Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Trackify X is a Shopify app that manages the Meta (Facebook) Pixel and the Meta Conversions API for online stores, and can also deploy TikTok, Google and Snapchat pixels. It powers advertising conversion tracking and audience building, setting Meta advertising cookies in the browser and sending event data server side to Meta. Because it relies on advertising cookies and shares data with platforms in the United States, it requires prior consent and careful transfer safeguards under European privacy law.
Trackify X is a Shopify app that manages advertising tracking for online stores. Its core job is to install and orchestrate the Meta (Facebook) Pixel and the Meta Conversions API, and it can also deploy TikTok, Google and Snapchat pixels from one place. Store owners use it to measure advertising conversions, build audiences and optimise campaigns. In practice it injects tracking tags into the storefront and forwards shopping events to the advertising platforms.
The Meta Pixel sets advertising cookies in the visitor browser, most notably the _fbp cookie and, when a click identifier is present, the _fbc cookie. Trackify X also reads shop events such as page views, product views, add to cart, checkout and purchase. Through the Conversions API it sends these events server side to Meta, often together with hashed customer identifiers such as email, phone or order value. This combination links browsing and purchase behaviour to advertising profiles held by Meta.
Advertising pixels and cookies fall squarely under article 5(3) of the ePrivacy Directive, which requires prior consent before any non essential storage or access on the device. The personal data processed for advertising also needs a lawful basis under the GDPR, and for marketing that basis is consent under article 6(1)(a). A common mistake is to assume that moving to the Conversions API removes these duties. It does not, because the server side flow processes the same personal data for the same advertising purpose.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
You must obtain freely given, specific and informed consent before the pixel fires and before the Conversions API sends data. In practice this means gating Trackify X behind a consent management platform and, where you use Meta tools, supporting the IAB Transparency and Consent Framework signals. Refusing should be as easy as accepting, and the choice must be respected on both the browser and server side paths. Keep a record of consent so you can demonstrate compliance.
Event data sent to Meta reaches Meta Platforms in the United States. These transfers rely on the EU US Data Privacy Framework where Meta is certified, backed up by the EU Standard Contractual Clauses. The Conversions API additionally transfers hashed customer data outside the European Economic Area. You should document these transfers in your records of processing and run a transfer impact assessment to confirm the safeguards are adequate.
List Trackify X and the Meta Pixel in your cookie policy with the cookies, purposes and retention. Wire the app to your consent banner so no advertising tag or server event runs without marketing consent. Sign a data processing agreement and review Meta controller to controller terms, then complete a data protection impact assessment for the profiling. Finally, test that withdrawing consent stops both the browser pixel and the server side Conversions API for that visitor.
Websites using Trackify X must obtain user consent under GDPR regulations.
DPIA considerations
Trackify X combines advertising cookies, behavioural event tracking and server side sharing of hashed customer data with Meta, which constitutes large scale monitoring for advertising. A data protection impact assessment is strongly recommended. Document the data categories sent through the Conversions API, the lawful basis (consent), the retention by Meta, the international transfer to the United States under the Data Privacy Framework and the Standard Contractual Clauses, and the measures that prevent firing pixels or the server side API before consent is captured.
Sample consent text
We use Trackify X to set Meta (Facebook) advertising cookies and to send conversion events to Meta, including data shared with Meta Platforms in the United States, so we can measure and target advertising. These tools only run after you accept marketing cookies. You can refuse or withdraw your consent at any time from our cookie settings.
Third-party domains contacted
connect.facebook.netfacebook.comtrackify.appbusiness.facebook.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| _fbp | advertising | 90 days | Set by the Meta Pixel to identify the browser and link visits to Meta advertising profiles for measurement and targeting. |
| _fbc | advertising | 90 days | Stores the Facebook click identifier from an ad click so conversions can be attributed to a Meta campaign. |
| trackify_helper | functional | session | Trackify helper cookie used by the app to hold its own configuration and event state for the storefront. |
Trackify X collects user analytics data — you legally need a consent banner. Try FlowConsent free.
Through the Meta Pixel, Trackify X sets advertising cookies such as _fbp, a persistent first party cookie used to identify the browser, and _fbc, which stores a Facebook click identifier. It may also use a Trackify helper cookie for its own configuration. All of these are non essential advertising cookies that require consent.
Yes. The Meta Pixel and the server side Conversions API process personal data for advertising, so you need prior consent under article 5(3) of the ePrivacy Directive and article 6(1)(a) of the GDPR. Trackify X must not fire any pixel or send any server event before the visitor accepts marketing cookies.
The lawful basis is consent. Advertising tracking and audience building cannot rely on legitimate interest, because users would not reasonably expect their behaviour to be shared with Meta for targeting. You must obtain and record consent before activating the app.
Yes. Event data and hashed customer data are sent to Meta Platforms in the United States. These transfers rely on the EU US Data Privacy Framework where Meta is certified, supported by the EU Standard Contractual Clauses. You should document the transfer and run a transfer impact assessment.
A data protection impact assessment is strongly recommended. The combination of advertising cookies, behavioural event tracking and server side sharing with Meta amounts to large scale monitoring for advertising. Document the data flows, the consent mechanism and the international transfers in the assessment.
Connect Trackify X to your consent management platform so neither the pixel nor the Conversions API runs without marketing consent. List the cookies in your cookie policy, sign a data processing agreement, and support the IAB Transparency and Consent Framework signals. Test that withdrawing consent stops both browser and server tracking.
You can manage the Meta Pixel and Conversions API directly, use Shopify native customer events, or choose a privacy first analytics tool that does not feed advertising platforms. Whatever you pick, advertising and retargeting features still require consent. Aggregated, cookieless analytics can reduce your compliance burden.
Add an advertising section that names Trackify X and the Meta Pixel, lists the cookies _fbp and _fbc with their purpose and duration, and explains that data is shared with Meta in the United States. State the legal basis as consent and link to your cookie settings so visitors can withdraw at any time.