In development, not yet available to install
Blocking that does not slow the page.
ConsentAlly is being built to hold every tracking script, iframe, image and network request until the visitor has decided, using a small synchronous script that runs before anything else on the page; the banner itself loads afterwards, so blocking and page speed do not trade against each other.
The usual trade-off
To stop a tracker, a consent tool has to run before the tracker does. The usual answer is one large script that blocks rendering until it has loaded. The other usual answer is to load the tool asynchronously and accept that trackers fire in the gap. Either the page is slower or the blocking leaks.
How ConsentAlly will do it
- A synchronous script of under 5 KB will run first. It will read any stored decision, read the browser's Global Privacy Control signal, set the Google Consent Mode defaults, and intercept scripts, iframes, images,
fetchandXMLHttpRequestcalls and beacons, holding anything the visitor has not allowed. - The banner and the preference centre will arrive afterwards, asynchronously, in under 30 KB compressed. They will never block the page's first paint.
- When the visitor decides, held elements will be released category by category and vendor by vendor, without reloading the page.
When the configuration cannot load
ConsentAlly is designed to fail closed. If the store's configuration has not arrived yet, or never arrives, known trackers from a built-in list and every unknown third party will stay held, while the store's own files and the platform's assets are allowed, so the store keeps working and nothing leaks while it waits.
Scripts nobody has checked
A script the configuration does not know will be held and treated as marketing. It will appear in the dashboard with the page it was found on, and the store owner will classify it with one click; that decision will be recorded. Unknown means held, not allowed.
On Shopify
The script will ship inside the Shopify app as an app embed, so it loads ahead of theme scripts. On the checkout, theme scripts and tag managers do not run; what runs there are Shopify's web pixels, in Shopify's sandbox, and consent for them will be enforced through the Customer Privacy API, which will receive the visitor's decision from ConsentAlly. The Shopify page explains the gap between Shopify's own banner and tags loaded through Google Tag Manager.