01What cookies are
Cookies are small files a website stores in your browser; local storage is a similar place where a site can keep information on your device. This policy calls both "storage" and lists the items represented in the reviewed application and runtime. The list must be reconciled with the live deployment before this draft is approved.
02Types of storage we use
In the application code reviewed on 19 September 2026, strongprivacy.com uses strictly necessary storage to sign users in and connect a store, plus user-initiated preference storage such as the theme. That review found no configured analytics, advertising or social-media tracker on the public site or dashboard. This is a dated implementation finding, not a permanent statement about every deployment.
The one page that loads a third party is the dashboard page embedded in the Shopify admin, which loads Shopify's App Bridge script so the app can run inside Shopify.
03Storage on strongprivacy.com
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
| strongprivacy_session | Cookie (HTTP-only) | Keeps you signed in to the dashboard. | 7 days, or until you sign out |
| strongprivacy_shopify_oauth | Cookie (HTTP-only) | Protects the Shopify connection step against forgery. | 10 minutes |
| strongprivacy_shopify_install | Cookie (HTTP-only) | Carries a store-initiated Shopify install through sign-in. | 10 minutes |
| strongprivacy_shopify_claim | Cookie (HTTP-only) | Links a newly installed Shopify store to your workspace. | 2 hours |
| strongprivacy-theme | Local storage | Remembers whether you chose the light or dark theme. | Until you clear it |
| strongprivacy-after-verify | Local storage | Returns you to the page you were heading for after confirming your email. | 2 hours |
04Cookie consent
The reviewed application does not show a cookie banner because its current inventory contains necessary storage and preferences a user explicitly selects. A fresh-browser production scan and response-header review must confirm that position. If optional storage is introduced where prior consent applies, it must be withheld until the required choice is obtained.
05Storage on websites that use StrongPrivacy
Customers install the StrongPrivacy runtime to ask their visitors for consent. To remember a visitor's choice, the runtime stores the items below on that website. The customer decides the consent duration and is responsible for describing these items in its own cookie notice.
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
| strongprivacy_<site id> | Cookie and local storage | The visitor’s consent choices, a random identifier for the choice, and when it was made. | 180 days by default; the site owner can set 1 to 730 days |
| strongprivacy_custom_<site id> | Local storage | Choices for any custom categories the site defines. | Same as the consent duration |
| strongprivacy_revision_<site id> | Local storage | Which version of the site’s policy the choice was made under, so a changed policy can ask again. | Until cleared |
| strongprivacy.config.<site id> | Local storage | A cached copy of the banner’s configuration, for speed. | Refreshed after 24 hours |
| __kla_off | Cookie | Tells Klaviyo not to track, set only on sites that use Klaviyo when the visitor declines. | 2 years |
On Shopify stores the runtime also passes the choice to Shopify's Customer Privacy API, which sets Shopify's own cookies under Shopify's policies.
06Managing your preferences
On a website that uses StrongPrivacy, reopen its preference center, usually from a "Privacy choices" or "Cookie settings" link, to change your choice at any time. On strongprivacy.com you can switch the theme from the header.
07Managing cookies in your browser
Major browsers provide controls to view, block and delete cookies and site data, although names and behaviour vary. Blocking the session cookie will stop dashboard sign-in; clearing a customer site's consent storage will normally cause its banner to ask again on the next applicable visit.
08Updates to this policy
We update this policy whenever we add, rename or remove an item, and change the date at the top. The privacy policy explains how we handle the information these items relate to.
Questions, or requests for a prior version of this document, go to info@accessible.org.