Butter Commerce
Cookie Notice
Effective: 14 August 2026
Last updated: 14 August 2026
This notice covers two different things, and they have different audiences.
Part 1 is about buttercommerce.co — our own site.
Part 2 is about what Butter's components store in a shopper's browser on a storefront you built. If you use Butter, read Part 2: you need to disclose this in your own privacy policy, and in some countries you need consent before it runs.
What we use
Purpose | What it does | Duration |
|---|---|---|
Strictly necessary | Keeps you signed in, maintains your session, protects against cross-site request forgery, routes you to the right infrastructure. The site cannot work without these. | Session, or up to 12 months |
Preferences | Remembers choices like light or dark theme. | Up to 12 months |
Analytics | Tells us which pages get read and where people drop off, so we can improve the docs and the site. | Up to 24 months |
What we run: Framer Analytics, which is cookieless — it sets no identifier and needs no consent. And Google Analytics 4, which sets _ga and _ga_, persisting for up to 24 months. Google Analytics is consent-gated and will not run before you answer the banner.
We expect to add the Meta Pixel for advertising measurement. It is consent-gated on the same basis.
We do not run advertising or cross-site tracking cookies on our own site.
Your choices
Every browser lets you block or delete cookies. Blocking strictly necessary ones will break sign-in.
Where the law requires consent for non-essential cookies — the EU, the UK, and elsewhere — we ask before setting them, and you can change your answer at any time from the cookie preferences link in our site footer. Our banner is provided by Framer.
If you build a storefront with Butter, our components store data in your shoppers' browsers. Most of it is functional — a cart that survives a page reload — but some of it is tracking, and that distinction is what determines your obligations.
Cookies
Name pattern | Purpose | Duration |
|---|---|---|
| Remembers the campaign a shopper arrived from, so a later purchase is credited to it | 30 days |
| Affiliate attribution for the SCA / Shop-Circle platform | 30 days |
| Generic affiliate referral codes, including BixGrow | 30 days |
| Ad-platform click identifiers, for reconciling Google, Meta, TikTok, Microsoft, Yandex, and Pinterest campaigns | 30 days |
These are set with the secure flag on HTTPS.
These are tracking cookies, not functional ones. In the EU and the UK they require consent before being set.
Local storage and session storage
Not cookies, but the same legal treatment in the EU and UK, and they need the same disclosure.
Key | Purpose |
|---|---|
| The shopper's Shopify cart identifier, so the cart persists across pages and visits |
| Selected market, country, and currency |
| Cart preview state |
| A discount code applied by a Recipe, held until checkout |
| Products the shopper has favourited |
| Products recently viewed, for the recently-viewed carousel |
| Timestamp of the previous visit, used by cart-abandonment and returning-visitor Recipes |
| Recipe evaluation state and cross-sell context |
| Per-store quantity limits |
Cart, market, and favourites storage is functional — the storefront cannot work correctly without it. Recently viewed, last visit, and Recipe state are closer to analytics, and a strict consent regime may treat them as non-essential.
Third parties, if you enable them
If you configure any of these in Butter, they set their own cookies and identifiers under their own policies, as your providers:
Google Analytics 4 · Meta Pixel · Klaviyo · Judge.me · Yotpo · Loox
Third parties your shoppers' browsers contact regardless
These don't set Butter cookies, but they do receive an IP address, user agent, and referring page because the browser requests something from them as the page loads:
Service | Why |
|---|---|
esm.sh | Butter's storefront components load their JavaScript dependencies from this module CDN at page load |
Iconify ( | Country flag icons, on stores using Markets |
Framer ( | Relays Yotpo and Judge.me API calls through Framer's CORS proxy |
Butter's location endpoint, falling back to freeipapi.com | Determines the shopper's country for Markets and currency |
How consent works
Butter passes consent through to Shopify. If your storefront has a cookie banner, Butter syncs the shopper's choices — sale of data, analytics, marketing, preferences — to Shopify's Customer Privacy API, so consent is respected consistently across your store rather than only by the banner that captured it.
Butter does not ship the banner itself, and we do not obtain consent on your behalf. Two things follow from that, and the second one matters:
If no consent manager is present on the page, Butter's components currently default to allowing tracking. That mirrors Framer's own behaviour, and it is the right default for a store with no EU exposure. It is the wrong default if you have EU or UK shoppers and no banner.
This is becoming a setting you control. We are adding a consent setting in your store settings: new stores will default to requiring consent, existing stores will keep current behaviour so nothing breaks silently, and we will warn you if you have an EEA or UK market enabled with the setting off.
If your storefront reaches shoppers in the EU, the UK, Brazil, or anywhere else with a prior-consent rule, you are responsible for:
Running a consent manager so the attribution cookies and any analytics or advertising pixels wait for permission. Butter will honour what it captures.
Disclosing this in your own storefront privacy policy. You are welcome to copy the tables above.
Honouring withdrawal — letting shoppers change their mind, and stopping the tracking when they do.
We will keep this notice current so you have something accurate to point at.
Changes
We will update this notice as the Product changes and revise the date at the top. Material changes are notified as described in the Privacy Policy.
Contact
privacy@buttercommerce.co