This article explains the legal frameworks the Cookiebot for Shopify app supports and which privacy tools are available depending on how your account was created.
Legal frameworks: GDPR and CCPA
The app supports two legal frameworks, managed on the Dashboard under Legal Frameworks:
GDPR
- Enabled by default on every plan. Your banner is GDPR-compliant out of the box: consent is collected before non-essential technologies run, and visitors can change or withdraw consent at any time via the privacy trigger.
- No configuration is required to meet GDPR transparency and consent requirements.
CCPA (Essential and Pro plans)
- CCPA support is included in the Essential and Pro plans. On the Dashboard, enable the CCPA Enabled toggle under Legal Frameworks.
- When enabled, you can adjust which visitors should see a CCPA-compliant banner (for example, visitors from California), while other visitors continue to see the GDPR banner.
- On the Free plan the CCPA toggle is visible but locked — upgrading to Essential or Pro unlocks it.
Privacy Policy Generator (app-created accounts)
When you create your account directly in the app (app-only account), the app includes a Privacy Policy Generator. It produces a privacy policy for your store based on the services detected on your site, which you can publish on a Shopify page and reference from your footer.
Cookie Declaration — only with a linked Cookiebot account
This is a key difference between the two account types:
App-only account (created in the app)
- The app does not declare individual cookies. It manages Third-Party Services — the technologies that read and write cookies (for example: Google Analytics, Meta Pixel, Shopify CDN).
- The Website Scan detects these services, you categorise them (Essential, Functional, Statistics, Marketing), and the banner presents consent per service category.
- Because consent is managed at service level, there is no per-cookie Cookie Declaration page in app-only mode.
Linked Cookiebot account (connector)
- When you link an existing Cookiebot account to the app, the Cookiebot account performs a cookie-level scan and maintains a full Cookie Declaration — the detailed list of every cookie, its provider, purpose, and expiry.
- The Cookie Declaration can then be displayed to your visitors as part of your setup, giving cookie-level transparency in addition to service-level consent.
Comments
0 comments
Please sign in to leave a comment.