BFCM 2026 · Privacy readiness
Cyber Week did $44.2 billion online last year, and every one of those visits was also a pixel firing, a consent decision, or a privacy request landing in the week your team has the least time to look. Here are the five things worth nailing before the code freeze.
The setup
More visitors means more of everything else.
Marketing manages pixels, legal updates policies, and support handles requests, which works fine until BFCM makes all three spike at once. The tools running your store during that spike are the same ones that get looked at hardest when something goes wrong.
1 of 5
Audit your stack. All of it.
Another vendor probably got added since summer, and BFCM tends to add a few more: a countdown timer, a gift-guide quiz, an exit-intent popup, an affiliate network for the influencer codes. Some of them weren't installed by you at all, because vendors bring their own vendors. When you find names you don't recognize, trace each one back to whoever brought it in rather than assuming it belongs.
8 tools
23 scripts
$5M
2 of 5
Get your banner right. Then make the California call.
The consent banner is the most visible piece of your privacy program, and also the piece most likely to get quietly restyled when the BFCM theme goes live. The test is simple: saying no has to be as easy as saying yes.
$25,000
3 of 5
Make sure consent actually reaches your tags.
A banner that looks right and a banner that works are two different things, and the gap between them costs you in both directions: a "Decline" that fires anyway is exposure anyone can catch with a free browser extension, while an "Accept" that never fires is a November click you paid for and can't attribute.
9 months
4 of 5
Clear the request inbox before the rush.
More traffic means more privacy requests, and a growing share of them come from consumer tools that fire a request at every brand a person has ever bought from, whether or not it's Cyber Monday. The clock starts when the request lands, not when someone finally gets around to it.
Stop selling and sharing their data and suppress them from ad audiences, within 15 business days in California and with no extension available.
Remove them from Shopify, your ESP, SMS, the support desk, and the CRM, within 45 days in most states, with one extension if you explain why.
An email-marketing rule rather than a privacy request, and confusing the three is how customers who only wanted fewer ads end up deleted.
5 of 5
Catch up on what changed in 2026.
In 2021 there was one state privacy law. Today there are 20 in effect, with more scheduled for January 1, each handling data privacy a little differently.
If you sell supplements, skincare, wellness, or fitness gear and customer data flows into ad platforms, you may need consent first, and the usual size thresholds won't save you.
Roughly 800 Delaware visitors a month puts you in scope, and BFCM traffic alone can push you over lines you were under in March.
If you knowingly collect from under-16s in California, targeted ads need consent first, which is why one brand dropped the birthday field from its loyalty signup entirely.
$12.75M
FAQ
Questions that come up on almost every call.
Does the CCPA require a cookie banner?
No. No US state privacy law requires consent before collecting data; they require disclosure and an easy opt-out. Brands run opt-in banners for California anyway because of CIPA, the wiretapping law, where the argument is consent rather than disclosure.
What’s the difference between opt-in, opt-out, and "none"?
Opt-in: nothing fires until the visitor clicks Accept. Opt-out: everything fires by default and the visitor can turn it off. None: no banner, which is the legal default in every US state. Set it per state; Shopify’s built-in banner is one setting for the whole world.
Someone opts out. Do I delete them from Shopify?
No. Opt-out and deletion are different requests. Leave the customer record alone and suppress them from advertising. Deleting someone who only wanted fewer retargeting ads can have unintended consequences and create its own violation.
What is a GPC signal and why does my banner need to show it?
Global Privacy Control is a browser setting that opts the visitor out of data sales and targeted ads on every site. Honor it as if they clicked it themselves, and since January 2026, California requires you to visibly confirm you did.
Can any tool guarantee I won’t get a CIPA demand letter?
No. Anyone can send a letter. What you can do is look well-handled to someone scanning for easy targets: an opt-in banner in California and Florida, pixels that actually wait for consent, and a current policy. That’s what most letters are screening for.
We’re on the Shopify default banner. Is that enough?
It’s a start, and better than nothing for CIPA purposes. Its limits: one setting for every region, no state-specific notices, no request workflow. Most brands outgrow it after the first letter or the first real request.
Does my privacy vendor charge more when traffic spikes?
Some price on traffic, page views, or seats, which means Cyber Week can show up on your next invoice. Worth checking the contract before November. TrueVault charges a flat rate that doesn’t move with traffic, seats, or usage.
My tool has shown zero requests for months. Is that good?
Maybe. On a site with real traffic, a long run of zeros can also mean the consent script isn’t loading and opt-out signals aren’t being recorded. Check the script is on the page, especially after any theme change.
the recap
Most teams don't need a privacy lecture so much as help understanding what matters and what to fix first. TrueVault's team will walk your live site with you, Tag Assistant open, and tell you what's fine and what needs fixing before the freeze.

