Guide
How to identify anonymous Shopify visitors
Most people browsing your Shopify store never identify themselves — and once they leave, they're gone. You can recover a share of that anonymous traffic into contactable profiles and feed it back into the Klaviyo and Meta flows you already run. Here's how the pieces fit together, and the consent controls that keep it honest.
Step 1 — Connect read-only, add one write
You connect your store with a read-only Shopify Custom App token (BYOK) and your own Klaviyo key — no App Store install and no OAuth consent screen. The only write Growth Layer ever asks for is the storefront pixel that Visitor-ID needs, and only if you switch Visitor-ID on. Everything else stays read-only.
Step 2 — The storefront pixel observes anonymous sessions
The pixel records the signals available from anonymous sessions on your storefront. It's the input to matching. Nothing about this step identifies anyone on its own — it's the raw signal that gets looked up against the identity graph in the next step.
Step 3 — Matching resolves a share of visitors
Signals are matched against a third-party identity graph to resolve a share of anonymous visitors into contactable profiles, and the rate varies because the graph is US-centric. This is the honest ceiling: you recover some of your high-intent anonymous traffic, not all of it. A store with mostly US visitors will resolve more than one with mostly EU traffic.
Step 4 — Consent-first sync into Klaviyo and Meta
Before any matched contact reaches your marketing tools, consent state and Global Privacy Control signals are checked and opt-outs are suppressed. The matches that pass sync into Klaviyo — and, on the Scale tier, Meta Custom Audiences — so your existing flows re-engage them. Suppression runs at the point of sync, so a visitor who has opted out is never handed to your flows.
Where this fits — and where it doesn't
Visitor identification is worth it when you have real anonymous traffic and existing Klaviyo flows to receive the matches. It is not a way to identify everyone, and it's not something to run without a lawful basis — you remain the data controller. If maximum match rate is your single priority, a dedicated identity specialist will typically resolve more; Growth Layer's trade is bundled diagnosis, consent-first controls, and a lower entry price.
Frequently asked questions
Do I need to install a Shopify app?
No. You connect with a read-only Custom App token and your own Klaviyo key — no App Store install and no OAuth consent screen. Visitor-ID adds one storefront pixel, and only if you turn it on.
What share of visitors will I recover?
It resolves a share of anonymous visitors, varying by store and audience because the identity graph is US-centric. It recovers a share of anonymous traffic, not all of it.
How are opt-outs handled?
Consent and GPC signals are checked and opt-outs are suppressed before any contact syncs into Klaviyo or Meta — suppression happens at the point of sync, not after.