Cookie Policy
Cookie Policy
Last updated: 18 August 2026
1. About this policy
This policy explains how Something & Nothing uses cookies and similar technologies on somethingandnothing.co. It should be read with our Privacy Policy.
A cookie is a small text file stored on a device. Similar technologies include pixels, tags, scripts, local storage and identifiers that store information or access information already stored on a device.
2. Cookie categories
Strictly necessary: needed for core functions such as security, checkout, baskets, payments, privacy choices and account sessions. These cannot generally be switched off through our consent tool.
Functionality: remember choices or enable optional services such as customer-support messaging.
Analytics or performance: help us understand use of the store, diagnose problems and measure performance.
Advertising or targeting: help measure campaigns, build audiences or personalise advertising.
We ask for consent before using non-essential technologies unless a specific legal exception applies. Rejecting non-essential technologies should not prevent normal shopping and checkout, although optional features may work differently.
3. Technologies currently identified
Our Pandectes scan on 18 August 2026 identified the following principal cookies or cookie families. Providers can change names or lifetimes, so the cookie settings panel on the website should be treated as the most current operational list.
|
Cookie or family |
Provider |
Category |
Main purpose |
Typical lifetime observed |
|
localization; cart_currency |
Shopify |
Strictly necessary |
Region, language and currency choices |
2 weeks to 1 year |
|
cart; discount_code |
Shopify |
Strictly necessary |
Basket and discount functions |
Session to 3 months |
|
shop_app_essential; merchant_essential; _shopify_essential and related essential identifiers |
Shopify |
Strictly necessary |
Store, checkout, account and merchant services |
Session to 1 year |
|
storefront_digest; login_with_shop_finalize |
Shopify |
Strictly necessary |
Store access and login completion |
5 minutes to 1 year |
|
shopify_pay |
Shopify |
Strictly necessary |
Shop Pay and checkout functions |
Up to 1 year |
|
_identity_session and related identity-session cookies |
Shopify |
Strictly necessary |
Customer identity and account session |
Session to 2 years |
|
_secure_admin_session_id and CSRF variant |
Shopify |
Strictly necessary |
Security and session protection |
Up to 12 weeks |
|
privacy_signal; _tracking_consent |
Shopify |
Strictly necessary |
Record privacy and consent choices |
Up to 1 year |
|
_shopify_y; _shopify_s; _shopify_analytics; shop_analytics; merchant_analytics |
Shopify |
Analytics/performance |
Store and merchant analytics |
30 minutes to 1 year |
|
orig_referrer; _landing_page |
Shopify |
Analytics/performance |
Attribution and landing-page measurement |
Up to 2 weeks |
|
_shopify_marketing |
Shopify |
Advertising/targeting |
Marketing attribution or personalisation |
Up to 1 year |
|
_ga; _ga_* |
|
Analytics/performance |
Google Analytics measurement |
Up to 1 year |
|
_gcl_* |
|
Advertising measurement |
Campaign and conversion measurement |
Up to 3 months |
|
NID |
|
Advertising/targeting |
Google preferences, security and advertising functions |
Up to 6 months |
|
_fbp |
Meta/Facebook |
Advertising/targeting |
Advertising measurement and audience functions |
Up to 3 months |
|
intercom-id-; intercom-device-id- |
Intercom |
Functionality |
Customer-support service and device recognition |
Up to 9 months |
|
intercom-session-* |
Intercom |
Functionality |
Maintain a support session |
Up to 1 week |
|
__cf_bm |
Cloudflare |
Security/performance |
Bot management and protection |
About 30 minutes |
|
_pandectes_gdpr |
Pandectes |
Strictly necessary |
Store your privacy choices |
Up to 1 year |
The scan also detected services or scripts associated with Shopify, Google/Google Pay, Meta/Facebook, Mailchimp, Intercom, Cloudflare, Amazon CloudFront, Unpkg and Bold Commerce. A script does not always set a cookie, and some services activate only when a feature is used or consent is given.
4. Consent and changing your choices
When you first visit, our cookie banner should let you:
accept all non-essential categories;
reject all non-essential categories; or
choose categories individually.
You can change or withdraw your choice at any time using the Cookie settings link or icon on the website. Essential technologies remain active because the store cannot operate securely without them.
Where supported, we communicate your choice to Google, Meta, Shopify and other connected services through consent signals. Browser settings can also delete or block cookies, but doing so may affect checkout, account or preference functions.
5. Third-party services
Some technologies are supplied by third parties that may receive device, usage or transaction-event data. Their privacy materials provide more detail:
Shopify: shopify.com/legal/privacy
Google: policies.google.com/privacy
Meta: facebook.com/privacy/policy
Mailchimp: intuit.com/privacy/statement
Intercom: intercom.com/legal/privacy
Pandectes: pandectes.io/privacy-policy
6. Updates and contact
We review this policy and our scan when technologies change. For questions, email george@somethingnothing.co.