Require consent to track limits what Alia stores about a visitor until that visitor has consented to being tracked. It strengthens your privacy position under the GDPR and similar laws, and your visitors won't notice any difference. Your popups run as usual and your reporting still shows how they perform.
The setting is off by default. You'll find it in Settings, under Require consent to track.
How this helps you comply
Privacy laws such as the GDPR and the ePrivacy Directive generally require consent before a website can store analytics data about a visitor. Most stores collect that consent with a cookie banner, but the banner only does its job if the apps on the page act on the visitor's answer.
This setting is how Alia acts on it. Until a visitor consents, Alia won't store their IP address, their location, their browser, or their Shopify customer details. It keeps a random visitor ID and a few basic facts, which means an unconsented visitor can't be identified from what Alia holds. Once consent arrives, Alia saves the date and time it was given, so you have a record of it.
You can also limit the requirement to the regions where it applies, so visitors elsewhere are tracked normally.
Alia doesn't show a cookie banner, and collecting valid consent from your visitors is still your responsibility. What this setting controls is what Alia does with the answer.
Turning it on
1. Go to Settings.
2. Navigate to the Tracking tab.
3. Find Require consent to track.
4. Check Require consent to track visitors.
5. Choose who the requirement applies to, and how consent is indicated.
6. Save.
Who this applies to
Determined by Shopify: Alia checks Shopify's Customer Privacy API and requires consent from the same visitors Shopify would show your cookie banner to. Choose this if you use Shopify's banner.
All visitors: Consent is required from everyone, wherever they are.
Only these countries: Consent is required from visitors in the countries you pick. The country list has an All EU countries option so you don't have to select them one at a time.
Everywhere except these countries: Consent is required from everyone apart from visitors in the countries you pick.
Alia works out a visitor's country from their IP address, which isn't stored. If it can't determine the country, it requires consent.
How consent is indicated
Shopify's cookie banner: Alia follows the visitor's answer to the analytics category in Shopify's banner. If they accept partway through their visit, Alia picks that up right away.
Custom code: Your own consent tool tells Alia when a visitor has consented by calling
alia.push({ type: 'enableAnalyticsTracking' }).Choose the one that matches the tool you use. Alia listens to that source only, so if you run your own consent platform, an old value in Shopify can't override what your platform reports.
What counts as consent
Alia treats a visitor as consented when any of these happens:
They accept analytics in Shopify's cookie banner, if you selected Shopify's banner as the source.
Your consent tool calls
alia.push({ type: 'enableAnalyticsTracking' }), if you selected custom code.They submit one of your popup forms. This applies either way. Filling in a form is a deliberate choice by the visitor, and the consent text on your form is what covers it, so it's worth checking that your forms say what you need them to say.
What Alia stores before a visitor consents
While a visitor requires consent but hasn't consented, Alia doesn't store:
their IP address
the country, region, or city taken from their IP address
their browser, operating system, or time zone
their Shopify customer ID or how many orders they've placed
their Shopify country, market, or language
which pages they viewed
Alia still records analytics events for these visitors, so their popup views, signups, and purchases are counted in your reports. The event is tagged as unconsented and carries only the visitor's country and device type, without personal details that describe the visitor.
This setting controls what Alia stores, not whether requests reach Alia's servers. A minimal request is still made, for example to check whether the setting is enabled at all. Those requests don't carry personal details that describe the visitor.
What keeps working
Most of Alia runs in the visitor's own browser, so turning this on doesn't change much day to day.
Popups look and behave exactly as they do now.
Signups, poll answers, and other form submissions are saved and passed to your email or SMS platform as usual.
Views, signups, conversions, and A/B test results are all counted, so your headline numbers stay accurate.
Targeting by most properties still works. Some targeting properties, listed below, are impacted.
What's reduced before a visitor consents
Reporting detail
For an unconsented visitor, you can break results down by country and device. You can't break them down by city, region, browser, operating system, landing page, UTM source, UTM medium, UTM campaign, or Shopify market and language. Those visitors won't appear in that breakdown.
Some targeting rules
These conditions have no data to read, so they won't match until the visitor consents:
Shopify number of orders
Klaviyo conditions, such as identified, in list, and in segment
Dotdigital conditions, such as in list
When the setting is on, Alia flags these conditions in the rule editor so you can see the effect while you're building a rule.
After a visitor consents
Alia records the visitor from that point on exactly as it would have without the setting, and saves the time consent was given. Your targeting rules and reports have full detail for them from their next page view.
Pages a visitor viewed before consenting aren't added retroactively, so Alia's history for them starts when they consented.
