What is the cart cookie?
The cart cookie is set automatically by Shopify, the e-commerce platform hosting the online store, as soon as a visitor adds a product to the cart, or in some cases already on the first page load. It is a native HTTP cookie belonging to Shopify's checkout engine, present by default on every store built on this platform (whether on a custom domain or a myshopify.com subdomain).
It is not a cookie added by the site owner through a third-party script: it is part of the platform's technical infrastructure and appears on all Shopify stores regardless of theme or installed apps.
What data it stores
The cookie stores a unique token (an identifier generated by Shopify) that links the visitor's browser to the shopping cart record kept on Shopify's servers. The value itself does not contain the cart items in plain text; it is a reference code, while the actual cart contents are stored server-side.
The data is sent to Shopify's infrastructure (the store's domain and, technically, the Shopify servers processing orders), not to marketing or analytics third parties. The exact value format may vary and is not publicly documented in detail.
What it is used for
The purpose of the "cart" cookie is purely functional: it lets products added to the cart stay there while the visitor browses other pages, refreshes the browser, or returns to the site a few days later, without having to start over. Without this cookie, the core function of an online store — the shopping cart — could not work correctly.
For the store owner, the cookie is essential to the sales process, supporting the flow from adding a product to completing checkout.
Does it require consent?
Under CookieFix's classification, "cart" is a strictly necessary cookie. Under Article 4(5) of Romanian Law 506/2004 (transposing the ePrivacy Directive 2002/58/EC) and ANSPDCP guidance, cookies strictly necessary to provide a service explicitly requested by the user (here, online shopping) do not require prior consent.
The site owner should still list it in the cookie policy, with its purpose and duration, for transparency toward visitors, in line with the GDPR (Regulation 2016/679) information obligations.
How to block or delete cart
A visitor can delete or block the "cart" cookie from their browser's settings (Chrome, Firefox, Safari, Edge, etc.), under cookie and site data management. The immediate effect is that the current shopping cart is emptied and items must be added again.
From the site owner's side, strictly necessary cookies like "cart" should not be blocked before consent, since that would break the store's core function. A CMP such as CookieFix automatically scans the site, identifies this type of cookie, classifies it as necessary and lists it correctly in the cookie policy, while blocking only statistics or marketing scripts until the visitor gives consent.
Frequently asked questions
It's a technical cookie set by the Shopify platform that keeps track of the products a visitor has added to their shopping cart, so the cart isn't emptied while they browse the site.
No. It is classified as strictly necessary because it directly supports a function the user explicitly requested (the shopping cart), so it doesn't need the prior consent required under ePrivacy and Law 506/2004.
Its typical duration is 2 weeks from the last interaction, after which the associated cart expires and must be rebuilt.
The current shopping cart is emptied, and any previously added products need to be added again to complete the order.