Butter Commerce

Cookie Notice

Effective: 14 August 2026

Last updated: 14 August 2026

This notice covers two different things, and they have different audiences.

Part 1 is about buttercommerce.co — our own site.

Part 2 is about what Butter's components store in a shopper's browser on a storefront you built. If you use Butter, read Part 2: you need to disclose this in your own privacy policy, and in some countries you need consent before it runs.

What we use

Purpose

What it does

Duration

Strictly necessary

Keeps you signed in, maintains your session, protects against cross-site request forgery, routes you to the right infrastructure. The site cannot work without these.

Session, or up to 12 months

Preferences

Remembers choices like light or dark theme.

Up to 12 months

Analytics

Tells us which pages get read and where people drop off, so we can improve the docs and the site.

Up to 24 months

What we run: Framer Analytics, which is cookieless — it sets no identifier and needs no consent. And Google Analytics 4, which sets _ga and _ga_, persisting for up to 24 months. Google Analytics is consent-gated and will not run before you answer the banner.

We expect to add the Meta Pixel for advertising measurement. It is consent-gated on the same basis.

We do not run advertising or cross-site tracking cookies on our own site.

Your choices

Every browser lets you block or delete cookies. Blocking strictly necessary ones will break sign-in.

Where the law requires consent for non-essential cookies — the EU, the UK, and elsewhere — we ask before setting them, and you can change your answer at any time from the cookie preferences link in our site footer. Our banner is provided by Framer.

If you build a storefront with Butter, our components store data in your shoppers' browsers. Most of it is functional — a cart that survives a page reload — but some of it is tracking, and that distinction is what determines your obligations.

Cookies

Name pattern

Purpose

Duration

utm_source, utm_medium, utm_campaign, utm_term, utm_content

Remembers the campaign a shopper arrived from, so a later purchase is credited to it

30 days

sca_ref, sca_source, sca_medium, sca_campaign, sca_term, sca_content

Affiliate attribution for the SCA / Shop-Circle platform

30 days

bg_ref, ref, aff, affiliate, aff_id

Generic affiliate referral codes, including BixGrow

30 days

gclid, gbraid, wbraid, fbclid, ttclid, msclkid, yclid, epik

Ad-platform click identifiers, for reconciling Google, Meta, TikTok, Microsoft, Yandex, and Pinterest campaigns

30 days

These are set with the secure flag on HTTPS.

These are tracking cookies, not functional ones. In the EU and the UK they require consent before being set.

Local storage and session storage

Not cookies, but the same legal treatment in the EU and UK, and they need the same disclosure.

Key

Purpose

butter_cart_id (per store)

The shopper's Shopify cart identifier, so the cart persists across pages and visits

butter_active_market (legacy: fc_active_market)

Selected market, country, and currency

butter_preview_cart (legacy: fc_preview_cart)

Cart preview state

butter_discount_code

A discount code applied by a Recipe, held until checkout

favorites

Products the shopper has favourited

recently_viewed

Products recently viewed, for the recently-viewed carousel

lastVisit

Timestamp of the previous visit, used by cart-abandonment and returning-visitor Recipes

_fc_active_recipes, _fc_price_override, _fc_cart_cross_sell

Recipe evaluation state and cross-sell context

butter_merchant_max_by_key (legacy: fc_merchant_max_by_key)

Per-store quantity limits

Cart, market, and favourites storage is functional — the storefront cannot work correctly without it. Recently viewed, last visit, and Recipe state are closer to analytics, and a strict consent regime may treat them as non-essential.

Third parties, if you enable them

If you configure any of these in Butter, they set their own cookies and identifiers under their own policies, as your providers:

Google Analytics 4 · Meta Pixel · Klaviyo · Judge.me · Yotpo · Loox

Third parties your shoppers' browsers contact regardless

These don't set Butter cookies, but they do receive an IP address, user agent, and referring page because the browser requests something from them as the page loads:

Service

Why

esm.sh

Butter's storefront components load their JavaScript dependencies from this module CDN at page load

Iconify (api.iconify.design)

Country flag icons, on stores using Markets

Framer (framer-team.workers.dev)

Relays Yotpo and Judge.me API calls through Framer's CORS proxy

Butter's location endpoint, falling back to freeipapi.com

Determines the shopper's country for Markets and currency

How consent works

Butter passes consent through to Shopify. If your storefront has a cookie banner, Butter syncs the shopper's choices — sale of data, analytics, marketing, preferences — to Shopify's Customer Privacy API, so consent is respected consistently across your store rather than only by the banner that captured it.

Butter does not ship the banner itself, and we do not obtain consent on your behalf. Two things follow from that, and the second one matters:

If no consent manager is present on the page, Butter's components currently default to allowing tracking. That mirrors Framer's own behaviour, and it is the right default for a store with no EU exposure. It is the wrong default if you have EU or UK shoppers and no banner.


This is becoming a setting you control. We are adding a consent setting in your store settings: new stores will default to requiring consent, existing stores will keep current behaviour so nothing breaks silently, and we will warn you if you have an EEA or UK market enabled with the setting off.

If your storefront reaches shoppers in the EU, the UK, Brazil, or anywhere else with a prior-consent rule, you are responsible for:

  1. Running a consent manager so the attribution cookies and any analytics or advertising pixels wait for permission. Butter will honour what it captures.

  2. Disclosing this in your own storefront privacy policy. You are welcome to copy the tables above.

  3. Honouring withdrawal — letting shoppers change their mind, and stopping the tracking when they do.

We will keep this notice current so you have something accurate to point at.

Changes

We will update this notice as the Product changes and revise the date at the top. Material changes are notified as described in the Privacy Policy.

Contact

privacy@buttercommerce.co