Skip to main content

Require consent to track visitors

Improve GDPR and data privacy compliance by avoiding data collection until users consent

Written by Joel Pednaud

Require consent to track limits what Alia stores about a visitor until that visitor has consented to being tracked. It strengthens your privacy position under the GDPR and similar laws, and your visitors won't notice any difference. Your popups run as usual and your reporting still shows how they perform.

The setting is off by default. You'll find it in Settings, under Require consent to track.
​

How this helps you comply

Privacy laws such as the GDPR and the ePrivacy Directive generally require consent before a website can store analytics data about a visitor. Most stores collect that consent with a cookie banner, but the banner only does its job if the apps on the page act on the visitor's answer.

This setting is how Alia acts on it. Until a visitor consents, Alia won't store their IP address, their location, their browser, or their Shopify customer details. It keeps a random visitor ID and a few basic facts, which means an unconsented visitor can't be identified from what Alia holds. Once consent arrives, Alia saves the date and time it was given, so you have a record of it.

You can also limit the requirement to the regions where it applies, so visitors elsewhere are tracked normally.

Alia doesn't show a cookie banner, and collecting valid consent from your visitors is still your responsibility. What this setting controls is what Alia does with the answer.
​

Turning it on

1. Go to Settings.

2. Navigate to the Tracking tab.

3. Find Require consent to track.

4. Check Require consent to track visitors.

5. Choose who the requirement applies to, and how consent is indicated.

6. Save.
​

Who this applies to

  • Determined by Shopify: Alia checks Shopify's Customer Privacy API and requires consent from the same visitors Shopify would show your cookie banner to. Choose this if you use Shopify's banner.

  • All visitors: Consent is required from everyone, wherever they are.

  • Only these countries: Consent is required from visitors in the countries you pick. The country list has an All EU countries option so you don't have to select them one at a time.

  • Everywhere except these countries: Consent is required from everyone apart from visitors in the countries you pick.

Alia works out a visitor's country from their IP address, which isn't stored. If it can't determine the country, it requires consent.
​

How consent is indicated

  • Shopify's cookie banner: Alia follows the visitor's answer to the analytics category in Shopify's banner. If they accept partway through their visit, Alia picks that up right away.

  • Custom code: Your own consent tool tells Alia when a visitor has consented by calling alia.push({ type: 'enableAnalyticsTracking' }).

  • Choose the one that matches the tool you use. Alia listens to that source only, so if you run your own consent platform, an old value in Shopify can't override what your platform reports.

What counts as consent

Alia treats a visitor as consented when any of these happens:

  • They accept analytics in Shopify's cookie banner, if you selected Shopify's banner as the source.

  • Your consent tool calls alia.push({ type: 'enableAnalyticsTracking' }), if you selected custom code.

  • They submit one of your popup forms. This applies either way. Filling in a form is a deliberate choice by the visitor, and the consent text on your form is what covers it, so it's worth checking that your forms say what you need them to say.
    ​

What Alia stores before a visitor consents

While a visitor requires consent but hasn't consented, Alia doesn't store:

  • their IP address

  • the country, region, or city taken from their IP address

  • their browser, operating system, or time zone

  • their Shopify customer ID or how many orders they've placed

  • their Shopify country, market, or language

  • which pages they viewed
    ​

Alia still records analytics events for these visitors, so their popup views, signups, and purchases are counted in your reports. The event is tagged as unconsented and carries only the visitor's country and device type, without personal details that describe the visitor.

This setting controls what Alia stores, not whether requests reach Alia's servers. A minimal request is still made, for example to check whether the setting is enabled at all. Those requests don't carry personal details that describe the visitor.
​

What keeps working

Most of Alia runs in the visitor's own browser, so turning this on doesn't change much day to day.

  • Popups look and behave exactly as they do now.

  • Signups, poll answers, and other form submissions are saved and passed to your email or SMS platform as usual.

  • Views, signups, conversions, and A/B test results are all counted, so your headline numbers stay accurate.

  • Targeting by most properties still works. Some targeting properties, listed below, are impacted.

What's reduced before a visitor consents

Reporting detail

For an unconsented visitor, you can break results down by country and device. You can't break them down by city, region, browser, operating system, landing page, UTM source, UTM medium, UTM campaign, or Shopify market and language. Those visitors won't appear in that breakdown.
​

Some targeting rules

These conditions have no data to read, so they won't match until the visitor consents:

  • Shopify number of orders

  • Klaviyo conditions, such as identified, in list, and in segment

  • Dotdigital conditions, such as in list

When the setting is on, Alia flags these conditions in the rule editor so you can see the effect while you're building a rule.

After a visitor consents

Alia records the visitor from that point on exactly as it would have without the setting, and saves the time consent was given. Your targeting rules and reports have full detail for them from their next page view.

Pages a visitor viewed before consenting aren't added retroactively, so Alia's history for them starts when they consented.

Did this answer your question?