Features Pricing GDPR cookie banner Google Consent Mode v2 WordPress plugin Cookiebot alternative For Agencies GDPR ePrivacy About Contact
RO | EN
Start Free →
Necessary

_cmp_a Cookie (Shopify) – What It Is and Why It's Set

_cmp_a is a technical cookie set by Shopify on online stores built on this platform, used to support the store's internal consent-management state. It is classified as strictly necessary because it underpins the store's own consent mechanism. Its typical duration is 1 day.

Name
_cmp_a
Provider
Shopify
Category
Necessary
Type
HTTP cookie
Lifetime
1 day
Consent
No, but it must be listed in the cookie policy

What is the _cmp_a cookie?

_cmp_a is an HTTP cookie set by Shopify, the e-commerce platform powering the visited store. It belongs to Shopify's internal Consent Management Platform infrastructure rather than to an external marketing tool.

It typically appears on a first visit to a Shopify store, when the platform initializes its own cookie-preference handling, whether or not the store also runs its own consent banner (such as the one offered by CookieFix).

What data it stores

Shopify does not publish detailed technical documentation about the exact value format of _cmp_a, so its internal structure can vary and should not be assumed. Cookies in this family generally store an identifier or technical flag tied to the platform-level consent state.

The value is read by Shopify scripts loaded on the store's pages; there is no public documentation confirming that this data is systematically sent to third-party servers.

What it is used for

The cookie's purpose is purely functional: it helps Shopify maintain internal consistency of the consent state and other technical mechanisms needed to display the store correctly across pages visited in the same session or day.

For the store owner, this cookie cannot be selectively disabled, as it is part of Shopify's core infrastructure; it does not serve marketing or third-party traffic-analysis purposes.

Does it require consent?

Under CookieFix's classification, _cmp_a is categorized as strictly necessary. Strictly necessary cookies do not require prior visitor consent under Article 5 of the ePrivacy Directive (implemented in Romania via Law 506/2004), since they support functionality explicitly requested by the user or required to operate the site.

  • No prior consent is required for it to be set.
  • It still must be listed in the store's cookie policy, with its purpose and provider (Shopify), per GDPR transparency obligations (Art. 13).
  • The store owner should not block it via a CMP, but must disclose it correctly to visitors.

How to block or delete _cmp_a

A visitor can delete or block _cmp_a from browser settings (Chrome, Firefox, Safari, Edge – per-site cookie management), though this may affect how the store's internal consent system functions.

Since it is strictly necessary, it should not be auto-blocked by a consent banner before user action. A CMP such as CookieFix can still detect and correctly classify this cookie during a scan, automatically blocking only scripts from categories that actually require consent (statistics, marketing, preferences), while leaving strictly necessary cookies like _cmp_a to function without interruption.

Frequently asked questions

No, it's a technical cookie set by Shopify for the store's internal operation and is not associated with advertising tracking.

No, since it is strictly necessary for the platform to function, it does not require prior visitor consent, but it must be disclosed in the cookie policy.

Its typical duration is 1 day, after which it expires automatically.

Shopify may set it again on the next visit; deleting it can temporarily affect the store's internal consent mechanisms.

Updated 7 September 2026 · Information comes from the provider’s public documentation and CookieFix scans; it is not legal advice.