Checked on 9/4/2026 · https://www.shopify.com/
Best-case value: the issues found are the minimum. Behind a tag manager or cookie banner, further services can load that this scan does not see — the real value is likely lower.
Critical items: 1 · also to review: 1.
| Tag manager: Google Tag Manager | -12 |
| Tag manager loads further scripts unchecked | -6 |
| 3 cookie(s) set on first load | -8 |
| Result | 74 / 100 |
Multiple services of the same kind count on a sliding scale. The score is a guide, not a legal verdict.
Cookies set on first load: _shopify_essential_, _shopify_s, _shopify_y
Analytics, advertising or social services load without any consent solution being detectable.
What you should do: Add a consent tool that loads these services only after active consent (not just displays a banner). Until then, remove the scripts or switch to consent-free alternatives.
§ 25 (1) TDDDG together with Art. 6 (1) GDPR — access to terminal equipment only with prior consent.
Set without a consent banner: _shopify_essential_, _shopify_s, _shopify_y. Only technically necessary cookies are permitted without consent.
What you should do: Check which of these cookies are really technically necessary (session, cart, language setting). Set everything else — especially analytics/marketing — only after consent.
§ 25 (2) TDDDG — exception only for strictly necessary cookies.
A text match of the linked privacy page found all detected providers. Whether the details are substantively complete is not checked by the match.
| Service | Purpose | Vendor | Country | Legal basis |
|---|---|---|---|---|
| Google Tag Manager www.googletagmanager.com |
loads further scripts — content depends on the configuration | Google LLC | US ⚠ | Consent required once it loads non-essential items |
⚠ Established outside the EU/EEA — the transfer needs an additional basis (e.g. the EU-US Data Privacy Framework or standard contractual clauses).
Weekly re-scan, email as soon as a new tracker appears — coming soon.
On 9/4/2026 we checked the HTML that www.shopify.com delivers on first load without a login (normal desktop browser, EU location). Detected: services embedded in the source (scripts, stylesheets, iframes, pixels), a cookie banner based on known providers, cookies from the server response, and links to the privacy policy and legal notice.
Not checked: anything that loads only via JavaScript, content behind a login, subpages, behaviour after clicking “Accept”/“Reject”, server locations and data-processing agreements. The result is an automated snapshot and not a substitute for legal advice.