Tracker library

Shopify platform: what it is, what it sets, and how to gate it.

Shopify’s purpose-specific storefront storage plus app-added technologies, which must be inventoried separately from the platform itself.

Vendor
Shopify
Scanner category
mixed
Consent category
Necessary, analytics and app-specific
Control
Custom script or container tag

What it is

Shopify’s current cookie policy separates storefront storage by purpose. It lists necessary storage such as `_shopify_essential` and `cart`, reporting and analytics entries such as `_shopify_analytics`, and a marketing entry named `_shopify_marketing`. Necessary status is purpose-specific: it should not be inherited by every cookie merely because Shopify sets it.

The documentation is not perfectly consistent. Shopify’s August 2025 changelog says `_shopify_y` and `_shopify_s` would no longer be set on merchant storefronts from 1 January 2026, while the cookie policy updated 15 September 2026 still lists them. Treat those names as implementation evidence to check, not a guaranteed current baseline.

Integrate choices through the Customer Privacy API rather than reading or editing Shopify cookies directly. Shopify explicitly warns that cookie values can change, and some newer or headless surfaces can persist consent through a server-backed path instead of the legacy `_tracking_consent` JavaScript-cookie path.

What a scan matches

A verification scan drives a real browser and records the outbound requests observed during its configured journeys, so Shopify platform is identified by request hosts and paths rather than by source-code claims. Requests on unvisited paths, after unperformed interactions or solely on the server remain outside that observation.

  • shopify.com, myshopify.com, shopifycdn.com, shopifysvc.com, shop.app

Cookies are classified by name before domain because many analytics and advertising tags write first-party cookies through the page, which places a vendor-related identifier on your domain. Matching known names helps attribute those values without assuming that every first-party cookie came from your own application.

CookieWhat it is for
_shopify_essential, cartStore, session, checkout and basket functions described by Shopify as necessary
_tracking_consentA consent-preference cookie in Shopify’s current policy; newer or headless surfaces may persist consent through a server-backed path instead
_shopify_analytics, _landing_page, _orig_referrerCurrent reporting and analytics entries in Shopify’s cookie policy
_shopify_y, _shopify_sShopify announced their retirement from merchant storefronts from 1 January 2026, although its cookie policy updated in September 2026 still lists both; report them only when observed
_shopify_marketingMarketing data for buyer surfaces in Shopify’s current cookie policy

Controlling it with consent

The Shopify theme app extension loads the shared runtime and synchronises choices with Shopify’s Customer Privacy API. Where an app is not installed, the same runtime can be added as a script tag with the `shopify-lite` platform value, which still drives Customer Privacy.

The real work on a storefront is the apps. Each one may inject its own pixels, and removing a tracker from the theme does not remove it from an app.

No named adapter: choose the appropriate control

The product ships named adapters for Google Tag Manager, Google Analytics, the Meta and TikTok pixels, and Klaviyo. Choose the control route that fits this technology: a custom HTTPS script declaration for a browser loader, an individual consent condition inside a tag manager, a platform or app setting, or a click-to-load placeholder for a frame. Server-side integrations need their own enforcement because a browser runtime cannot stop them.

What breaks if it is refused: basket or checkout behavior if storage that is genuinely necessary for the requested shopping flow is blocked. Keep that purpose-limited set available; analytics identifiers and app pixels remain separate, optional questions.

Verifying it

Scan the live storefront with apps enabled. Compare the Customer Privacy API state with the visitor’s choice, inspect the storage actually present in that deployment, and look for pixels arriving from apps rather than assuming a fixed Shopify cookie list.

  • Before a choice: optional tracking endpoints and optional identifiers are absent; any intentionally loaded necessary or functional surface matches the control model described above
  • After rejecting optional categories: optional activity remains absent and the refusal persists across a reload
  • After granting the relevant category: the expected loader or embed appears and the feature behaves normally
  • After withdrawing: new optional activity stops; where the vendor supports a consent signal, verify that the signal is sent as well as checking network behavior

Common questions

Which Shopify cookies are strictly necessary?

Basket, checkout-session and security cookies can qualify when they are actually limited to providing the shopping or payment flow the visitor requested. Analytics identifiers serve a different purpose, and app-added storage must be assessed separately rather than inheriting Shopify’s label.

Does Shopify’s Customer Privacy API replace a consent platform?

It is the mechanism by which Shopify surfaces and apps learn the decision. Something still has to present the choice, record it, and be able to demonstrate it later, and to cover the apps that do not consult the API.

Sources and verification

Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.

See what your own site is loading

A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.