Sector white paperUS Direct-to-Consumer Retail · 23 storefronts · read 30 Sep 2026

The Choice Gap: US Direct-to-Consumer Retail, September 2026

Twenty-three storefronts across beauty, apparel and home asked shoppers to choose what happens to their data. What we observed when shoppers said no.

What we observed

  • 21 of 23kept loading advertising services with the “Do not sell” signal switched on
  • 22 of 23loaded trackers before the shopper made any choice
  • 14 of 23kept tracking after the reject or opt-out control was pressed
  • 11 of 23started a session-recording tool before any consent

Figures describe these 23 storefronts, one reading of each homepage, not every brand in the sector. No business in the sample is named.

Summary

Every storefront in this review asks shoppers, in one way or another, what they want done with their data. We wanted to know what happens after they answer. On 30 September 2026 we read the homepages of 23 US direct-to-consumer storefronts in beauty and wellness, apparel and footwear, and home and jewelry, the way a shopper in California would see them.

Most did not wait for the answer. On 22 of the 23, trackers were already running before the shopper had made any choice. On 11 of 23, a session-recording tool had started before any consent was given.

Saying no changed less than a shopper would expect. With the browser’s “Do not sell” signal switched on, advertising services kept loading on 21 of 23. After the reject or opt-out control was pressed, tracking continued on 14 of 23.

The same kinds of conduct appear again and again in the public enforcement record of the last four years, from California’s first settlement over an ignored opt-out signal in 2022 to the largest yet, announced in February 2026. Every storefront here is a business that already invests in its customers’ trust. The gap we describe is not a lack of effort. It is the distance between the choice a banner records and what the rest of the site does next.

One visit, four moments

A shopper’s first visit, step by step. Each square is one of the 23 storefronts; a filled square is a storefront where we observed the conduct at that moment.

  1. The page loadsTrackers start before the banner is answered22 of 23Advertising and analytics services were already loading while the choice was still on screen.
  2. Still loadingA session recorder starts11 of 23A tool that can replay a visit, click by click and scroll by scroll, was running before any consent.
  3. The browser says no“Do not sell” is sent, and advertising carries on21 of 23The shopper’s browser sent its “Do not sell” signal. Advertising services kept loading anyway.
  4. The shopper says noReject is pressed, and tracking continues14 of 23After the reject or opt-out control was pressed, trackers kept sending data as the shopper browsed on.

Compare the segments

Pick a segment to redraw the chart. Each bar shows how many storefronts in that segment showed the conduct, out of the storefronts we read in it.

  • Kept loading advertising services with “Do not sell” on21 of 2391%
  • Loaded trackers before any choice22 of 2396%
  • Kept tracking after reject or opt-out14 of 2361%
  • Started session recording before consent11 of 2348%

Beauty & wellness in focus

Beauty and wellness was the most consistent segment in the review, and not in a good way. All seven storefronts we read kept loading advertising services with the “Do not sell” signal switched on, and all seven loaded trackers before any choice.

Session recording is where beauty stood apart. Five of the seven started a session-recording tool before any consent, against six of the sixteen storefronts in apparel, footwear, home and jewelry. Beauty brands sell through content, reviews and quizzes, so they measure closely how visitors behave on the page. The tools that do that measuring are the ones that started earliest.

Five of the seven also kept tracking after the reject or opt-out control was pressed. Beauty is also the sector of the first public settlement over an ignored opt-out signal.

Who was still collecting after no

On the 14 storefronts that kept tracking after the reject or opt-out control, these services were the ones most often still receiving data.

  • Google9 of 23
  • Meta7 of 23
  • Microsoft6 of 23
  • TikTok6 of 23
  • Klaviyo4 of 23
  • Pinterest4 of 23
  • X3 of 23

Counts are storefronts, out of all 23 read, where requests to the service were observed after the control was pressed. A service receiving data says nothing about what that service then does with it.

Why a consent tool doesn’t close the gap

A consent banner records a choice. What happens next is decided elsewhere: in advertising tags, in apps installed on the store platform, in analytics and recording tools, each added at a different time, often by a different team or agency. Each one has to be told about the shopper’s choice, and each one has to listen.

That is how a storefront can show a banner, offer a reject button and still send data after it is pressed. Nobody inside the business sees the site the way a new shopper does, on a first visit, with the opt-out signal switched on. The only reliable way to know what happens is to look from the outside, the same way every time.

The public enforcement record

Recent actions announced by US regulators where a website’s tracking, opt-out handling or consent banner was part of what the regulator described. Filter by the kind of conduct to see which actions resemble each thing we measured. None of these businesses is in our sample.

  1. California Privacy Protection Agency
    Ford Motor CompanyUSD 375,703

    Alleged that consumers had to verify their identity by email before opting out, and that opt-outs were not processed when that step was not completed.

    Resembles: After saying no

    Source: Agency announcement, privacy.ca.gov, 5 Mar 2026

  2. California Privacy Protection Agency
    PlayOn SportsUSD 1.1 million

    Alleged that visitors had to agree to tracking technologies before they could view its websites or use tickets, with no adequate way to opt out, and that opt-out preference signals were not honoured.

    Resembles: Before any choice“Do not sell” signal

    Source: Agency announcement, privacy.ca.gov, 3 Mar 2026

  3. California Attorney General
    The Walt Disney CompanyUSD 2.75 million

    Alleged that opt-outs made through website and app toggles, and through the browser’s opt-out signal, applied only to one service or device, and that data kept flowing to advertising partners whose code ran on its sites.

    Resembles: “Do not sell” signalAfter saying no

    Source: Attorney General’s announcement, oag.ca.gov, 11 Feb 2026

  4. California Attorney General
    Sling TV and Dish Media SalesUSD 530,000

    Alleged that cookie preferences were bundled with the opt-out of sale, so turning off cookies was not enough, and that the opt-out sat behind a webform with extra confirmation steps.

    Resembles: After saying no

    Source: Attorney General’s announcement, oag.ca.gov, 30 Oct 2025

  5. California Privacy Protection Agency
    Tractor Supply CompanyUSD 1.35 million

    Alleged that consumers had no working way to opt out of the sale or sharing of their data, including through opt-out signals sent by the browser. The terms include scanning its digital properties for tracking technology.

    Resembles: “Do not sell” signalAfter saying no

    Source: Agency announcement, cppa.ca.gov, 30 Sep 2025

  6. California Attorney General
    Healthline MediaUSD 1.55 million

    Alleged that data kept going to advertising partners after readers opted out, including through the browser’s opt-out signal, and that unticking a box in its consent banner did not turn tracking cookies off.

    Resembles: “Do not sell” signalAfter saying no

    Source: Attorney General’s announcement, oag.ca.gov, 1 Jul 2025

  7. California Privacy Protection Agency
    Todd SnyderUSD 345,178

    Alleged that a misconfigured privacy portal left opt-out requests unprocessed for 40 days. The agency added that using a consent management platform does not take the responsibility away from the business.

    Resembles: After saying no

    Source: Agency announcement, cppa.ca.gov, 6 May 2025

  8. California Privacy Protection Agency
    American Honda Motor Co.USD 632,500

    Alleged that its online privacy tool did not offer symmetrical choices, that opting out asked for too much information, and that data went to advertising technology firms without the contracts the law sets out.

    Resembles: After saying no

    Source: Agency announcement, cppa.ca.gov, 12 Mar 2025

  9. Federal Trade Commission
    BetterHelpUSD 7.8 million

    Alleged that email addresses, IP addresses and health questionnaire answers were passed to advertising platforms for targeting without consumers’ affirmative express consent.

    Resembles: Before any choice

    Source: FTC announcement, ftc.gov, 2 Mar 2023

  10. Federal Trade Commission
    GoodRxUSD 1.5 million

    Alleged that health information was shared with advertising platforms through tracking tools, against the company’s own promise not to share it.

    Resembles: Before any choice

    Source: FTC announcement, ftc.gov, 1 Feb 2023

  11. California Attorney General
    SephoraUSD 1.2 million

    The first settlement of its kind. Alleged that third-party tracking on its website and app amounted to a sale of shoppers’ data, and that opt-outs, including those sent by the browser’s opt-out signal, were not honoured.

    Resembles: “Do not sell” signalAfter saying no

    Source: Attorney General’s announcement, oag.ca.gov, 24 Aug 2022

No action in this list centres on session recording; in California, recording and pixel tools have mostly drawn private demand letters rather than regulator action. Amounts are the totals each regulator announced; some include other terms. Summaries describe what the regulator announced, in our words, not our view of any business. Each action resolved its own facts; nothing here predicts any outcome for anyone else.

Five questions for your next leadership meeting

  1. When a first-time visitor presses Reject on our site, what is still loading a minute later, and who would know?
  2. Does our site do anything different when a shopper’s browser sends the “Do not sell” signal?
  3. Which tools on our storefront can replay a visitor’s session, and when do they start?
  4. Who added each advertising and analytics tag we run, and who is responsible for it now?
  5. When did anyone last look at our site the way a new shopper does, from outside the business?

Scope and limits

  • One reading of each storefront’s homepage on 30 Sep 2026, from California, in a standard browser. Sites change often; a later reading may differ.
  • 30 storefronts were attempted. 23 gave a complete reading and the other 7 are left out of every figure. Segment counts for apparel, footwear, home and jewelry are combined.
  • On several storefronts the opt-out control we pressed was a “Do not sell or share” link rather than a banner’s reject button. The after-no figure covers both.
  • Conduct only: what loaded, and when. Not a legal assessment and not a statement about any business’s obligations.
  • No business in the sample is named, here or anywhere else, before it has heard from us privately and had 28 days to respond. Paying for any Tolbrook service never changes a sector report.

Commission a sector review

For investors, multi-brand groups and trade bodies: the same review across up to 100 storefronts in one sector, on the criteria used here, with a full report for your team and a briefing on what we found.

See sector reviews

Scope

How each storefront’s homepage behaved toward a shopper’s privacy choices and tracking, observed from California in a standard browser on 30 Sep 2026. 30 storefronts were attempted and 23 gave a complete reading. Conduct only; not a legal assessment.

All reports and audits

Running one of these storefronts, or one like them? A free audit shows you exactly what we observe on your own site.

Claim a free audit