Google tags need their own check
Consent signals do not install or automatically govern every third-party tag. Configure each tag or pixel to use its supported consent integration, and check its actual behavior after acceptance and withdrawal.
Connect your CYB App, enable the consent embed, and check how visitor choices reach Shopify and Google. Use the Google Tag Manager setup below for the reviewed Google consent route. It connects the shared CYBEXO Web CMP to Shopify and Google Consent Mode v2; formal platform approval is separate.
You need access to the CYBEXO dashboard and permission to manage your Shopify theme and customer privacy settings.
Open the CYBEXO dashboard, create an App for your Shopify storefront, and add its domain. Configure your banner, applicable regions, IAB TCF options, and Google Consent Mode.
Copy its CYB App ID, which begins with CYB-. Older App IDs need a new CYB App; changing the prefix of an old ID does not migrate it.
In Shopify, go to Online Store → Themes → Customize → App embeds. Enable Consent management under Cybexo CMP.
Paste your CYB App ID. Under Google integration, select Google Tag Manager and enter your GTM container ID. Save the active theme. If your store uses the cybexo.settings_id shop metafield, its value takes priority over the text field.
Remove an old direct CYBEXO script or another CMP installation from this theme. Check any tag-manager integration as well. A second consent manager can create competing banners and signals.
After an upgrade, confirm that the embed is still enabled and contains your current CYB App ID.
Open Settings → Customer privacy. Configure consent regions to match where your CYBEXO banner asks for consent. Use CYBEXO as the storefront banner and avoid displaying a competing Shopify cookie banner.
Keep Shopify’s data-sale opt-out page and Global Privacy Control settings configured separately for applicable regions.
In the chosen container, install the current CYBEXO CMP Gallery template. Use the same CYB App ID and fire one CMP tag on Consent Initialization – All Pages. Preview and publish the container. The app embed loads that container, and the template sets native Google defaults before loading the single managed CMP. Keep Google Consent Mode enabled in CYBEXO.
Remove duplicate container snippets, standalone CMP loaders and competing Google consent writers. Load measurement only after native defaults. The embed cannot reorder existing theme scripts; check the actual storefront in Tag Assistant.
Existing Direct Google tags installations keep their selected mode and require separate live verification. They are not automatically migrated. The native-GTM setup was verified with Web CMP 1.5.57 on October 11, 2026; later site or runtime changes require the affected checks to be repeated. Merchants do not select an engine release.
Test a fresh visit in a region where consent is required. Check acceptance, rejection, individual choices, reopening settings, and withdrawal. Verify your Google tags in Tag Assistant and repeat after a reload. Use the checklist below before relying on a store’s production configuration.
The embed records a Shopify choice after a visitor completes a choice in CYBEXO. Loading the page, ordinary restoration, or regional defaults does not create a new Shopify decision. A visitor’s completed choice in another open tab is synchronized, including Shopify categories, without another CYBEXO decision or receipt.
| Shopify category | What controls it |
|---|---|
| Analytics | The visitor’s separate Analytics preference, together with the effective Google Analytics consent gate. |
| Marketing | Advertising storage, advertising user data, and personalized advertising must all be permitted. |
| Preferences | The same conservative personalization gate as Marketing. TCF does not provide a separate Shopify preferences category. |
| Sale or sharing | Shopify’s independent data-sale opt-out page and Global Privacy Control. Accept All, Reject All, and TCF customization do not change this setting. |
If CYBEXO asks for a fresh decision after an earlier choice expires or becomes invalid, Shopify may still hold its earlier platform choice. The embed does not invent a new decision on page load; the visitor’s next completed choice updates Shopify.
Consent signals do not install or automatically govern every third-party tag. Configure each tag or pixel to use its supported consent integration, and check its actual behavior after acceptance and withdrawal.
A theme app embed runs on the online storefront, not Shopify checkout pages. Shopify pixels and checkout use platform-managed environments. Verify those integrations separately with the store’s customer privacy configuration.
Check the saved CYB App ID, the active theme’s app embed, the storefront domain, and the banner’s regional settings. A visitor with a valid saved choice may not see the first layer again; use the preferences entry to reopen it.
Keep one storefront consent installation. Remove an old direct script, duplicate tag-manager loader, or competing CMP. Save the active theme and reload before testing again.
Confirm the current app embed is enabled and Shopify’s customer privacy integration is available. Make a new explicit choice after a temporary failure. Contact support if the platform still does not confirm the choice; a banner closing by itself is not proof of synchronization.
The existing embed setting is retained, but the App ID must belong to a current CYB App. Replace a retired App ID through the dashboard setup flow. Do not rename an old ID manually or add another loader.
Share your storefront domain and the step that needs attention.