What is the cart_sig cookie?
cart_sig is an HTTP cookie automatically set by the Shopify e-commerce platform on any online store built on this infrastructure. It appears as soon as a visitor adds a product to the cart or interacts with the site's shopping functionality.
It is generated and managed exclusively by Shopify, as part of its checkout and cart management system, not directly by the site owner.
What data it stores
The cookie stores a signature (a cryptographic string) used by Shopify to verify the integrity and authenticity of the shopping cart data associated with the visitor, preventing unauthorized tampering with it.
The exact value varies and is generated internally by Shopify's systems; it does not contain human-readable information. The data is sent to Shopify's servers with every cart interaction (adding a product, updating quantity, checkout).
What it is used for
Its main purpose is security and proper functioning of the shopping cart: Shopify uses this signature to make sure cart data hasn't been altered between request and response.
For the store owner, this cookie is indispensable — without it, the add-to-cart function and checkout process would not work correctly, which would block sales.
Does it require consent?
Under CookieFix's classification, cart_sig is a strictly necessary cookie. Since it is essential for the basic operation of an online store (the shopping cart), it falls under the exception provided in Article 5(3) of the ePrivacy Directive (implemented in Romania via Law 506/2004), which does not require prior consent for cookies without which the service requested by the user cannot be provided.
Even though it doesn't require consent, the site owner must still list it in the cookie policy, including its purpose and duration, in line with GDPR transparency obligations.
How to block or delete cart_sig
A visitor can delete or block this cookie via browser settings (Chrome, Firefox, Safari, Edge — the site data/cookie management section), though this may make the shopping cart unusable on Shopify stores.
- Site owners cannot and should not block this cookie via the consent banner, since it is essential for cart functionality.
- A CMP such as CookieFix can automatically block, until consent is given, only statistics and marketing scripts (e.g. Google Analytics, Meta Pixel), leaving strictly necessary cookies like
cart_sigunaffected.
Frequently asked questions
No. It is classified as strictly necessary because it ensures the basic functioning of the shopping cart, so it is exempt from the consent requirement under ePrivacy and Romanian Law 506/2004.
The Shopify store's shopping cart may stop working correctly, or products added to it may not be retained across pages.
It is set automatically by the Shopify platform on any online store built on that infrastructure, not directly by the site owner.
Yes, even though it doesn't require consent, GDPR transparency rules require the site owner to list it in the cookie policy, along with its purpose and duration.