Features Pricing GDPR cookie banner Google Consent Mode v2 WordPress plugin Cookiebot alternative For Agencies GDPR ePrivacy About Contact
RO | EN
Start Free →
Necessary

cart_sig Cookie (Shopify) – What It Is and Why It's Used

cart_sig is a technical cookie set by the Shopify platform to validate the integrity of a visitor's shopping cart. It is strictly necessary for the online store to function correctly and does not require visitor consent.

Name
cart_sig
Provider
Shopify
Category
Necessary
Type
HTTP cookie
Lifetime
2 weeks
Consent
No, but it must be listed in the cookie policy

What is the cart_sig cookie?

cart_sig is an HTTP cookie automatically set by the Shopify e-commerce platform on any online store built on this infrastructure. It appears as soon as a visitor adds a product to the cart or interacts with the site's shopping functionality.

It is generated and managed exclusively by Shopify, as part of its checkout and cart management system, not directly by the site owner.

What data it stores

The cookie stores a signature (a cryptographic string) used by Shopify to verify the integrity and authenticity of the shopping cart data associated with the visitor, preventing unauthorized tampering with it.

The exact value varies and is generated internally by Shopify's systems; it does not contain human-readable information. The data is sent to Shopify's servers with every cart interaction (adding a product, updating quantity, checkout).

What it is used for

Its main purpose is security and proper functioning of the shopping cart: Shopify uses this signature to make sure cart data hasn't been altered between request and response.

For the store owner, this cookie is indispensable — without it, the add-to-cart function and checkout process would not work correctly, which would block sales.

Does it require consent?

Under CookieFix's classification, cart_sig is a strictly necessary cookie. Since it is essential for the basic operation of an online store (the shopping cart), it falls under the exception provided in Article 5(3) of the ePrivacy Directive (implemented in Romania via Law 506/2004), which does not require prior consent for cookies without which the service requested by the user cannot be provided.

Even though it doesn't require consent, the site owner must still list it in the cookie policy, including its purpose and duration, in line with GDPR transparency obligations.

How to block or delete cart_sig

A visitor can delete or block this cookie via browser settings (Chrome, Firefox, Safari, Edge — the site data/cookie management section), though this may make the shopping cart unusable on Shopify stores.

  • Site owners cannot and should not block this cookie via the consent banner, since it is essential for cart functionality.
  • A CMP such as CookieFix can automatically block, until consent is given, only statistics and marketing scripts (e.g. Google Analytics, Meta Pixel), leaving strictly necessary cookies like cart_sig unaffected.

Frequently asked questions

No. It is classified as strictly necessary because it ensures the basic functioning of the shopping cart, so it is exempt from the consent requirement under ePrivacy and Romanian Law 506/2004.

The Shopify store's shopping cart may stop working correctly, or products added to it may not be retained across pages.

It is set automatically by the Shopify platform on any online store built on that infrastructure, not directly by the site owner.

Yes, even though it doesn't require consent, GDPR transparency rules require the site owner to list it in the cookie policy, along with its purpose and duration.

Updated 7 September 2026 · Information comes from the provider’s public documentation and CookieFix scans; it is not legal advice.