What is the _shopify_sa_t cookie?
_shopify_sa_t is an HTTP cookie used by Shopify, the e-commerce platform powering a large number of online stores. It belongs to Shopify's internal "sales attribution" cookie set, alongside related cookies such as _shopify_sa_p.
It is set automatically by Shopify's own scripts whenever a visitor loads a store built on the platform, regardless of whether the store owner has installed additional marketing apps. It typically appears from the very first page load.
What data it stores
The cookie stores technical information about the current visit session, used to determine where a visitor came from (for example, an ad campaign, a social network, or a search engine). Shopify does not publicly document the exact value format, and it may vary.
The data is read by Shopify's scripts directly in the browser and may be sent to Shopify's internal systems to build attribution reports available to the merchant in the store's admin panel.
What it is used for
The main purpose is to correctly attribute sales and conversions to the traffic source that generated them (channel, campaign, referral). In practice, it helps the merchant understand which marketing channels actually drive customers and sales.
For Shopify, this data feeds the performance statistics shown in the store's dashboard, which merchants use to optimize advertising budgets.
Does it require consent?
Since it is used for marketing/traffic-analytics purposes rather than being strictly necessary for the site to function, _shopify_sa_t falls under the cookies for which the ePrivacy Directive (transposed in Romania via Law 506/2004) and the GDPR require prior visitor consent, obtained through a consent banner.
The Shopify store owner should list it in the cookie policy, classify it under the marketing/statistics category, and make sure it is not activated before the visitor gives explicit consent.
How to block or delete _shopify_sa_t
A visitor can delete or block this cookie manually from browser settings (Chrome, Firefox, Edge, Safari – per-site cookie management) or by using private/incognito browsing.
- Site owners can automatically block the script that sets this cookie until consent is given, using a CMP such as CookieFix, which intervenes before Shopify's attribution scripts run.
- It's worth testing this separately across installed Shopify themes and apps, since some native scripts can fire very early in the page load.
Frequently asked questions
No, it is a standard traffic-attribution cookie used by Shopify and does not contain sensitive data like passwords or financial details.
Yes, blocking it doesn't affect core store functions like the cart or checkout, only internal sales-attribution reporting.
It is set natively by the Shopify platform itself, not by a third-party app, as part of core traffic-source tracking functionality.
Yes, any marketing or statistics cookie must be disclosed in the site's cookie policy under GDPR and ePrivacy rules.