You're set for BFCM.
22 of 22, 57 days to spare. Print it and date it, and re-run this after any theme change.

BFCM 2026 · Privacy readiness

Your store is ready for BFCM. Is your privacy setup?

Cyber Week did $44.2 billion online last year, and every one of those visits was also a pixel firing, a consent decision, or a privacy request landing in the week your team has the least time to look. Here are the five things worth nailing before the code freeze.

$5.1M
/min
Shopify peak, 12:01pm Black Friday
94,900
Merchants had their best day ever
2.2T
Edge requests your consent script sits in front of

The setup

More visitors means more of everything else.

Marketing manages pixels, legal updates policies, and support handles requests, which works fine until BFCM makes all three spike at once. The tools running your store during that spike are the same ones that get looked at hardest when something goes wrong.

Signal
2025 number
Why it matters for privacy
US online spend, Thanksgiving–Cyber Monday · Adobe
$44.2B, up 7.7%
Every visit is a consent decision and a tracking event
Shopify BFCM weekend · Shopify
$14.6B · 81M+ buyers
Shopify is where most lean ecommerce teams live
Shopify edge requests over the weekend · Shopify
2.2 trillion
Raw traffic, the load your consent script sits in front of
Browsing before buying, Oct 1–Nov 15 · Salesforce
Page views ~2×, sales up 3%
The research window is when new pixels get added and nobody notices
Cyber Monday online shoppers · Digital Commerce 360
75.9M, up from 64.4M
More people, more devices, more GPC signals to honor
Traffic from AI assistants to US retail · Adobe
Up 693% YoY
A new referral channel that came with new scripts on a lot of sites
The five checks below are in the order we'd run them, and together they take only a few hours.

1 of 5

Audit your stack. All of it.

Another vendor probably got added since summer, and BFCM tends to add a few more: a countdown timer, a gift-guide quiz, an exit-intent popup, an affiliate network for the influencer codes. Some of them weren't installed by you at all, because vendors bring their own vendors. When you find names you don't recognize, trace each one back to whoever brought it in rather than assuming it belongs.

The list you think you have
Shopify
GA4
Meta pixel
Klaviyo
Google Ads
Zendesk
Stripe
TikTok

8 tools

What a scan actually finds
…those 8
Session replay
Chat widget
Countdown timer
Exit-intent popup
Affiliate network
Quiz app
Heatmaps
Search bar
Reviews app
Paused UTM tool
Agency tag
A connector nobody recognizes

23 scripts

Signal
1 of 5
Pull every script loading on your site
Not just the ones in your tag manager: agency installs, Shopify-injected apps, server-side partners, and anything hard-coded into the theme all count.
Dev
Compare that list to your privacy policy and data map
If a tool is live and not disclosed, that's the gap.
Legal
Delete paused tags
They have a way of showing up in scans long after anyone remembers turning them off.
Dev
Get it in writing that departed vendors deleted your customer data
Ask any AI vendor you’re leaving whether it trained on that data, and whether that stops.
Legal
Put agencies, contractors, and freelancers with store-admin access on the vendor list
If they can see customer data, they belong there, and California wants specific contract language with them.
Legal

$5M

European Wax Center settled for $5 million over tracking pixels run the way almost every site runs them. Fines count per violation, and page views nearly double in November.

2 of 5

Get your banner right. Then make the California call.

The consent banner is the most visible piece of your privacy program, and also the piece most likely to get quietly restyled when the BFCM theme goes live. The test is simple: saying no has to be as easy as saying yes.

We use cookies to run the store and measure our marketing. You can say no.

Opt-out signal honored for this browser
Marketing tags fire, once
each.
Nothing fires. Signal
honored.
Try it: this one passes

Same color, same size, same number of clicks, plus the note California has required since January 2026 confirming a browser opt-out signal was honored. Click either button to see what would fire.

What to check
1 of 5
Accept and Decline match
A brand-colored Accept next to a gray Decline is the pattern that gets flagged most often.
Marketing
Nothing is pre-checked, and the words say what the button does
Be literal: "opt out of targeted advertising and data selling."
Marketing
The sale theme didn’t restyle it
Sale themes love a big red button, so look at the banner on the live theme, on a phone, before launch.
Marketing
The welcome pop-up waits its turn
Someone who came from an ad gives you about a second, and two overlays stacked on a phone screen can lock it entirely, so sequence the pop-up after the banner.
Dev
You’re running one banner, not two
Three of five brands we spoke with this month were paying for a second one they didn’t need.
Marketing
Where the letters come from
100+ wiretap filings
10 to 99
Under 10

No state privacy law actually requires a banner; the demand letters come from wiretapping claims instead, and those cluster hard. California has close to 4,000 filings since 2022 and Florida over 800, after which there's a steep drop to Illinois, New York, and Pennsylvania. How you set your banner in those states is a call for you and your counsel, but the map tells you where the question is worth asking.

Hover a state for its filing count.
Source: Fisher Phillips Digital Wiretapping Litigation Map, digital-privacy matters filed since May 31, 2022, as of July 2026.

$25,000

What a single demand letter typically costs to settle. Peak traffic is when the sampling happens, so it's worth getting this right before then.
TrueVault lets you set banner mode state by state, so whatever you and counsel decide, it can be applied only where you decide it. See how

3 of 5

Make sure consent actually reaches your tags.

A banner that looks right and a banner that works are two different things, and the gap between them costs you in both directions: a "Decline" that fires anyway is exposure anyone can catch with a free browser extension, while an "Accept" that never fires is a November click you paid for and can't attribute.

Broken: pixels don't wait
Visitor lands
GTM already loaded
Pixel fires
…then the banner shows
By the time the visitor says no, the data has already left.
Working: the order holds
Consent script, in the head
Visitor decides
GTM hears it
Tags fire, or don't
Banner first, decision second, tags last, and the checks below confirm that order actually holds on your site.
What to check, with the question to forward
0 of 4
Is the consent script still on the page at all?
Theme changes drop it more often than anyone expects, and nothing visibly breaks when they do.
Marketing
Ask your dev: "Did the consent script and the footer privacy links carry over to the new theme?"
Copy
Nothing is pre-checked, and the words say what the button does
Be literal: "opt out of targeted advertising and data selling."
Marketing
Ask your dev: "In Tag Assistant, does the default consent state show as denied before I click anything?"
Copy
The sale theme didn’t restyle it
Sale themes love a big red button, so look at the banner on the live theme, on a phone, before launch.
Marketing
Ask your dev: "Is the consent script in the head, above GTM, on the current version, and not set to defer?"
Copy
The welcome pop-up waits its turn
Someone who came from an ad gives you about a second, and two overlays stacked on a phone screen can lock it entirely, so sequence the pop-up after the banner.
Dev
You’re running one banner, not two
Three of five brands we spoke with this month were paying for a second one they didn’t need.
Marketing

9 months

A brand relaunched its theme in January, and for months the weekly summary showed zero requests, which everyone read as good news. What it actually meant was that the script wasn't loading, so roughly two dozen opt-out signals a day went unhonored for nine months. A BFCM theme is a theme relaunch, and it deserves the same check.
Rather have someone run this check with you? Book time

4 of 5

Clear the request inbox before the rush.

More traffic means more privacy requests, and a growing share of them come from consumer tools that fire a request at every brand a person has ever bought from, whether or not it's Cyber Monday. The clock starts when the request lands, not when someone finally gets around to it.

Type
From
Received
due
Status
Opt-out
GPC signal · returning visitor
Nov 12
Dec 3
Auto-honored
Deletion
Consumer privacy tool, on behalf of a 2023 buyer
Nov 18
Jan 2
Open
Deletion
Customer, via privacy@ inbox
Oct 2
Nov 16
Overdue
Access
Customer, verified
Nov 21
Jan 5
Open
The row you don't want: an October deletion request that aged past due while everyone shipped the sale.
Opt-out

Stop selling and sharing their data and suppress them from ad audiences, within 15 business days in California and with no extension available.

Deletion

Remove them from Shopify, your ESP, SMS, the support desk, and the CRM, within 45 days in most states, with one extension if you explain why.

Unsubscribe

An email-marketing rule rather than a privacy request, and confusing the three is how customers who only wanted fewer ads end up deleted.

What to do
0 of 4
Get the inbox to zero before Thanksgiving
So that anything arriving during peak is visible on its own instead of buried under October.
Support
Bulk-process the opt-outs once a week
They're the most common request and the fastest to close.
Support
Name the owner for the holiday weeks, and a backup
Assign it on purpose rather than by default, and forward privacy@ into your ticketing system so it doesn’t depend on one inbox.
Support
Turn on identity verification and keep the audit trail
Unverified requests expire on their own instead of sitting in the queue as false work, and if anyone asks in December you want a log rather than a Slack reconstruction.
Dev
TrueVault batches opt-outs and exports the CSV for your ad-platform exclusion lists. Ask your success manager

5 of 5

Catch up on what changed in 2026.

In 2021 there was one state privacy law. Today there are 20 in effect, with more scheduled for January 1, each handling data privacy a little differently.

In effect: 20 states
Landing 2027 to 2028
January 1, 2026
Indiana, Kentucky, Rhode Island live. Plus California’s rule: visibly confirm when a browser’s opt-out signal is honored.
August 1, 2026
California’s DROP enforceable. Data brokers face $200 per request, per day. First question: does California think you’re one?
January 1, 2027
Oklahoma, Louisiana, Delaware’s rewrite, SB 690: three laws land while your team is still on holiday.
May 1, 2027 · January 1, 2028
Alabama: 25,000-resident threshold, 45-day cure. Vermont: health-data rules that apply regardless of size.
Worth a second look
Vermont counts shopping as health data

If you sell supplements, skincare, wellness, or fitness gear and customer data flows into ad platforms, you may need consent first, and the usual size thresholds won't save you.

Worth a second look
Delaware's threshold is low

Roughly 800 Delaware visitors a month puts you in scope, and BFCM traffic alone can push you over lines you were under in March.

Worth a second look
Minors change your banner

If you knowingly collect from under-16s in California, targeted ads need consent first, which is why one brand dropped the birthday field from its loyalty signup entirely.

What to do
0 of 4
Re-check your thresholds for every state you ship to
Give the policy a section per state
Deep-link the California notice from the footer
Put January 1 on the calendar now

$12.75M

GM, the largest CCPA fine to date
A brand relaunched its theme in January, and for months the weekly summary showed zero requests, which everyone read as good news. What it actually meant was that the script wasn't loading, so roughly two dozen opt-out signals a day went unhonored for nine months. A BFCM theme is a theme relaunch, and it deserves the same check.

FAQ

Questions that come up on almost every call.

Does the CCPA require a cookie banner?

No. No US state privacy law requires consent before collecting data; they require disclosure and an easy opt-out. Brands run opt-in banners for California anyway because of CIPA, the wiretapping law, where the argument is consent rather than disclosure.

What’s the difference between opt-in, opt-out, and "none"?

Opt-in: nothing fires until the visitor clicks Accept. Opt-out: everything fires by default and the visitor can turn it off. None: no banner, which is the legal default in every US state. Set it per state; Shopify’s built-in banner is one setting for the whole world.

Someone opts out. Do I delete them from Shopify?

No. Opt-out and deletion are different requests. Leave the customer record alone and suppress them from advertising. Deleting someone who only wanted fewer retargeting ads can have unintended consequences and create its own violation.

What is a GPC signal and why does my banner need to show it?


Global Privacy Control is a browser setting that opts the visitor out of data sales and targeted ads on every site. Honor it as if they clicked it themselves, and since January 2026, California requires you to visibly confirm you did.

Can any tool guarantee I won’t get a CIPA demand letter?


No. Anyone can send a letter. What you can do is look well-handled to someone scanning for easy targets: an opt-in banner in California and Florida, pixels that actually wait for consent, and a current policy. That’s what most letters are screening for.

We’re on the Shopify default banner. Is that enough?

It’s a start, and better than nothing for CIPA purposes. Its limits: one setting for every region, no state-specific notices, no request workflow. Most brands outgrow it after the first letter or the first real request.

Does my privacy vendor charge more when traffic spikes?

Some price on traffic, page views, or seats, which means Cyber Week can show up on your next invoice. Worth checking the contract before November. TrueVault charges a flat rate that doesn’t move with traffic, seats, or usage.

My tool has shown zero requests for months. Is that good?

Maybe. On a site with real traffic, a long run of zeros can also mean the consent script isn’t loading and opt-out signals aren’t being recorded. Check the script is on the page, especially after any theme change.

the recap

1
Audit your stack: every script, traced back to whoever added it.
2
Get the banner symmetric, then set California and Florida to opt-in.
3
Prove consent reaches your tags on the live sale theme, in Tag Assistant.
4
Inbox to zero before Thanksgiving, with a named owner for the holidays.
5
Re-check thresholds and notices against 20 live laws, and January 1.

Most teams don't need a privacy lecture so much as help understanding what matters and what to fix first. TrueVault's team will walk your live site with you, Tag Assistant open, and tell you what's fine and what needs fixing before the freeze.