English
consentglass · GDPR scanner for websites

www.shopify.com

Checked on 9/4/2026 · https://www.shopify.com/

C
74 / 100
No cookie banner in the initial HTML · Privacy-policy link: yes · Legal-notice link: no

Best-case value: the issues found are the minimum. Behind a tag manager or cookie banner, further services can load that this scan does not see — the real value is likely lower.

Critical items: 1 · also to review: 1.

How is the score calculated? (100 starting points)
Tag manager: Google Tag Manager-12
Tag manager loads further scripts unchecked-6
3 cookie(s) set on first load-8
Result74 / 100

Multiple services of the same kind count on a sliding scale. The score is a guide, not a legal verdict.

What this scan doesn't see consentglass reads only the first, unmodified HTML — without executing JavaScript. A tag manager is embedded — which services it loads is decided only in the browser. So a good result here doesn't automatically mean “GDPR-compliant”. Monitoring runs the full test with JavaScript enabled.
Tiefen-Scan (mit JavaScript) Lädt die Seite wie ein echter Browser, führt JavaScript aus und protokolliert, welche Dritt-Dienste vor einer Einwilligung feuern und wie sich das Banner beim Ablehnen verhält. Dauert etwa eine Minute.

Cookies set on first load: _shopify_essential_, _shopify_s, _shopify_y

Findings

Critical

1 services requiring consent, no cookie banner in the initial HTML

Analytics, advertising or social services load without any consent solution being detectable.

What you should do: Add a consent tool that loads these services only after active consent (not just displays a banner). Until then, remove the scripts or switch to consent-free alternatives.

§ 25 (1) TDDDG together with Art. 6 (1) GDPR — access to terminal equipment only with prior consent.

To review

3 cookie(s) set on first load

Set without a consent banner: _shopify_essential_, _shopify_s, _shopify_y. Only technically necessary cookies are permitted without consent.

What you should do: Check which of these cookies are really technically necessary (session, cart, language setting). Set everything else — especially analytics/marketing — only after consent.

§ 25 (2) TDDDG — exception only for strictly necessary cookies.

OK

Detected services are named in the privacy policy

A text match of the linked privacy page found all detected providers. Whether the details are substantively complete is not checked by the match.

Next steps

  1. 1 services requiring consent, no cookie banner in the initial HTML. Add a consent tool that loads these services only after active consent (not just displays a banner). Until then, remove the scripts or switch to consent-free alternatives.
  2. 3 cookie(s) set on first load. Check which of these cookies are really technically necessary (session, cart, language setting). Set everything else — especially analytics/marketing — only after consent.

Third parties detected (1)

ServicePurposeVendorCountryLegal basis
Google Tag Manager
www.googletagmanager.com
loads further scripts — content depends on the configuration Google LLC US ⚠ Consent required once it loads non-essential items

⚠ Established outside the EU/EEA — the transfer needs an additional basis (e.g. the EU-US Data Privacy Framework or standard contractual clauses).

Monitor this URL automatically?

Weekly re-scan, email as soon as a new tracker appears — coming soon.

Method & limits

On 9/4/2026 we checked the HTML that www.shopify.com delivers on first load without a login (normal desktop browser, EU location). Detected: services embedded in the source (scripts, stylesheets, iframes, pixels), a cookie banner based on known providers, cookies from the server response, and links to the privacy policy and legal notice.

Not checked: anything that loads only via JavaScript, content behind a login, subpages, behaviour after clicking “Accept”/“Reject”, server locations and data-processing agreements. The result is an automated snapshot and not a substitute for legal advice.

Scan another website