Do you actually have a working cookie banner?
We scan your homepage for known consent-management tools and flag analytics or ad trackers running without one.
Enter your email to unlock every issue we found, with a specific explanation and fix for each.
We’ll also send occasional Shopify tips and Bespop product updates. Unsubscribe anytime. See our privacy policy.
Consent tooling vs. what’s actually tracking
A signature-based scan of your public homepage — we look for the consent tools you’d expect, and the trackers that shouldn’t run before consent.
Consent tool signatures
We detect the fingerprints of major consent platforms: Cookiebot, OneTrust, Iubenda, Termly, CookieYes, and Shopify’s own Customer Privacy API.
Analytics trackers
Google Analytics, Tag Manager, and Microsoft Clarity loaded on first paint — before any consent choice — are exactly what EU regulators look for.
Advertising pixels
Meta (Facebook) pixel, TikTok pixel, and similar ad trackers place identifying cookies. Running them without consent carries the highest fine risk.
The dangerous combination
The critical finding is trackers present + no consent tool detected. That’s the pattern that turns a routine complaint into a formal notice.
Selling into the EU, UK, or California makes this your problem
GDPR (EU/UK) and CCPA (California) don’t care where your business is registered — they care where your shoppers are. If your Shopify store ships to Europe and drops a Meta pixel before the visitor consents, you’re technically non-compliant on every single page view. Enforcement started with the giants, but national data authorities now process complaints against small merchants too, and the typical trigger is exactly one annoyed customer.
There’s also a commercial angle: consent banners are so universal now that their absence reads as carelessness to privacy-conscious shoppers, and some B2B buyers check for them before doing business at all.
What a proper consent setup gets you
A defensible compliance position
A working consent banner with real blocking behavior is the single clearest signal to a regulator that you take privacy seriously — it de-escalates complaints before they become cases.
Cleaner analytics data
Consent-mode analytics separates real engaged visitors from bounces. Many stores find their conversion metrics get more honest, not worse.
Customer trust where it counts
EU shoppers abandon carts on stores that feel non-compliant. A proper banner is table stakes for selling into those markets.
Protection as rules tighten
Privacy enforcement only moves one direction. A store that’s compliant today doesn’t scramble when the next regulation lands.
Three steps, about ten seconds
Paste your store URL
Any public storefront works — yourstore.com or the myshopify.com address. No login, no install, no admin access.
We scan what visitors see
Our scanner reads your public storefront the same way a browser and a search engine do, and runs every check server-side.
Get your score & full report
Your score and top issue appear instantly. Unlock the full issue-by-issue report — with a specific fix for each finding — with your email.
Common questions
Is this legal advice?
No. This is a technical signature scan — it tells you whether a known consent tool is detectable and whether common trackers are present. Whether your specific setup satisfies your specific jurisdictions is a question for counsel. But if this scan finds trackers with no consent tool, you have a concrete gap worth raising.
I use Shopify’s built-in cookie banner. Will you detect it?
Yes — we look for Shopify’s Customer Privacy API signatures. If you’ve enabled the native banner and we still don’t detect it, it may be limited to certain regions, which is worth double-checking in your settings.
Can the scan miss my consent tool?
Possible: it’s signature-based, and less common or custom-built banners may not match. A "not detected" result on a store that has a banner is worth verifying manually — but "not detected" plus visible trackers is a strong signal something is wrong.
What should I do if trackers run without consent?
Either enable a consent management tool that actually blocks scripts until consent (not just displays a banner), or move your pixels behind Shopify’s Customer Privacy API. Unlock the full report to see exactly which trackers we found.
Need a consent banner that matches your brand and actually blocks trackers until consent? Bespop builds and configures exactly this.