Vafer holds known trackers until your shopper says yes, deletes their cookies when they say no, and shows you proof it's working — country by country, store by store.
Consent is a switch
Anyone can show a bar that says "We value your privacy." The question that matters to a regulator — and to your customers — is what happens after the click. Vafer treats every consent choice as a switch: Reject stops known trackers, removes their cookies, and is recorded. Accept turns them back on. Both are enforced in the browser, not just noted somewhere.
_ga, _fbp, _ttp deleted from device · decision recorded: DE · reject · 14:02:11
What you get
Scripts, invisible pixels and ad frames from known tracking services, plus anything you tag, held until consent.
Identifiers already on the device are removed, driven by your own cookie declaration. Necessary cookies never.
Opt-in for the EU, opt-out with the Do Not Sell link for the US, your call everywhere else. First matching rule wins.
Pre-filled declaration, one-click provider bundles, displayed in the banner or on any page with one line of HTML.
Every decision logged with time, region and choice; export as CSV. Deduplicated, and retention is yours to set.
Diagnostics shows what each country is served right now, and lists plainly what the app does not cover.
Honest by design
Vafer blocks known trackers plus anything you tag — and tells you, inside the app, exactly where its limits are. We'd rather you know.
How it works · no half-baked consent
The banner, per-country rules and cookie declaration arrive pre-set with the cookies every Shopify store sets.
Adjust your per-country rules, wording and colours. Add Google, Meta or TikTok to the declaration with one click.
Rules are applied at the edge, close to your shopper, in 9 languages picked from their browser. Global Privacy Control is honoured automatically.
Questions
No tool can promise that, and you should distrust any that does. Vafer enforces consent choices, keeps the records, and gives you the cookie disclosure — the technical requirements. Your policies and legal obligations remain yours; this is a tool, not legal advice.
The storefront script is 14 KB and loads without blocking your page. We're publishing measured before/after Core Web Vitals numbers rather than a claim.
Honest answer: code hard-wired into your theme runs before any consent app loads. Vafer gives you a one-line tagging convention to bring those scripts under consent control, and its Diagnostics screen flags the gap instead of hiding it.
No names, emails, or IP addresses. Consent records carry a one-way hash, the choice made, the region and the time — enough for an audit, nothing that identifies a person.
Free while in early access. Join the waitlist and we'll email you when your store's invite is ready.
A wafer is a cookie. We guard cookies. The pun was sitting right there and we refuse to apologise for taking it.
Claims we never make
Overclaiming is how consent vendors get sued. Here's what we say instead.
Join the waitlist and we'll email you when early access opens for your store. Nothing goes live until you press Publish.