Cookie Policy
This document is meant to explain the types of cookies and other tracking technologies that Shopify may place on your device, either when you are visiting our web properties, or if you are visiting the storefront of a merchant who uses our platform to power their site.
What are cookies?
A cookie is a small amount of information that’s downloaded to your computer or device when you visit certain websites. We use a number of different cookies on the Shopify website, including strictly necessary, performance, advertising, and social media or content cookies. Cookies make your browsing experience better by allowing the website to remember your actions and preferences (such as login and region selection). This means you don’t have to re-enter this information each time you return to the site or browse from one page to another. Cookies also provide information on how people use the website, for instance whether it’s their first time visiting or if they are a frequent visitor. Read more about cookies (and other similar tracking technologies) and how we use the data collected through these technologies, in our Privacy Policy.
What cookies do we use and why?
Some cookies are necessary to allow you to browse our website, use its features, and access secure areas. The use of these cookies is essential for the website to work. For example, we use user-input cookies for the duration of a session to keep track of a user’s input when filling in forms that span several pages.
We also use functional cookies to remember choices you’ve made or information you’ve provided, such as your username, language, or the region you are in. This allows us to tailor your website experience specifically to your preferences. For example, authentication cookies are functional cookies that are used for the duration of a session (or persistent, if you agree to the “remember me” function) to allow users to authenticate themselves on subsequent visits or to gain access to authorized content across pages. The functional cookies we use include:
- User-centric security cookies to detect authentication abuses for a limited persistent duration, like repeated failed login attempts. These cookies are set for the specific task of increasing thesecurity of the service.
- Multimedia content player session cookies (flash cookies) are used for the duration of a session to store technical data needed to play back video or audio content (e.g. image quality, network link speed, and buffering parameters).
- Load balancing session cookies are used for the duration of the session to identify the same server in the pool in order for the load balancer to redirect user requests appropriately.
- User interface customization persistent cookies are used to store a user’s preference regarding a service across web pages.
Shopify is dedicated to user experience and we use many tools to help us improve our website and our commerce platform. To this end, we use reporting and analytics cookies to collect information about how you use our website or our merchants’ storefronts, and how often. These cookies only gather information for statistical purposes and only use pseudonymous cookie identifiers that do not directly identify you. The performance cookies we use include:
- First party analytics cookies - We use these cookies to estimate the number of unique visitors, to improve our websites and our merchants’ websites, and to detect the most searched for words in search engines that lead to a webpage. These cookies are not used to target you with online marketing. We use these cookies to learn how our websites and our merchants’ websites are performing and make relevant improvements to improve your browsing experience.
- Third party analytics cookies - We also use Google Analytics and other third-party analytics providers listed below to help measure how users interact with our website content. These cookies “remember” what our users have done on previous pages and how they’ve interacted with the website. For more information on Google Analytics, visit Google’s information page. For instructions on how to opt out of Google Analytics, see below.
Advertising cookies are used on our website to tailor marketing to you and your interests and provide you with a more personalized service in the future. These cookies remember that you visited our website and we may share this information with third-parties, such as advertisers. Although these cookies can track your device’s visits to our website and other sites, they typically cannot personally identify you. Without these cookies, the advertisements that you see may be less relevant and interesting to you. Read more about how companies use cookies to conduct targeted or retargeted advertising here. We do not set advertising cookies through our merchants’ storefronts ourselves, though merchants may choose to do so independently.
Finally, Social and Content cookies are placed by many social media plugins (for example the Facebook ’like’ button), and other tools meant to provide or improve the content on a website (for example services that allow the playing of video files, or that create comments sections). We integrate these modules into our platform to improve the experience of browsing and interacting with our websites. Please note that some of these third party services place cookies that are also used for things like behavioural advertising, analytics, and/or market research.
Merchant storefronts
When merchants use our platform to power their online stores, we place the following cookies for visitors of their stores:
Cookies Necessary for the Functioning of the Store:
Name | Function | Duration |
_ab | Used in connection with access to admin. | 2y |
_customer_account_shop_sessions | Used in combination with the _secure_account_session_id cookie to track a user's session for new customer accounts | 30d |
_secure_account_session_id | Used to track a user's session for new customer accounts | 30d |
_secure_session_id | Used to track a user's session through the multi-step checkout process and keep their order, payment and shipping details connected. | 24h |
_shopify_country | For shops where pricing currency/country set from GeoIP, that cookie stores the country we've detected. This cookie helps avoid doing GeoIP lookups after the first request. | session |
_shopify_m | Used for managing customer privacy settings. | 1y |
_shopify_tm | Used for managing customer privacy settings. | 30min |
_shopify_tw | Used for managing customer privacy settings. | 2w |
_storefront_u | Used to facilitate updating customer account information. | 1min |
_tracking_consent | Used to store a user's preferences if a merchant has set up privacy rules in the visitor's region. | 1y |
_cmp_a | Used for managing customer privacy settings. | 1d |
c | Used in connection with checkout. | 1y |
cart | Used in connection with shopping cart. | 2w |
cart_currency | Set after a checkout is completed to ensure that new carts are in the same currency as the last checkout. | 2w |
cart_sig | A hash of the contents of a cart. This is used to verify the integrity of the cart and to ensure performance of some cart operations. | 2w |
cart_ts | Used in connection with checkout. | 2w |
cart_ver | Used in connection with shopping cart. | 2w |
checkout | Used in connection with checkout. | 4w |
checkout_token | Used in connection with checkout. | 1y |
customer_account_locale | Used in connection with new customer accounts | 1y |
dynamic_checkout_shown_on_cart | Used in connection with checkout. | 30min |
hide_shopify_pay_for_checkout | Used in connection with checkout. | session |
keep_alive | Used in connection with buyer localization. | 2w |
master_device_id | Used in connection with merchant login. | 2y |
previous_step | Used in connection with checkout. | 1y |
discount_code | Used in connection with checkout. | session |
remember_me | Used in connection with checkout. | 1y |
secure_customer_sig | Used to identify a user after they sign into a shop as a customer so they do not need to log in again. | 1y |
shopify_pay | Used in connection with checkout. | 1y |
shopify_pay_redirect | Used in connection with checkout. | 1 hour, 3w or 1y depending on value |
shop_pay_accelerated | Used in connection with checkout. | 1y |
source_name | Used in combination with mobile apps to provide custom checkout behavior, when viewing a store from within a compatible mobile app. | session |
storefront_digest | Stores a digest of the storefront password, allowing merchants to preview their storefront while it's password protected. | 2y |
tracked_start_checkout | Used in connection with checkout. | 1y |
checkout_session_lookup | Used in connection with checkout. | 3w |
checkout_prefill | Used in connection with checkout. | 5m |
checkout_queue_token | Used in connection with checkout. | 1y |
checkout_queue_checkout_token | Used in connection with checkout. | 1y |
checkout_worker_session | Used in connection with checkout. | 3d |
checkout_session_token | Used in connection with checkout. | 3w |
checkout_session_token_<<token>> | Used in connection with checkout. | 3w |
cookietest | Used to ensure our systems are working correctly | 1m |
order | Used in connection with order status page. | 3w |
identity-state | Used in connection with customer authentication | 24h |
identity-state-<<token>> | Used in connection with customer authentication | 24h |
identity_customer_account_number | Used in connection with customer authentication | 12w |
card_update_verification_id | Used in connection with checkout. | 20m |
customer_account_new_login | Used in connection with customer authentication | 20m |
customer_account_preview | Used in connection with customer authentication | 7d |
customer_payment_method | Used in connection with checkout. | 1h |
customer_shop_pay_agreement | Used in connection with checkout. | 20m |
pay_update_intent_id | Used in connection with checkout. | 20m |
localization | Used in connection with checkout. | 2w |
profile_preview_token | Used in connection with checkout. | 5m |
login_with_shop_finalize | Used in connection with customer authentication | 5m |
preview_theme | Used in connection with the theme editor | session |
shopify-editor-unconfirmed-settings | Used in connection with the theme editor | 16h |
wpm-test-cookie | Used to ensure our systems are working correctly. | session |
Reporting and Analytics
Name | Function | Duration |
_landing_page | Track landing pages. | 2w |
_orig_referrer | Track landing pages. | 2w |
_s | Shopify analytics. | 30min |
_shopify_d | Shopify analytics. | session |
_shopify_fs | Shopify analytics. | 30min |
_shopify_s | Shopify analytics. | 30min |
_shopify_sa_p | Shopify analytics relating to marketing & referrals. | 30min |
_shopify_sa_t | Shopify analytics relating to marketing & referrals. | 30min |
_shopify_y | Shopify analytics. | 1y |
_y | Shopify analytics. | 1y |
_shopify_ga | Shopify and Google Analytics. | session |
customer_auth_provider | Shopify analytics. | session |
customer_auth_session_created_at | Shopify analytics. | session |
unique_interaction_id | Shopify analytics. | 10min |
Shopify’s websites
When visitors load Shopify’s websites, we generally place the following Shopify cookies:
Cookies Necessary for the Functioning of the Sites
Name | Function | Duration |
_Brochure_session | Used in connection with browsing through site. | - |
checkout | Used in connection with Pay checkout on shop.app. | 3w |
signed_in | Used in connection with Shop login. | 1y |
user | Used in connection with Shop login. | 1y |
Reporting and Analytics
Name | Function |
_landing_page | Tracks landing pages. |
_orig_referrer | Tracks landing pages. |
_s | Shopify analytics. |
_session_id | Shopify analytics. |
_shopify_s | Shopify analytics. |
_shopify_sa_t | Shopify analytics relating to marketing & referrals. |
_shopify_uniq | Shopify analytics. |
_shopify_y | Shopify analytics. |
_y | Shopify analytics. |
*_assignment | Shopify analytics. |
ab_test_* | Shopify analytics. |
cart_sig | Shopify analytics. |
ki_r | Shopify analytics. |
ki_t | Shopify analytics. |
Additionally, we use pixels and tags from the following third parties, which may in turn place cookies:
Cookies Necessary for the Functioning of the Sites
Third Party | Description | Privacy Policy |
Cloudflare | Shopify uses Cloudflare Network as a Service for edge routing. | https://www.cloudflare.com/privacypolicy/ |
Reporting & Analytics
Third Party | Description | Privacy Policy |
Alexa Metrics | We use Alexa Metrics to help measure how users interact with our websites. | https://www.alexa.com/help/privacy |
Bizible | We use Bizible to help measure how users interact with our websites. | https://documents.marketo.com/legal/privacy/ |
Chartbeat | We use Chartbeat to help measure how users interact with our websites. | https://chartbeat.com/privacy/ |
Crazy Egg | We use Crazy Egg to help measure how users interact with our websites. | https://www.crazyegg.com/privacy |
Datadog RUM | We use Datadog RUM to help measure how users interact with our websites. | https://www.datadoghq.com/legal/privacy/ |
DC Analytics | We use DC Analytics to help measure how users interact with our websites. | https://dcanalytics.dcmn.com/privacy-policy |
Facebook Pixel | We use Facebook Pixel to help measure how users interact with our websites. | https://www.facebook.com/privacy/explanation |
Fullstory | We use Google Analytics to help measure how users interact with our websites. | https://www.fullstory.com/legal/privacy/ |
Google Analytics | We use Google Analytics to help measure how users interact with our websites. | https://policies.google.com/privacy |
Google Tag Manager | We use Google Tag Manager to help manage analytics vendors. | https://policies.google.com/privacy |
Hotjar | We use Hotjar to help measure how users interact with our websites. | https://www.hotjar.com/legal/policies/privacy |
iSpot | We use iSpot to help measure how users interact with our websites. | https://www.ispot.tv/terms-of-service |
KissInsights | We use KissInsights to help measure how users interact with our websites. | https://signin.kissmetrics.com/privacy/ |
LinkedIn Insight Tag | We use LinkedIn Insight Tag to help measure how users interact with our websites. | https://www.linkedin.com/legal/privacy-policy |
New Relic | We use New Relic to help measure how users interact with our websites. | https://newrelic.com/termsandconditions/privacy |
Optimizely | We use Optimizely to help us test improvements or changes to our websites. | https://www.optimizely.com/privacy/ |
Pinterest Analytics | We use Pinterest Analytics to help measure how users interact with our websites. | https://policy.pinterest.com/privacy-policy |
Segment | We use Segment to help measure how users interact with our websites. | https://segment.com/legal/privacy/ |
Snapchat | We use Snapchat to help measure how users interact with our websites. | https://snap.com/privacy/privacy-policy |
Taboola | We use Taboola to help measure how users interact with our websites. | https://www.taboola.com/policies/privacy-policy |
Tealium | We use Tealium to help manage analytics vendors. | https://tealium.com/privacy/ |
TikTok | We use TikTok to help measure how users interact with our websites. | https://www.tiktok.com/legal/privacy-policy?lang=en |
We use Twitter to help measure how users interact with our websites. | https://twitter.com/en/privacy | |
Yelp Audience Platform | We use Yelp to help measure how users interact with our websites. | https://terms.yelp.com/privacy/en_us/20200101_en_us/ |
Advertising
Third Party | Description | Privacy Policy |
Microsoft Advertising | We use Microsoft Advertising to deliver targeted advertisements to individuals who visit our websites. | https://privacy.microsoft.com/en-ca/privacystatement |
Drift | We use Drift to help us with conversational marketing to customers while they visit our websites. | https://www.drift.com/privacy-policy/ |
Facebook Custom Audiences | We use Facebook Custom Audiences to deliver targeted advertisements to individuals who visit our websites. | https://www.facebook.com/policy.php |
We use Google Ads to deliver targeted advertisements to individuals who visit our websites. | https://policies.google.com/privacy | |
Hubspot | We use Hubspot to manage our relationships with our customers. | https://legal.hubspot.com/privacy-policy |
Intercom | We use Intercom to manage our relationships with our customers. | https://www.intercom.com/terms-and-policies#privacy |
Marketo | We use Marketo to manage our relationships with our customers. | https://documents.marketo.com/legal/privacy/ |
Outbrain | We use Outbrain to deliver targeted advertisements to individuals who visit our websites. | https://www.outbrain.com/privacy |
Quora | We use Quora to deliver targeted advertisements to individuals who visit our websites. | https://www.quora.com/about/privacy |
We use Reddit Ads to deliver targeted advertisements to individuals who visit our websites. | https://www.reddit.com/help/privacypolicy | |
SourceKnowledge | We use SourceKnowledge to deliver targeted advertisements to individuals who visit our websites. | http://www.sourceknowledge.com/privacy |
Yahoo Japan Ads | We use Yahoo Japan Ads to deliver targeted advertisements to individuals who visit our websites. | https://about.yahoo.co.jp/common/terms/ |
Social Media & Content
Third Party | Description | Privacy Policy |
Disqus | We use Disqus to provide commenting capabilities on posts on our websites. | https://help.disqus.com/terms-and-policies/disqus-privacy-policy |
Facebook Connect | We use Facebook Connect to allow visitors to our website to interact with and share content via Facebook’s social media platform. | https://www.facebook.com/policy.php |
Gravatar | We use Gravatar to allow visitors to our websites to create avatars. | https://en.gravatar.com/site/privacy |
We use Twitter to allow visitors to our website to interact with and share content via Twitter’s social media platform. | https://twitter.com/en/privacy | |
Wistia | We use Wistia to display video content. | https://wistia.com/privacy |
Oberlo websites
When visitors load Oberlo’s websites, we generally place the following Oberlo cookies:
Cookies Necessary for the Functioning of the Sites
Name | Function |
oberlo_session | Used in connection with navigation through an app. |
shippingCountry | Used in connection with navigation through an app. For product exploration, calculating shipping price. |
user_locale | Used in connection with customer login. For storing language chosen in log-in page. |
hideFufilmentBanner | Used in connection with navigation through an app. |
hideBulkOrderingFeatureBanner | Used in connection with navigation through an app. |
hideChangePlanBannerBulkFulfillment | Used in connection with navigation through an app. |
hideBanner101 | Used in connection with navigation through an app. |
alert_setup_notifications_1 | Used in connection with navigation through an app. |
Reporting and Analytics
Name | Function |
conversion | Oberlo analytics. |
conversion_leave | Oberlo analytics. |
trackExtensionCheck | Oberlo analytics. |
shopify_ref | Analytics relating to marketing & referrals. Referrals tracking. |
Additionally, we use pixels and tags from the following third parties, which may in turn place cookies:
Reporting & Analytics:
Third Party | Description | Privacy Policy |
Loggly | We use Loggly to help us troubleshoot and fix issues with our websites. | https://www.loggly.com/about/privacy-policy/ |
Sleeknote | We use Sleeknote to measure how people interact with our website. | https://sleeknote.com/privacy-policy |
Inspectlet | We use Inspectlet to help measure how users interact with our websites. | https://www.inspectlet.com/terms-of-service |
Google Analytics | We use Google Analytics to help measure how users interact with our websites. | https://policies.google.com/privacy |
Fullstory | We use Fullstory to help measure how users interact with our websites. | https://www.fullstory.com/legal/privacy/ |
KissInsights | We use KissInsights to help measure how users interact with our websites. | https://signin.kissmetrics.com/privacy/ |
Optimizely | We use Optimizely to help us test improvements or changes to our websites. | https://www.optimizely.com/privacy/ |
LinkedIn Insight Tag | We use LinkedIn Insight Tag to help measure how users interact with our websites. | https://www.linkedin.com/legal/privacy-policy |
Tapfiliate | We use Tapfiliate to help measure how users interact with our websites. | https://tapfiliate.com/privacy/privacy-policy/ |
Advertising:
Third Party | Description | Privacy Policy |
Microsoft Advertising | We use Microsoft Advertising to deliver targeted advertisements to individuals who visit our websites. | https://privacy.microsoft.com/en-ca/privacystatement |
Facebook Custom Audiences | We use Facebook Custom Audiences to deliver targeted advertisements to individuals who visit our websites. | https://www.facebook.com/policy.php |
We use Google Ads to deliver targeted advertisements to individuals who visit our websites. | https://policies.google.com/privacy | |
Intercom | We use Intercom to manage our relationships with our customers. | https://www.intercom.com/terms-and-policies#privacy |
Social Media & Content:
Third Party | Description | Privacy Policy |
Disqus | We use Disqus to provide commenting capabilities on posts on our websites. | https://help.disqus.com/terms-and-policies/disqus-privacy-policy |
Facebook Connect | We use Facebook Connect to allow visitors to our website to interact with and share content via Facebook’s social media platform. | https://www.facebook.com/policy.php |
Gravatar | We use Gravatar to allow visitors to our websites to create avatars. | https://en.gravatar.com/site/privacy |
Youtube | We use Youtube to display video content. | https://policies.google.com/privacy?hl=en-US |
Wistia | We use Wistia to display video content. | https://wistia.com/privacy |
AddThis | We use AddThis to display social share capabilities on the website. | https://www.addthis.com/privacy/terms-of-service |
We use Twitter to allow visitors to our website to interact with and share content via Twitter’s social media platform. | https://twitter.com/en/privacy | |
Kajabi | We use Kajabi to serve Oberlo 101 course material. | https://kajabi.com/policies/privacy |
How long will cookies remain on my computer or mobile device?
The length of time that a cookie remains on your computer or mobile device depends on whether it is a “persistent” or “session” cookie. Session cookies last until you stop browsing and persistent cookies last until they expire or are deleted. Most of the cookies we use are persistent and will expire between 30 minutes and two years from the date they are downloaded to your device. See the section below on how to control cookies for more information on removing them before they expire.
How to control cookies?
You can control and manage cookies in various ways. Please keep in mind that removing or blocking cookies can negatively impact your user experience and parts of our website may no longer be fully accessible.
Most browsers automatically accept cookies, but you can choose whether or not to accept cookies through your browser controls, often found in your browser’s “Tools” or “Preferences” menu. For more information on how to modify your browser settings or how to block, manage or filter cookies can be found in your browser’s help file or through such sites as: www.allaboutcookies.org.
Many of the third party advertising and other tracking services listed above offer you the opportunity to opt out of their tracking systems. You can read more about the information they collect and how to opt out through the privacy policy links listed above.
Last updated: April 20, 2021