An online shop runs the heaviest tracker stack — analytics, remarketing pixels, heatmaps, chat, affiliates — but also cart and session cookies that do NOT need consent. A correct e-commerce cookie banner lets checkout work friction-free (essential cookies fire anyway) while blocking marketing trackers until consent. With Google Consent Mode v2 configured, Google Ads conversion data survives even when the visitor refuses — because a legally blocked pixel beats an illegally firing one.
Which cookies can fire and which must be blocked?
The classic worry for online shops is that a banner will "break" the cart or checkout. It won't: the cookies that make the shop work are strictly necessary and need no consent — they fire anyway. What must be blocked are the marketing and statistics trackers, until the visitor accepts.
| Cookie / tracker | Category | Needs consent? |
|---|---|---|
| Shopping cart, login session | Strictly necessary | No — without it the shop doesn't work |
| The cookie storing the consent choice | Strictly necessary | No |
Google Analytics (_ga) | Statistics | Yes |
Meta / Facebook Pixel (_fbp) | Marketing | Yes |
| Heatmaps, session replay | Statistics | Yes |
| Affiliate pixels, Ads remarketing | Marketing | Yes |
Not sure which category a cookie you see falls into? See the difference between essential and marketing cookies or look it up in the glossary of 1,300+ documented cookies.
How do you keep checkout friction-free?
The key is that blocking marketing trackers never touches the essential cookies. A well-built banner lets the cart, session and payment flow work normally regardless of what the visitor chooses at the banner — because those cookies are in the strictly-necessary category, exempt from consent.
In practice, this means you don't even have to force the visitor to click before adding a product to the cart. The banner asks for consent for analytics and marketing, while the sales funnel runs unimpeded. Friction only appears if someone misconfigures the banner and accidentally blocks a session cookie — which is why verification matters.
On the usual platforms (WooCommerce, Shopify, PrestaShop), the single-banner-script approach that blocks trackers before consent works regardless of theme or builder — see also the guide on adding a cookie banner on WordPress, which applies to WooCommerce shops too.
Why do you need Consent Mode v2 in a shop?
Here is the real stake for e-commerce: if you simply block Google's pixels when the visitor refuses, you lose all Google Ads conversion data for those visitors. Google Consent Mode v2 solves this — instead of cutting everything off, it sends signals about consent state, and Google can estimate conversions without cookies (cookieless pings) when you have no consent.
Consent Mode v2 became required for Google advertising features in the EEA in March 2024, so for a shop running Google Ads it is not optional. The banner must send all four signals: ad_storage, analytics_storage, ad_user_data, ad_personalization. FewCookies sends all four out of the box.
Want implementation detail? See the pillar guide on Consent Mode v2 in Romania and check your setup with the free Consent Mode v2 checker.
Why does a blocked pixel beat an illegal one?
It's tempting to let the Meta or Ads pixel fire from the first visit "so you don't lose remarketing data". It's the most common non-compliance scans find on shops — and it's a bad trade. Remarketing data collected without consent is data collected illegally: it doesn't build you an advantage, it builds you an exposure.
Any visitor can file a free complaint with ANSPDCP, and GDPR penalties can reach €20 million or 4% of global turnover. Against that, a few remarketing conversions "lost" until consent are a small price — especially since, with Consent Mode v2, you recover part of the data through modeling anyway. A properly blocked pixel is an asset; a pixel that fires illegally is a liability.
The fastest way to see what fires illegally on your shop right now is a free scan at /check, no account needed. It shows exactly which trackers load before consent — then you know what to block. For a banner with real blocking, all four Consent Mode v2 signals and bilingual policies, see FewCookies.
Frequently asked questions
Does the cookie banner break the cart or checkout?
No, if it is configured correctly. Cart, session and login cookies are strictly necessary and need no consent, so they fire anyway regardless of what the visitor chooses at the banner. The banner only blocks analytics and marketing. Friction only appears if someone accidentally blocks an essential cookie — which is why you verify with a scan.
Do I lose Google Ads conversion data if I block the pixels?
Not entirely, if you use Consent Mode v2. Instead of cutting everything off when the visitor refuses, Consent Mode sends signals about consent state and Google estimates conversions without cookies. Without Consent Mode, a simply blocked pixel means you lose those conversions — which is why the four signals matter in a shop.
Do WooCommerce and Shopify need different setups?
The principle is the same: let cart and session cookies fire, block marketing trackers until consent, and send the Consent Mode v2 signals. A single-script banner that blocks before consent works on both platforms, regardless of theme. Only where you add the script differs; real blocking is verified the same way, with a scan.
Want to see which cookies and trackers fire on your site before consent? The scan is free and needs no account. Check your site for free →