What it does
Shopify’s cookie policy, updated 15 September 2026, still describes `_shopify_y` as Shopify analytics with a one-year duration and `_shopify_s` as a 30-minute browser-session/shop identifier. However, Shopify’s developer changelog says both would stop being set on merchant storefronts from 1 January 2026. Because those first-party sources conflict, a declaration should follow observed production behavior and record the date and surface tested.
If `_shopify_y` is observed, it is analytics rather than basket or checkout storage. Shopify’s current policy separately lists necessary entries such as `_shopify_essential` and `cart`; grouping all Shopify cookies together would hide the purpose distinction.
What to write in a cookie declaration
List `_shopify_y` only if the live store actually sets it. Separate observed analytics storage from necessary basket, checkout and consent-preference storage, and recheck after platform changes.
| Field | Value |
|---|---|
| Name | _shopify_y |
| Provider | Shopify |
| Purpose category | analytics |
| Consent category | Analytics, when observed |
| Expiry | Shopify documents 1 year, but also announced retirement (vendor default) |
| Storage | First-party |
Treat the expiry as indicative
The value above is the vendor’s documented default. Vendors change configuration and several browsers cap script-written lifetimes. Record what repeated scans observe on your own site, with the browser, region, path and interaction state; one run is not authoritative for every visitor.
Can a visitor refuse it?
When observed for analytics, it is optional in the product model. Do not infer that basket and checkout storage is optional—or that every Shopify cookie is necessary—from this one name; assess each purpose separately and pass choices through Shopify’s Customer Privacy API.
A verification scan supplies runtime evidence for the pages and states it exercises. Test a fresh profile with no choice made, then after refusal, and reconcile observed storage with response headers, server-side integrations and paths the scan did not visit.
Common questions
Did Shopify retire _shopify_y?
Shopify announced that `_shopify_y` and `_shopify_s` would no longer be set on merchant storefronts starting 1 January 2026. Its cookie policy updated 15 September 2026 nevertheless still lists both. Do not resolve that documentary conflict by guessing: inspect the live store and report the observed behavior.
Sources and verification
Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.
- Shopify Cookie Policy
Vendor documentation
Checked
- Shopify changelog: _shopify_y and _shopify_s retirement notice
Vendor documentation
Checked
- Shopify Customer Privacy API
Vendor documentation
Checked
See what your own site is loading
A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.