Legal

Cookie policy

Effective 11 August 2026. ShopMCP uses a deliberately short list of cookies and similar storage mechanisms. This page names each one and explains why we set it.

Consent-gated product analytics

Google Analytics loads only after you choose "Accept analytics". We send sanitized page paths and a small set of product-funnel events; we disable Google Signals and advertising personalization, and never send connected-store data or email-bearing URLs. LinkedIn campaign attribution uses first-party storage and server-side conversion events when configured. Server-side request logs are retained for operational purposes only — see the privacy policy for the full list.

The cookies we set

NamePurposeCategoryRetention
better-auth.session_tokenSigns a logged-in session. Without it, the dashboard cannot remember who you are between requests.Strictly necessarySession, renewed for up to 30 days
better-auth.csrf_tokenCross-site request forgery defence. Pairs with the session cookie so we can reject requests that did not originate from the dashboard.Strictly necessarySession
shopmcp_analytics_consentRecords whether you accepted or declined optional analytics so we can honour that choice across ShopMCP subdomains.Strictly necessary365 days
_ga / _ga_<container-id>Google Analytics pseudonymous browser and session identifiers. Set only after you accept analytics; never used to send connected-store data or email-bearing URLs.AnalyticsUp to 2 years
shopmcp:ga4:*First-party local storage used after consent to prevent duplicate onboarding, integration, first-result, trial, and purchase events. Events waiting for your choice are held only in page memory, not browser storage.Analytics30 to 400 days
shopmcp.active_workspaceRemembers which workspace you last selected when your account belongs to more than one. Purely a convenience — the active workspace is still authenticated server-side on every request.Functional30 days
shopmcp.themeRemembers the dashboard's light / dark / system preference across visits.Functional365 days
shopmcp_li_fat_idStores LinkedIn's first-party ads click id when a LinkedIn campaign sends you to ShopMCP, so server-side conversion events can be attributed to the campaign.Analytics90 days
shopmcp:linkedin-capi:website-visit:*Session storage key that deduplicates the LinkedIn website-visit conversion event within the same browser session.AnalyticsSession
Smallchat / Firebase storagePowers the support chat bubble and keeps the chat conversation available while visitors use the app.FunctionalControlled by Smallchat and Firebase
__stripe_mid / __stripe_sidSet by Stripe on the billing and checkout pages for fraud prevention. Only present while you are on a Stripe-rendered page; we do not set them ourselves.Strictly necessary__stripe_mid 365 days, __stripe_sid 30 min

How to refuse non-essential cookies

Strictly necessary cookies cannot be refused without breaking the service — you cannot sign in without a session cookie. Functional cookies can be declined by clearing them in your browser at any time; the dashboard will fall back to defaults (the first workspace in alphabetical order, system-default theme) on the next visit.

Choose "Only necessary" in the consent banner to prevent Google Analytics from loading, or change your choice below at any time. If you withdraw consent, ShopMCP disables analytics and deletes its first-party Google Analytics cookies from this browser.

Analytics preference: not selected.

Third parties

The third-party cookies or browser storage you may encounter while using ShopMCP are set by Smallchat for support chat and by Stripe on pages that render Stripe's billing or checkout elements. If you accept analytics, Google Analytics also sets the pseudonymous cookies listed above. See Smallchat's privacy policy, Stripe's privacy policy, and Google's privacy policy.

Changes to this policy

If we add a cookie we will update the table in the same release and, where consent is required, show a banner asking for it before the cookie is set. Material changes will be emailed to workspace owners.

Questions

Email privacy@shop-mcp.app if anything on this page is unclear.