookie Management and they say they do block google and facebook. Did you have managed to try it? Regarding other aspects they seen to be quite compliant (granular consent, ability to change consent, consent log etc).
Any feedback would be appreciated,
Cheers
Francisco
Hi There,
I am currently using teh "GDPR/CCPA + Cookie Management" app but it is really the best worst solution I could find on the market. So I am always scanning for new, better apps.
I think I have found quite a good one called "GDPR Cookie Bar +ePrivacy Page". This seems to include all relevant legal aspects and is for free too so I am going to switch to this one.
Cheers
Just posting to say "argh"
This cannot be optional and must be solved for EU vendors.
I've just inherited a store as part of a job. But there's no way any EU vendor should use Shopify if it is not watertight with GDPR.
Should be right at the top of the roadmap!
You can reach out to our support team we could work on that, try our free application
https://apps.shopify.com/responsive-cookie-consent-by-appifycommerce
but we can provide you satisfying solution though
@Appify_Commerce wrote:You can reach out to our support team we could work on that, try our free application
https://apps.shopify.com/responsive-cookie-consent-by-appifycommerce
but we can provide you satisfying solution though
Like many have pointed out in this thread most of the available apps (including yours) DO NOT make you GDPR compliant. Merely notifying the customer the page uses cookies (implied consent) is meaningless when it comes to being compliant. The customer needs to be able to give CLEAR consent by clicking a button before you start tracking them and that means NO tracking cookies are set and tracking scripts DO NOT run before they have consented. Apart from that, the user should be able to able to change their cookie settings after the initial consent.
Hi everyone,
I am starting a new shopify store in Feb 2021 and was also concerned about GDPR (for EU) and CCPA (for California).
Isn't having a privacy policy (the default one provided by shopify) sufficient to satisfy GDPR and CCPA regulations? I'm in California myself and when I go to Banana Republic's website (for example), there is no CCPA or cookies banner popping up at the bottom of the page. They only have a privacy policy link at the bottom of the page like everyone else. And when I checked out some GDPR banner apps on shopify, it doesn't look like a lot of shopify stores downloaded them. So I'm wondering if having a privacy policy page is enough. Aren't customers giving their consent by using the website?
Also, there are instructions for store owners (GDPR white pages) to contact shopify if a customer requests information about themselves or want to erase their data. I believe we go to the shopify admin, click customers, and click "request blah blah" which starts a process with shopify. I believe the instructions also mentioned that shopify sends this request to all the connected apps in our store (not sure about this one).
Any advice from shopify owners would be helpful. Thanks and take care.
I really hope @Shopify is looking into this, if only for their own bottom line. Merchants will be scared off if there is the slightest risk of getting one of these huge business ruining fines if they are not compliant.
It should be possible for Shopify to adjust the way app developers create apps and force them to add new steps where consent can (perhaps optionally) be obtained (or not) and cookies or other scripts can be then used (or not) depending on the user's answer. Of course, this will add work for the developers but there really is no other option if eCommerce on Shopify is to continue.
Hi everyone,
Same issue here: setting up the shop end of 2021 and cannot get fully GDPR compliant as Shopify is triggering cookies prior to consent (their script is read before mine so Cookiebot is too late to block them) and they send some data to a "not adequate" country (US).
I reached out to customer service but they are not really tackling the issue as they suggested that I install their customer banner app (which only shows a banner without taking any actions on the background to block cookies). Therefore, I insisted until they suggested that I talk to a "Shopify Expert" which costs between $50 to $1k just as a starting fee.
Honestly, I do not get why this is so complicated - I spent hours going on forums, trying different Cookie blockers apps, understanding GDPR regulations, etc. - and this should be a native functionality (at least for all the core functions - not the third party which are usually easy to block).
Please let me know if you have any information or found a solution.
Thank you,
Kevin
Hi everyone,
I've already tried inumerous apps, November 2, 2021, and no signal of a perfect solution.
Does anyone knows if this this code works for shopify?
It's not full compliant, but at least we can inform and have full control of the css, and we can also add "if" for languages.
Thank you
Hi Kevin,
Have you made any progress in this area? I have tried the GDPR/CCPA + Cookie Management app mentioned, but the issue is how they go about blocking cookies which ends up offsetting shopify analytics by a lot (since they delete cookies on every page load).
Curious if you have made any further progress in this area?
Thank you in advance!
Thanks to all who participated in our AMA with 2H Media on planning your 2023 marketing bu...
By Jacqui Mar 30, 2023Thanks to all Community members that participated in our inaugural 2 week AMA on the new E...
By Jacqui Mar 10, 2023Upskill and stand out with the new Shopify Foundations Certification program
By SarahF_Shopify Mar 6, 2023