Persistent Cart · Legal

COOKIE POLICY

Persistent Cart — Cookie Policy

Effective date: 2026-10-01

This Cookie Policy explains what cookies and similar technologies the Persistent Cart Shopify application uses, why, and how you can control them.


1. What is a cookie

A cookie is a small text file placed on your device by a website or application. Cookies are widely used to make applications work, or work more efficiently, and to provide information to the operator. This policy also covers similar technologies that store information in your browser, such as localStorage.


2. Who this applies to

Merchants (Shopify Admin users): when you use the Persistent Cart admin interface embedded inside your Shopify Admin, certain cookies are set by Shopify and by the App to maintain your authenticated session.

End-customers of Merchant stores: when you visit a store where Persistent Cart is installed, the App's storefront Theme App Extension stores information in your browser only if you are logged in to the store. See Section 4.


3. Cookies used in the Shopify Admin (merchants)

The Persistent Cart admin interface is an embedded Shopify app that operates inside an iframe within the Shopify Admin.

Name / categoryTypeSet byPurposeDuration
Shopify Admin session cookiesStrictly necessaryShopify Inc.Authenticate the Shopify Admin session; required for the embedded app frame to function.Session / as set by Shopify
App session identifierStrictly necessaryPÉCI Kft. via Shopify session storageMaintains the authenticated connection between the embedded app and our servers. Managed via Shopify's app authentication (server-side session storage and App Bridge session tokens); the App does not set its own tracking cookie.Until token expiry or uninstall

No analytics, advertising, or cross-site tracking cookies are set in the admin interface by us.


4. Storage used by the storefront Theme App Extension (customers)

The Persistent Cart Theme App Extension runs as a JavaScript widget injected into the Merchant's storefront via Shopify App Embeds. It sets no cookies and does not use sessionStorage. What it keeps in the browser:

TechnologyWhoWhat is storedPurposeDuration
Browser localStorage, one entry (persistent_cart_state)Logged-in customers onlyThe Shopify customer ID, the cart token, the number of items and the cart items (product variant IDs and quantities), the time the entry was written, and the expiry of the cart saved on our serverTells the widget whether this device has already been used with the customer's saved cart, so that a cart emptied here is saved as empty rather than replaced by an older saved cartRemoved by the widget at the first page load of the store after the saved cart expires on our server (and at most 60 days after the entry was written), after the customer logs out, or after a different customer logs in on the device
NoneCustomers who are not logged inNothing--

Shopify's own cart cookie. To read the cart, the widget calls the store's cart endpoint (/cart.js). That request relies on Shopify's cart cookie, which Shopify sets and controls, not the App.

Data kept on our servers. The saved cart, the share links and the attribution records (LinkClick, OrderConversion) are kept on our servers, not in the browser. When someone opens a Share a Cart link and allows marketing in the store's consent settings, the storefront widget sends the click to our servers together with the referring address and the token of the browser's cart; for a link that goes straight to checkout, a Shopify Web Pixel sends it instead, reading the link code from the checkout attributes and the checkout token. Nothing is written to the device for either. These records are described in the Privacy Policy, Sections 3b and 5.

Consent. We consider the localStorage entry above strictly necessary for the cross-device cart service that the logged-in customer uses, and we keep it no longer than the saved cart itself. The App reads the Customer's marketing consent from Shopify's Customer Privacy API and records a Share a Cart link click only when marketing is allowed; the localStorage entry does not depend on it. Where the law that applies to the store requires consent for any storage or processing through the App, the Merchant, who operates the store, is responsible for informing customers and obtaining it. We do not use this data for cross-site tracking or advertising, and we do not place advertising pixels or third-party tracking scripts in the storefront widget. The Shopify Web Pixel we use for checkout-direct links is a first-party pixel that records only the Share a Cart link click, with the Customer's marketing consent, and does no cross-site tracking or advertising.


5. Third-party cookies

The App does not load third-party scripts that set cookies. Any third-party cookies present on a Merchant's storefront (e.g. Google Analytics, Meta Pixel) are the responsibility of the Merchant.


6. Your choices

Merchants: you cannot opt out of the strictly necessary session cookies while using the Shopify Admin — they are required for the service to function. You can end your session by logging out of Shopify Admin.

End-customers: the widget stores information in your browser only if you are logged in to the store (Section 4). You can remove it at any time by clearing the store's site data in your browser; the widget also removes it when you log out, when your saved cart expires, or when another customer logs in on the same device. For questions about consent, or about the store's own cookies, contact the Merchant whose store you used. Most browsers let you control cookies and site data through their settings:


7. Changes to this policy

We will update this policy if we introduce new cookies or storage technologies. Material changes are notified per the Privacy Policy, Section 13.


8. Contact

For questions about this Cookie Policy:

PÉCI Kft. Aradi utca 5., 2119 Pécel, Hungary Data / privacy matters: privacy@peci.io Legal notices: legal@peci.io