What is the _secure_session_id cookie?
_secure_session_id is a technical cookie automatically set by Shopify on any online store hosted on its platform. It appears on the first visit to the site, regardless of whether the visitor accepts the cookie policy, because it is part of the core infrastructure required for the store to work.
The cookie is created and managed exclusively by Shopify, the e-commerce platform provider, not by the merchant running the actual store.
What data it stores
The cookie stores a unique session identifier, generated by Shopify's servers to recognize a visitor throughout their browsing session. The exact value and internal format vary and are managed by Shopify; they typically do not contain directly readable personal data such as a name or email address.
Session-related data is sent to Shopify's servers, which host the technical infrastructure of the store.
What it is used for
Its main role is maintaining session state during the visit: remembering the shopping cart contents, keeping the customer logged into their account, and ensuring continuity through the checkout process. Without this cookie, the core functions of a Shopify store could not work properly.
Does it require consent?
Under CookieFix's classification, _secure_session_id is a strictly necessary cookie, since it supports essential functionality explicitly requested by the user (cart, checkout, login). Under the ePrivacy Directive (transposed in Romania as Law 506/2004) and GDPR, strictly necessary cookies do not require prior consent.
The store owner should still list this cookie in the cookie policy, along with its purpose and duration, to maintain transparency with visitors and meet GDPR information obligations.
How to block or delete _secure_session_id
A visitor can delete or block this cookie from browser settings (Chrome, Firefox, Safari, Edge), under the cookie and site data management section. Blocking it may break the shopping cart and login functionality on that store.
- Because it is strictly necessary, it should not and cannot be blocked via a consent banner, or the store's core functions will break.
- A consent management platform like CookieFix automatically classifies this cookie as "necessary" and excludes it from the pre-consent blocking applied to statistics or marketing scripts, letting it run from the first moment of the visit.
Frequently asked questions
No, since it is strictly necessary for the shopping cart and checkout to function, it does not require prior consent under ePrivacy and GDPR. It should still be disclosed in the cookie policy.
The cookie is set technically by Shopify, the e-commerce platform, as part of its core infrastructure for any store hosted on it. The merchant does not configure it manually.
The current session is lost, meaning cart items may disappear and the user may be logged out of their account if they were signed in.
The typical duration is 1 day, after which the cookie expires automatically and a new session is generated on the next visit.