Every Shopify storefront sets its own cookies — before you install a single app. Eleven are strictly necessary (cart, checkout, session, security), two are analytics, four support marketing attribution, and one remembers locale preferences. Here is the complete table, the same one a cookie policy needs to disclose.
The complete table of Shopify's cookies
Strictly necessary — no consent required, must be disclosed
| Cookie | What it does | Lasts |
_secure_session_id | Tracks your session as you navigate the store | 24 hours |
cart | Remembers the items in the shopping cart | 2 weeks |
cart_ts | Records when the cart was last changed, for checkout | 2 weeks |
cart_sig | Verifies the cart has not been tampered with at checkout | 2 weeks |
checkout_token | Links the cart to a checkout so an order can complete | 1 year |
secure_customer_sig | Keeps a customer signed in to their account | 20 years |
storefront_digest | Remembers the storefront password on protected stores | 2 years |
keep_alive | Keeps the session alive while browsing | 30 minutes |
_tracking_consent | Records the visitor's tracking preferences | 1 year |
_cmp_a | Manages privacy settings for the store | 24 hours |
Analytics — consent required in opt-in regions
| Cookie | What it does | Lasts |
_shopify_y | Identifies a returning visitor for store analytics | 1 year |
_shopify_s | Identifies a single browsing session for analytics | 30 minutes |
Marketing and attribution
| Cookie | What it does | Lasts |
_shopify_sa_t | Records the time of a marketing or referral visit | 30 minutes |
_shopify_sa_p | Records the marketing or referral source of the visit | 30 minutes |
_landing_page | Records the first page the visitor arrived on | 2 weeks |
_orig_referrer | Records the site that referred the visitor | 2 weeks |
Preferences
| Cookie | What it does | Lasts |
localization | Remembers chosen country, language and currency | 1 year |
Durations are Shopify's documented values and can change as the platform evolves. Treat any published table — including this one — as a starting point you review, not a permanent fact.
What controls whether the non-essential ones get set?
Shopify gates its own analytics and marketing cookies on its native consent system, the Customer Privacy API. When a consent app writes “analytics: denied” to that API, Shopify stops setting _shopify_y and _shopify_s. That is the correct mechanism — hiding the banner does not do it, and blocking Shopify's own scripts is neither possible nor necessary.
What about the cookies your apps add?
Everything above is just the platform. A typical store adds Google Analytics (_ga, _ga_*), Meta (_fbp), TikTok (_ttp), Klaviyo (__kla_id) and more through apps and pixels. Those need their own rows in your cookie declaration, and in opt-in regions they need real blocking before consent — not just a banner that mentions them.
Frequently asked
Which Shopify cookies are strictly necessary?
The cart and checkout cookies (cart, cart_ts, cart_sig, checkout_token), session cookies (_secure_session_id, keep_alive), account cookies (secure_customer_sig, storefront_digest) and Shopify's own consent cookies (_tracking_consent, _cmp_a). A store cannot function without them, so consent laws do not require asking permission for them.
What are _shopify_y and _shopify_s?
Shopify's own analytics cookies. _shopify_y identifies a returning visitor for about a year; _shopify_s ties together one browsing session for about 30 minutes. Both are analytics cookies, so under GDPR they need consent before being set — which is what Shopify's Customer Privacy API controls.
Do I have to list Shopify's cookies in my cookie policy?
Yes. GDPR transparency rules and CCPA notice-at-collection expect you to disclose the cookies your store sets, including the platform's own. That is exactly what a cookie declaration table is for.