Does a Shopify geolocation popup need a cookie banner?

A question we get from EU merchants more often than any other, once the redirect itself works: “Do I need to add this to my cookie banner?” It usually comes with a screenshot of a compliance scanner flagging a geolocation script, and a slightly panicked tone, because the last thing anyone wants is a third banner on their homepage.

The honest answer has three parts. What the law actually regulates is broader than cookies. What a geolocation app does varies enormously from one app to another. And what GeoBeacon specifically does is small enough to describe in two sentences, which we will. This is not legal advice; it is a technical description precise enough that your adviser can give you legal advice without having to read our source code.

What the rules cover, and why “it is not a cookie” does not help

The relevant provision in the EU is Article 5(3) of the ePrivacy Directive. It says that storing information on a user’s device, or accessing information already stored there, requires the user’s consent, unless the storage or access is strictly necessary to provide a service the user explicitly asked for. Notice what it does not say: it does not say “cookie”. In 2023 the European Data Protection Board published guidelines on the technical scope of that article, and they are explicit that it applies to localStorage, to fingerprinting, to pixel requests and to any other technique that reads from or writes to the device. A scanner that flags a localStorage key is not being pedantic.

So the question for any script on your storefront is not “does it set a cookie” but two other questions: what does it store or read on the device, and for what purpose; and separately, what does it send off the device, and to whom. Consent is the default answer to the first unless the purpose is strictly necessary for something the shopper asked for. The second brings the GDPR in, because an IP address is personal data.

Where most geolocation apps sit on those two questions

Country redirect apps have to do two things: find out where the shopper is, and remember what happened so the shopper is not asked again on the next page. The common implementations are not equal.

Typical geolocation app behaviours and what they touch
BehaviourStored on the device?Sent off the device?
IP lookup against a third-party geo-IP APIUsually a cookie with the resultYes: the shopper’s IP to the vendor, from the browser or the app’s server
Per-visitor analytics dashboard in the appOften a visitor ID cookieYes: a hit per page view to the app’s servers
Remembering “stay here” or “go to the other store”Yes: a cookie or localStorage entryDepends on the app
Detection through Shopify’s own storefront endpointOptionally a short cacheOnly to Shopify, on your own domain

The first two rows are where the real exposure is, and they tend to go together with apps that bill per visitor; our post on why geolocation apps charge per visitor explains why counting visitors requires the app to see every one of them. An app that sends each shopper’s IP address to a geo-IP vendor has made that vendor a processor of your visitors’ personal data, with the contract and transfer questions that come with it, and your privacy policy needs to say so. The third row is the one every app shares, and it is the one where the “strictly necessary” exemption is usually argued.

What GeoBeacon stores and sends

Two sentences, as promised. GeoBeacon detects the country by asking Shopify’s own browsing context endpoint on your store domain, from the shopper’s browser, the same mechanism your theme’s country selector uses to suggest a market, so no request ever goes to a GeoBeacon server and no IP address is seen by us or by any geo-IP vendor. It writes two entries to the shopper’s browser, both under a geobeacon: prefix, and sets no cookies.

  • geobeacon:choice in localStorage: whether the shopper chose to go to the suggested market or to stay, plus an expiry. It is written when the shopper clicks a button in the popup, or in redirect mode when the redirect happens, so the shopper is not bounced again. It expires after the “remember for” period you set in the app, 30 days by default, and contains no identifier of any kind.
  • geobeacon:detected in sessionStorage: the country and language Shopify returned, cached for up to six hours so the endpoint is not called on every page. It is discarded when the tab closes.

That is the complete list. There is no visitor ID, no analytics hit, no dashboard of who came from where, and the configuration itself lives in a metafield owned by the app on your shop, read by the theme embed through Liquid. The design goal, described on the landing page, was that a shopper’s visit should leave no trace outside their own browser and Shopify.

So: banner or no banner?

Here is the reasoning your adviser will want to check, laid out plainly. The one persistent thing GeoBeacon stores is the shopper’s own answer to a question the shopper was asked. Regulators have long treated remembering a preference the user set through an explicit action, a language choice or a display setting, as falling within the strictly-necessary exemption, provided it is kept for a limited period and used for nothing else. A “stay on this store” choice kept for 30 days and read only to avoid asking again is about as clean an example of that category as exists. The session cache of the detected country is shorter-lived still and exists so the page does not re-detect on every navigation.

Two honest caveats. First, in redirect mode the remembrance is written without a click, because the shopper never sees a popup. It is still there to serve the shopper (without it they would be redirected on every page, which is the loop our redirect loop post is about), but if your adviser prefers that any persistent storage follow a visible interaction, popup mode gives you that. Second, national regulators differ on how narrowly they read “strictly necessary”, and some scanners flag every localStorage key regardless of purpose. If yours does, the fix is a description, not a consent gate: add the two keys, their purposes and their lifetimes to your cookie policy under functional or preference storage.

Shopify’s own customer privacy settings give you a cookie banner and a privacy policy generator, and the Customer Privacy API is how pixels and apps that do track visitors are supposed to respect the shopper’s answer. GeoBeacon does not register with it, for the simple reason that it has no tracking to switch off; its storage is functional either way. If you have configured the banner to cover only the EU and UK, as most stores do, nothing about GeoBeacon changes that configuration.

The Digital Omnibus, briefly

In November 2025 the European Commission proposed the Digital Omnibus, a package that among many other things aims at what its own text calls “consent fatigue and the proliferation of cookie banners”. The direction is to move the device-storage rules out of the ePrivacy Directive into the GDPR, widen the list of purposes that do not need consent, and let browsers carry a consent signal so sites stop asking one at a time. It is a proposal working through Parliament and Council; nothing in it changes what you must do today, and the final text may differ. What it will not do, in any version, is make shipping your visitors’ IP addresses to a third party a non-event. The apps that have the least to worry about under the current rules are the same ones that will have the least to change under the next.

A checklist for any geolocation app

  1. Open your storefront in a private window with the developer tools on the Application tab. Note every cookie and storage key the geolocation app writes, and how long each lasts.
  2. Switch to the Network tab and reload. Any request to a domain that is not your store, Shopify’s CDN or a service you already list in your privacy policy is a question for the app’s developer: what is sent, and why.
  3. Ask the developer, in writing, whether the app stores visitor IP addresses or per-visitor records on their servers. Per-visitor billing is a strong hint that it does.
  4. Add what you found to your privacy and cookie policies under the right category, with purpose and lifetime. For GeoBeacon that is two entries under functional storage and no third party.
  5. If the app does send data off-site, check that your data processing agreement with the developer covers it, and reconsider whether you need that data at all.

If you would rather start from an app whose answer to steps one to three fits on an index card, install GeoBeacon and run the checklist yourself; the developer tools will show you exactly what this article describes and nothing more.

Frequently asked questions

Does a country redirect app on Shopify use cookies?

Most store something in the shopper's browser so the same visitor is not asked twice, either a cookie or a localStorage entry. Many also send the visitor's IP address to a third-party geolocation service to work out the country. Both are things EU ePrivacy rules care about, so it is worth knowing which your app does.

Is localStorage covered by the EU cookie rules?

Yes. Article 5(3) of the ePrivacy Directive covers storing or accessing information on a user's device, and the European Data Protection Board's 2023 guidelines say this includes localStorage and similar techniques, not just HTTP cookies. Whether consent is needed depends on the purpose, not on the technology.

What does GeoBeacon store on the shopper's device?

Two entries and no cookies: the shopper's answer to the popup, kept in localStorage for the number of days you configure, and a short-lived sessionStorage cache of the country Shopify detected. Neither contains an identifier, and nothing about the visitor is sent to GeoBeacon's servers.

Does GeoBeacon send my visitors' IP addresses to a geolocation service?

No. Country detection uses Shopify's own browsing context endpoint on your store domain, the same mechanism the theme's country selector relies on. The request goes from the shopper's browser to Shopify, and GeoBeacon never sees the IP or the result.