Skip to content

Cookie policy

Last updated 28 August 2026

Picklist sets no analytics, advertising or cross-site tracking cookies anywhere. It does store two small values in a shopper’s browser so that a list survives a page reload, and this page says exactly what they are — because you may need to describe them in your own consent banner.

On your storefront

Neither of these is a cookie. Both are browser storage, are readable only by your own domain, and are never sent to a third party.

KeyWhereWhat it holdsLifetime
picklist:tokenlocalStorageA random identifier for a guest’s list. It identifies a list, not a person — it holds no name, no email and nothing derived from the shopper. Without it, a shopper who is not signed in loses their list on the next page loadUntil the shopper signs in, at which point the list is merged into their account and the token is discarded — or until they clear site data
picklist:statesessionStorageA cached copy of the current list, so moving between pages does not re-fetch itThe browser tab session

What this means for your consent banner

Both values are strictly necessary to provide a feature the shopper asked for by pressing save. Under the ePrivacy Directive and equivalent rules, storage that is strictly necessary for a service the user explicitly requested does not require prior consent.

Nothing is written before a shopper interacts with the app: opening a page and never touching the save control leaves no storage behind. Picklist adds no advertising or analytics category to your banner.

You know your own compliance posture better than we do. If your legal advice is that these should sit behind consent, block the app embed until consent is given — the extension is inert until its script runs.

Installing the app

Shopify’s OAuth flow sets short-lived, strictly necessary cookies, managed by Shopify’s own app library rather than by us:

CookiePurposeLifetime
shopify_app_stateCarries the OAuth state parameter, which prevents an attacker completing an authorisation you startedMinutes — cleared once the install completes
shopify_app_sessionIdentifies the session during the install handshakeThe browser session

The embedded app in Shopify admin

Once installed, the Picklist admin runs inside Shopify’s admin and authenticates with App Bridge session tokens rather than cookies. The Shopify admin’s own cookies are Shopify’s and are covered by their policies.

This website

The landing page, the FAQ and the policy pages set no cookies at all and load no third-party scripts. There is nothing here to consent to.

Controlling storage

A shopper can clear site data in their browser at any time. Doing so discards a guest list; a list attached to a customer account is unaffected and returns on the next sign-in. If storage is blocked entirely, saving still works for the current page but the list will not persist.

Questions

See the privacy policy for what is stored on our side, or write to [email protected].