vafer.app / blog

Every cookie Shopify sets on your store: the complete list

Every Shopify storefront sets its own cookies — before you install a single app. Eleven are strictly necessary (cart, checkout, session, security), two are analytics, four support marketing attribution, and one remembers locale preferences. Here is the complete table, the same one a cookie policy needs to disclose.

The complete table of Shopify's cookies

Strictly necessary — no consent required, must be disclosed

CookieWhat it doesLasts
_secure_session_idTracks your session as you navigate the store24 hours
cartRemembers the items in the shopping cart2 weeks
cart_tsRecords when the cart was last changed, for checkout2 weeks
cart_sigVerifies the cart has not been tampered with at checkout2 weeks
checkout_tokenLinks the cart to a checkout so an order can complete1 year
secure_customer_sigKeeps a customer signed in to their account20 years
storefront_digestRemembers the storefront password on protected stores2 years
keep_aliveKeeps the session alive while browsing30 minutes
_tracking_consentRecords the visitor's tracking preferences1 year
_cmp_aManages privacy settings for the store24 hours

Analytics — consent required in opt-in regions

CookieWhat it doesLasts
_shopify_yIdentifies a returning visitor for store analytics1 year
_shopify_sIdentifies a single browsing session for analytics30 minutes

Marketing and attribution

CookieWhat it doesLasts
_shopify_sa_tRecords the time of a marketing or referral visit30 minutes
_shopify_sa_pRecords the marketing or referral source of the visit30 minutes
_landing_pageRecords the first page the visitor arrived on2 weeks
_orig_referrerRecords the site that referred the visitor2 weeks

Preferences

CookieWhat it doesLasts
localizationRemembers chosen country, language and currency1 year
Durations are Shopify's documented values and can change as the platform evolves. Treat any published table — including this one — as a starting point you review, not a permanent fact.

What controls whether the non-essential ones get set?

Shopify gates its own analytics and marketing cookies on its native consent system, the Customer Privacy API. When a consent app writes “analytics: denied” to that API, Shopify stops setting _shopify_y and _shopify_s. That is the correct mechanism — hiding the banner does not do it, and blocking Shopify's own scripts is neither possible nor necessary.

What about the cookies your apps add?

Everything above is just the platform. A typical store adds Google Analytics (_ga, _ga_*), Meta (_fbp), TikTok (_ttp), Klaviyo (__kla_id) and more through apps and pixels. Those need their own rows in your cookie declaration, and in opt-in regions they need real blocking before consent — not just a banner that mentions them.

Frequently asked

Which Shopify cookies are strictly necessary?

The cart and checkout cookies (cart, cart_ts, cart_sig, checkout_token), session cookies (_secure_session_id, keep_alive), account cookies (secure_customer_sig, storefront_digest) and Shopify's own consent cookies (_tracking_consent, _cmp_a). A store cannot function without them, so consent laws do not require asking permission for them.

What are _shopify_y and _shopify_s?

Shopify's own analytics cookies. _shopify_y identifies a returning visitor for about a year; _shopify_s ties together one browsing session for about 30 minutes. Both are analytics cookies, so under GDPR they need consent before being set — which is what Shopify's Customer Privacy API controls.

Do I have to list Shopify's cookies in my cookie policy?

Yes. GDPR transparency rules and CCPA notice-at-collection expect you to disclose the cookies your store sets, including the platform's own. That is exactly what a cookie declaration table is for.

When a shopper says no, it means no.

Vafer is a cookie consent app for Shopify that holds known trackers until consent, deletes cookies on reject, and shows you proof it's working. Free in early access.

Join the waitlist

Keep reading