Every definition below is our own analysis of the underlying statute, regulation, or platform documentation — not a rewrite of a third-party summary. Where a term has a deeper per-product treatment, the "Deep dive" link points to the product-specific glossary that carries the additional context. If a definition here contradicts a scanner's output, the scanner is authoritative for what the scanner did; this page is authoritative for what the words mean.
- ACE (Automated Commercial Environment)
- CBP's primary system for processing imports into the United States. Every formal entry (goods valued over $2,500, plus a growing list of Partner Government Agency (PGA)-regulated goods regardless of value) is filed electronically through ACE by a licensed customs broker. The CPSC electronic-filing rule that went mandatory Jul 8, 2026 requires the PGA message set to be transmitted through ACE — a filing that is missing a required PGA data element can hold a container at the port even though the CBP-side entry looks clean.Deep dive: EntryProof glossary → ACE
- BIS (Bureau of Industry and Security)
- The U.S. Department of Commerce bureau responsible for administering export controls, dual-use items, and (relevant to TariffWatch) Section 232 derivative-article investigations and inclusion rebuttal comments. The Aug 6, 2026 BIS-14 Federal Register notice — the source of TariffWatch's current derivative-article rule set — was published by this bureau, and its public inclusion/inclusion rebuttal comment docket is where TariffWatch's comment-letter templates file.Deep dive: TariffWatch glossary → BIS
- CBP (U.S. Customs and Border Protection)
- The federal agency inside DHS responsible for physical border enforcement and the collection of import duties. CBP runs ACE, publishes the Harmonized Tariff Schedule (HTS) via USITC, and issues binding rulings on classification and origin. Every import touched by any of the three products in this portfolio (Shopify DTC merchant, cross-border seller, metals importer) is ultimately answering to CBP on entry.
- CCPA / CPRA
- The California Consumer Privacy Act (2018) and its expanded successor the California Privacy Rights Act (2020), which together create a private right of action for California residents whose personal information is mishandled. Relevant to PixelProof because Meta Pixel and GA4 pass first-party visitor data (email, IP, click behavior) that qualifies as "personal information" under CCPA's definition — the required disclosure and opt-out plumbing has to be wired regardless of what the tracking pixel does technically.
- CFR (Code of Federal Regulations)
- The codified rule text produced by federal agencies (as distinct from statutes passed by Congress). Every one of this portfolio's underlying compliance rules is a specific CFR section: 16 CFR Part 1110 (CPSC electronic filing), 19 CFR 111 (customs brokers), 21 CFR Part 700 (MoCRA cosmetics regulation), 47 CFR Part 64 (TCPA), etc. When a scanner cites a rule, the citation is to the CFR section, not to a downstream summary of it.
- Comment letter (regulations.gov / Federal Register)
- A formal written response to a proposed federal rule during its public-comment window, submitted through regulations.gov (or, for some agencies, directly to a docket-management system). The BIS-14 comment window that opened Aug 4, 2026 and runs through Aug 27, 2026 is exactly this kind of process — TariffWatch ships 14 templates so importers can submit their real exposure numbers to that docket in the language BIS actually reads.Deep dive: TariffWatch comment letters
- Conversions API (CAPI)
- Meta's server-to-server alternative to the browser-based Meta Pixel. Instead of a visitor's browser sending an event to Meta (which ad blockers, Safari's ITP, and third-party-cookie restrictions can all interfere with), the store's own server sends the same event directly. Meta recommends running CAPI alongside the browser Pixel with a matching event_id for deduplication — running CAPI instead of the Pixel is the mistake that produces phantom "lost conversions."Deep dive: PixelProof glossary → CAPI
- CPC (Children's Product Certificate)
- A required document under CPSIA (Consumer Product Safety Improvement Act) for any product designed or intended primarily for children 12 and under. The CPC has to identify the product, the applicable safety rules, the third-party testing lab, and the date and place of manufacture. The CPSC electronic-filing rule that went live Jul 8, 2026 requires the CPC data elements to be transmitted through the PGA message set at entry, not just kept in the importer's records.Deep dive: EntryProof glossary → CPC
- CPSIA (Consumer Product Safety Improvement Act of 2008)
- The federal statute that codified third-party testing, tracking labels, and CPC requirements for children's products, plus lead-content and phthalate limits. CPSIA is the parent statute; 16 CFR Parts 1109 (component-part testing), 1110 (electronic filing), and 1500-series (specific product rules) are its implementing regulations.
- DMARC / SPF / DKIM
- The three modern email-authentication standards. SPF (Sender Policy Framework) publishes which mail servers are authorized to send for a domain. DKIM (DomainKeys Identified Mail) cryptographically signs each message. DMARC (Domain-based Message Authentication) tells receivers what to do when SPF or DKIM fails, and where to send aggregate reports. Google and Yahoo enforced DMARC in 2024 — any bulk cold-email operator whose domain does not publish a valid DMARC record with a non-`p=none` policy will see deliverability collapse.
- FDA (U.S. Food and Drug Administration)
- Federal agency responsible for cosmetics, food, drugs, medical devices, and (post-MoCRA, 2022) mandatory cosmetic-product listing and adverse-event reporting. FDA is a Partner Government Agency in ACE, meaning FDA-regulated imports have to transmit an FDA-specific PGA message set at entry alongside CBP's own filing.
- GDPR (General Data Protection Regulation)
- The EU's 2018 comprehensive privacy statute. Directly relevant to PixelProof because any Shopify store shipping to the EU is subject to GDPR regardless of where the store itself is based — and GDPR Article 22 forbids fully automated decisions (including some kinds of pixel-driven personalization) without an explicit legal basis, while Article 33 requires 72-hour breach notification. Cookie consent under GDPR is stricter than under CCPA (opt-in, not opt-out).
- GRI (General Rules of Interpretation, HTS)
- The six sequential rules used to classify a good under the Harmonized Tariff Schedule when the classification is not immediately obvious from the heading text. GRI 1 is the terms-of-heading rule; GRI 3 handles composite/mixed goods; GRI 6 handles subheading tie-breakers. Real HTS classification (especially for Section 232 derivative articles under a mixed-metal composition) turns on GRI application, which is why TariffWatch's methodology is explicit that its chapter/heading-level match is not a substitute for a full 10-digit classification by a licensed broker.
- HTS / HTSUS (Harmonized Tariff Schedule of the United States)
- The 10-digit classification system CBP uses to identify goods entering the U.S. and assign duty rates. Chapters 1-97 group goods by material and use; the first 6 digits are internationally harmonized (WCO), digits 7-8 are U.S. tariff-line subdivisions, and digits 9-10 are U.S. statistical suffixes. TariffWatch matches at the chapter (2-digit) and heading (4-digit) level; full 10-digit classification is a customs-broker judgment.Deep dive: HTS Code Lookup (free tool)
- MoCRA (Modernization of Cosmetics Regulation Act, 2022)
- The 2022 statute that gave FDA authority over cosmetics for the first time in ~80 years — mandatory facility registration, product listing, adverse-event reporting, and Good Manufacturing Practice regulations. FDA published its final MoCRA product-listing rule in 2024 and phased enforcement across 2025-2026. Relevant to any DTC store selling cosmetics, even small-batch/indie brands that were exempt under the previous voluntary system.
- Partner Government Agency (PGA)
- The umbrella term CBP uses for the ~50 federal agencies (CPSC, FDA, USDA, EPA, ATF, and many others) whose regulations govern specific classes of import in addition to CBP's own duty and classification rules. A PGA-regulated import has to transmit both the CBP entry data and the PGA-specific message set through ACE. Missing PGA data is the most common cause of a container being held at the port on an otherwise clean CBP entry.Deep dive: EntryProof glossary → PGA
- Section 232 (Trade Expansion Act of 1962)
- The federal statute that lets the President impose import tariffs on national-security grounds. The 2018 steel and aluminum tariffs (originally 25% and 10%, subsequently modified up to 50%) were imposed under Section 232, and the Aug 6, 2026 BIS-14 Federal Register notice proposes expanding those tariffs to 14 additional derivative-article categories — the entire subject of TariffWatch's exposure calculator.Deep dive: TariffWatch glossary → Section 232
- Section 301 (Trade Act of 1974)
- The federal statute the U.S. Trade Representative uses to impose retaliatory tariffs on unfair foreign trade practices. The 2018-onward China tariffs (Lists 1-4A) are Section 301 tariffs, not Section 232. TariffWatch does not currently cover Section 301 — the Section 301 exclusion docket is USTR, not BIS, and the calculator would need a separate rules-version tag.
- SoR (Statement of Registry, CPSC)
- The specific data element in the CPSC PGA message set that identifies which children's-product safety rule(s) the imported item is certified to. A missing or mismatched SoR is one of the most common reasons a CPSC-regulated entry gets flagged at the port, and one of the checks EntryProof's readiness scanner runs.
- TCPA (Telephone Consumer Protection Act, 47 U.S.C. §227)
- The federal statute that governs marketing calls, texts, and (via 47 CFR 64.1200) prerecorded messages. Relevant to any e-commerce operator running SMS marketing — CTIA-registered short codes, prior express written consent, and honoring STOP within one message cycle are all TCPA requirements, and TCPA class actions are a real business risk (statutory damages of $500-$1,500 per unsolicited message).
- USMCA (United States-Mexico-Canada Agreement)
- The 2020 trade agreement replacing NAFTA. USMCA rules-of-origin determine when a good qualifies for preferential (usually zero) duty treatment on entry from Mexico or Canada. Relevant to TariffWatch because the Section 232 aluminum-and-steel tariffs interact with USMCA's rules-of-origin in specific and often surprising ways — some derivative articles that would qualify under USMCA's own rules still get hit by Section 232 because the underlying metal content is not USMCA-originating.
- Web Pixels API (Shopify)
- Shopify's sandboxed system for running tracking pixels, replacing the Additional Scripts checkout field and checkout.liquid theme editing that Shopify's Aug 26, 2026 upgrade removes for non-Plus stores. Pixels registered through the Web Pixels API receive standardized Shopify customer events (checkout_started, product_added_to_cart) in a restricted sandbox, rather than having free-form DOM access. Migrating from the legacy fields to the Web Pixels API is the specific action PixelProof's scan recommends when it finds a pixel that will break Aug 26.Deep dive: PixelProof glossary → Web Pixels API
Related pages
- PixelProof glossary — full Meta Pixel + Shopify tracking dictionary (22+ terms).
- EntryProof glossary — full CPSC electronic-filing dictionary (28+ terms).
- TariffWatch glossary — full Section 232 and HTS dictionary (24+ terms).
- Portfolio methodology — how each scanner applies these terms.
- Portfolio roadmap — which of these areas we're expanding coverage in next.
- Portfolio changelog — release notes.
Digital Empire builds compliance tools for regulated verticals — pharma, consumer products, metals.
Also from Digital Empire