Shopify Integration
Last updated: October 5, 2026
Use the Cybexo CMP theme app embed to connect a Shopify storefront to CYBEXO. The embed provides early IAB TCF initialization, Google Consent Mode v2 defaults, and synchronization with Shopify’s Customer Privacy API after a visitor completes a consent choice.
1. Create the storefront App
Section titled “1. Create the storefront App”- Open the CYBEXO dashboard and create an App for your Shopify storefront.
- Add the storefront domain and configure the banner’s regions and privacy options.
- Enable Google Consent Mode and configure the IAB TCF options required by your implementation.
- Copy the real CYB App ID, beginning with
CYB-.
A retired App ID must be replaced with a new CYB App. Changing an old ID’s prefix does not migrate it.
2. Enable the theme app embed
Section titled “2. Enable the theme app embed”- Install or open Cybexo CMP in Shopify.
- Go to Online Store → Themes → Customize → App embeds.
- Enable Consent management under Cybexo CMP.
- Paste the CYB App ID and save the active theme.
The cybexo.settings_id shop metafield takes priority when present. The embed keeps its existing setting key during upgrades, but the saved value must be a current CYB App ID.
Keep one consent installation per storefront. Remove an older direct loader, a duplicate tag-manager installation, or a competing CMP before enabling this embed. Adding the standalone Web loader alone does not provide this Shopify consent adapter.
The merchant setup guide provides the same steps in the app’s onboarding page.
3. Align Shopify privacy settings
Section titled “3. Align Shopify privacy settings”In Settings → Customer privacy, configure consent regions to match the regions where the CYBEXO banner collects consent. Use one storefront cookie banner and avoid a competing Shopify banner.
Configure Shopify’s data-sale opt-out page and Global Privacy Control behavior independently for applicable regions. The CYBEXO embed does not replace that separate flow.
4. Consent mapping
Section titled “4. Consent mapping”| Shopify category | CYBEXO mapping |
|---|---|
| Analytics | The independent Analytics preference must be permitted, together with the effective Google Analytics consent gate. |
| Marketing | All three Google advertising signals—ad_storage, ad_user_data, and ad_personalization—must be granted. |
| Preferences | The same conservative personalization gate as Marketing. TCF does not provide a separate Shopify preferences category. |
| Sale or sharing | Owned by Shopify’s independent data-sale opt-out and GPC flow. Generic Accept All, Reject All, and TCF customization leave sale_of_data unchanged. |
A completed visitor choice records the mapped categories through Shopify’s granular API. Initial loading, regional defaults, and restored CMP choices do not create new Shopify decisions. Shopify’s yes, no, and empty states are handled distinctly; the adapter does not read or write Shopify cookies directly.
If a stored CMP choice expires or becomes invalid, Shopify may retain an earlier platform choice. When Shopify’s Customer Privacy API is available, the adapter exposes this difference for review and waits for a fresh visitor decision. It does not fabricate a new platform decision during page load.
5. Startup and delivery behavior
Section titled “5. Startup and delivery behavior”The app embed uses Shopify’s compliance_head placement to install the TCF bootstrap and denied Google defaults synchronously. The Shopify bridge then loads before the single CYBEXO runtime loader. A competing CMP or loader prevents a second installation from taking ownership.
Place direct Google and tag-manager initialization after the CYBEXO bootstrap. Shopify’s compliance_head prioritizes the app embed’s placement among extensions; it does not move theme-owned scripts that already appear earlier in the HTML head. For a direct theme installation, place the measurement or tag-manager snippet immediately after the opening <body> tag, after the head’s CYBEXO bootstrap. Remove an earlier duplicate and verify the actual emitted HTML order. The adapter cannot reorder scripts in your theme.
Updates use the effective consent state after a completed visitor action. Repeated notifications are deduplicated. Delayed Shopify API availability retains the newest completed choice, writes are serialized, and retries are bounded. An invalidated choice cancels pending work. Failure is reported rather than represented as a successful platform update.
These read-only checks help diagnose the integration:
window.CybexoShopifyBridge?.status()window.Shopify?.customerPrivacy?.currentVisitorConsent?.()A synced status confirms the adapter’s platform readback for the last choice. review with platform-choice-needs-review means the CMP requires a fresh decision while Shopify retains an earlier grant. An error requires investigation; make a new explicit choice after correcting a temporary delivery problem.
6. Verify the published storefront
Section titled “6. Verify the published storefront”| Scenario | Expected result |
|---|---|
| Fresh visitor in a consent-required region | One banner; early TCF API and all four Google consent types initially denied; no fabricated Shopify decision. |
| Accept All | Permitted Google signals and the corresponding Shopify categories update after the choice. |
| Reject All | Google consent and mapped Analytics, Marketing, and Preferences categories are denied. Independent sale/share remains unchanged. |
| Withdraw advertising personalization | Marketing and Preferences are denied; a separately permitted Analytics choice remains independent. |
| Withdraw Analytics | Analytics is denied while other permitted choices remain intact. |
| Reload and reopen settings | The CMP restores the visitor’s current choice without recording a new Shopify choice merely because the page loaded. |
| Temporary API or runtime failure | No invented grant; errors remain visible and a new explicit decision can recover after the problem is fixed. |
Use Google Tag Assistant to verify that denied defaults are processed before your Google tags initialize, then check the effective consent state after acceptance and withdrawal. Confirm the actual emitted HTML order as well. A data-layer entry alone does not prove that a tag received or enforced the expected consent state. Run Runtime Verification as an additional installation check.
7. Checkout, pixels, and scope
Section titled “7. Checkout, pixels, and scope”Theme app embeds run on the online storefront, not Shopify checkout pages. Checkout and Shopify pixels use platform-managed environments. Verify each configured integration against Shopify’s customer privacy settings; do not assume the parent storefront’s scripts run inside a pixel sandbox or checkout.
Consent signals do not install or automatically control every third-party tag. Configure each tag or pixel to use its supported consent integration, and test both acceptance and withdrawal. A working integration is separate from any formal Google or IAB certification.
See Shopify’s Customer Privacy API and theme app extension configuration for the platform contracts.
8. Troubleshooting and support
Section titled “8. Troubleshooting and support”| Issue | Check |
|---|---|
| Banner missing | Active theme, enabled embed, current CYB App ID, storefront domain, regional settings, and existing saved choice. |
| Duplicate banner or blocked initialization | Remove the competing CMP, old direct loader, or duplicate tag-manager installation. |
| Shopify categories do not change | Inspect bridge status and API availability; complete a new explicit choice after correcting the problem. |
| Google tags disagree with the banner | Check effective consent and tag order in Tag Assistant, including each Shopify pixel integration. |
| Upgrade retains an older App ID | Create a current CYB App and update the saved embed value. Do not rename an old ID or install a second loader. |