Policara

Cookie Policy Generator

Under GDPR and the EU ePrivacy Directive, you must disclose every cookie your site sets — including third-party analytics, advertising pixels, and authentication cookies. Policara reads your tech stack to identify which cookies each service drops, then generates a policy with the disclosures each one calls for. Cookie Policy generation is a Pro feature — the free plan covers privacy policies only; Pro is $9/month.

Step 2 of 7

About your product

Frequently asked questions

Do I need a cookie policy?
Yes, if your site sets cookies and you have visitors from the EU, UK, or many other jurisdictions. The EU ePrivacy Directive (Article 5(3)) generally requires consent before non-essential cookies are set, and GDPR Article 13 governs what you must tell users about the data involved — including third-party cookies from Google Analytics, Meta Pixel, and Stripe.
What is a cookie policy?
A cookie policy (also called a cookie notice or cookie disclosure) lists every cookie your website sets, who sets it (first party vs third party), what it does, and how long it lasts. It's typically linked from your cookie consent banner and your privacy policy.
What cookies does my Shopify store set?
Shopify sets several cookies by default: _shopify_y (analytics, 1 year), _shopify_s (session, 30 min), cart (session commerce), and secure_customer_sig (auth). If you use Shopify Payments or Google Analytics, additional cookies apply. Policara lists the ones we detect from the platform you select.
Do I need a cookie policy for Google Analytics?
Yes. Google Analytics sets the _ga cookie (2 years) and _gid cookie (24 hours), and requires disclosure under GDPR Article 13 and ePrivacy. If you use GA4 with Google Signals, additional tracking applies. Policara generates a disclosure for the Analytics configuration you describe.
Is a cookie policy the same as a privacy policy?
No, but they're related. A privacy policy covers all personal data you collect. A cookie policy specifically covers tracking technologies — cookies, pixels, and local storage. GDPR requires both, and your cookie policy is often referenced from your privacy policy.

Compliance rules last updated 2026-06-10