Features Pricing GDPR cookie banner Google Consent Mode v2 WordPress plugin Cookiebot alternative For Agencies GDPR ePrivacy About Contact
RO | EN
Start Free →
Marketing

_shopify_sa_p – Shopify marketing cookie

_shopify_sa_p is a short-lived HTTP cookie set by the Shopify platform on online stores hosted on its infrastructure. It is used for attributing sales and traffic to marketing sources, which is why it falls under the marketing/advertising category.

Name
_shopify_sa_p
Provider
Shopify
Category
Marketing
Type
HTTP cookie
Lifetime
30 minutes
Consent
Yes, before it is set (GDPR / ePrivacy)

What is the _shopify_sa_p cookie?

_shopify_sa_p is a first-party cookie created by Shopify's core scripts running on any store hosted on the platform. It belongs to the "shopify_sa" (sales attribution) family of cookies, used internally by Shopify to analyze commercial traffic.

It appears as soon as a visitor lands on a Shopify store, regardless of whether they interact with the page, since it is set by the platform's base code rather than an optional app installed by the merchant.

What data it stores

The cookie stores information about the visitor's traffic source (such as referrer, channel, or campaign parameters) for a short time window, used to link a session to a possible later conversion.

The exact value format is not publicly documented by Shopify and may vary; manually reading or editing it is not recommended. The data is read by Shopify's own scripts in the browser and may be sent back to Shopify's internal systems for traffic and sales reporting.

What it is used for

Its main purpose is sales attribution: Shopify uses this cookie to determine which source (search engine, social network, paid campaign, etc.) a visitor came from before completing an order, information later surfaced in analytics reports for merchants.

For the store owner, this attribution helps evaluate how well different marketing channels perform, even though the cookie itself isn't directly configurable from the Shopify admin.

Does it require consent?

_shopify_sa_p is classified as a marketing/tracking cookie, since it contributes to traffic behavior analysis and conversion attribution across advertising sources. Under Law 506/2004 (transposing the ePrivacy Directive) and the GDPR, this type of cookie requires the visitor's prior consent before being set.

  • The store owner must list it explicitly in the cookie policy, under the marketing category.
  • Active consent must be obtained before it loads, not just a passive notice.
  • Declining consent should not break the store's core shopping functionality.

How to block or delete _shopify_sa_p

A visitor can delete or block this cookie at any time from browser settings (Chrome, Firefox, Edge, Safari — the per-site cookie management section), either individually or by clearing all browsing data for the store's domain.

For the site owner, automatic blocking until consent is given is handled through a CMP (Consent Management Platform) such as CookieFix, which can stop Shopify's marketing scripts from running before the visitor accepts cookies, showing the consent banner on the first visit.

Frequently asked questions

No, it doesn't hold directly identifying information like passwords or payment data; it's used strictly to attribute traffic to marketing sources.

Yes, blocking it doesn't affect core store functions like the shopping cart or checkout, since it's an analytics/marketing cookie, not a strictly necessary one.

If it loads before consent, the store lacks a proper pre-consent blocking mechanism; a correctly configured CMP should stop Shopify's marketing scripts until the visitor accepts.

It typically lasts around 30 minutes, meant to cover a single short browsing session.

Updated 7 September 2026 · Information comes from the provider’s public documentation and CookieFix scans; it is not legal advice.