- Do I need a cookie policy?
- Yes, if your site sets cookies and you have visitors from the EU, UK, or many other jurisdictions. The EU ePrivacy Directive (Article 5(3)) generally requires consent before non-essential cookies are set, and GDPR Article 13 governs what you must tell users about the data involved — including third-party cookies from Google Analytics, Meta Pixel, and Stripe.
- What is a cookie policy?
- A cookie policy (also called a cookie notice or cookie disclosure) lists every cookie your website sets, who sets it (first party vs third party), what it does, and how long it lasts. It's typically linked from your cookie consent banner and your privacy policy.
- What cookies does my Shopify store set?
- Shopify sets several cookies by default: _shopify_y (analytics, 1 year), _shopify_s (session, 30 min), cart (session commerce), and secure_customer_sig (auth). If you use Shopify Payments or Google Analytics, additional cookies apply. Policara lists the ones we detect from the platform you select.
- Do I need a cookie policy for Google Analytics?
- Yes. Google Analytics sets the _ga cookie (2 years) and _gid cookie (24 hours), and requires disclosure under GDPR Article 13 and ePrivacy. If you use GA4 with Google Signals, additional tracking applies. Policara generates a disclosure for the Analytics configuration you describe.
- Is a cookie policy the same as a privacy policy?
- No, but they're related. A privacy policy covers all personal data you collect. A cookie policy specifically covers tracking technologies — cookies, pixels, and local storage. GDPR requires both, and your cookie policy is often referenced from your privacy policy.