Cookies Policy
Draft v1 — Last updated 2026-05-28. Pending counsel review.
StoreWiz is operated by its parent company, currently in formation. The operating entity, jurisdiction of incorporation, and governing-law clauses will be finalized prior to general availability. For current corporate status, contact
legal@storewiz.ai.
This Cookies Policy explains how StoreWiz uses cookies and similar technologies when you visit our marketing website and use the StoreWiz platform. It supplements our Privacy Policy — defined terms used here have the meaning given in the Privacy Policy.
In some jurisdictions (notably the EEA, the UK, Switzerland, Brazil, and parts of California) non-strictly-necessary cookies require your consent. We ask for consent via a banner the first time you visit; you can change your preferences at any time (see §7).
Section status (2026-05-28): The cookie banner is live as of M0.S2b for visitors detected in the EEA, the UK, and Switzerland. Granular per-category controls ("Customize") and the persistent footer "Cookie preferences" widget ship with Module M2 alongside the authenticated Admin Console; until then, the banner offers Accept all or Reject all only, and you can change your choice by clearing the
sw-consentcookie in your browser.
1. What are cookies?
A cookie is a small text file placed on your device when you visit a website. Cookies are widely used to make websites work efficiently and to provide reporting information.
This policy also covers similar technologies: local storage, session storage, IndexedDB, web beacons, pixel tags, fingerprinting signals, and SDKs that perform analogous functions. When we say "cookies" in this policy, we mean cookies and these similar technologies.
Cookies set by storewiz.ai or a StoreWiz-controlled domain are first-party cookies. Cookies set by other domains (including some sub-processors) are third-party cookies.
2. The four categories of cookies we use
We classify our cookies into four standard categories. Only Strictly Necessary cookies are set without your consent in jurisdictions that require consent for non-necessary cookies.
| Category | What it does | Consent required (EEA/UK/CH/BR) |
|---|---|---|
| Strictly Necessary | Essential for the site/app to function — authentication, session management, security (CSRF), load balancing, cookie-consent state itself | No (notice only) |
| Preferences | Remember your choices — language, region, theme, dismissed banners | Yes |
| Analytics | Help us understand how the site/app is used so we can improve it | Yes |
| Marketing | Used on our marketing site only (not in the paid product). Limited to first-party analytics and email-attribution; we do not use third-party advertising/retargeting cookies on our marketing site | Yes |
We do not use third-party retargeting or behavioral-advertising cookies on our own marketing site, and we do not sell or share Personal Data for cross-context behavioral advertising (see Privacy Policy §7.5).
3. The cookies we set (current list)
The lists below describe the cookies we set today. We update this list when cookies are added, changed, or removed.
3.1 Strictly Necessary
| Name | Set by | Purpose | Duration | Type |
|---|---|---|---|---|
__storewiz_session |
StoreWiz (via Clerk from Module M2) | Authenticates your logged-in session | Session or up to 30 days for "Remember me" | First-party HTTP cookie |
__storewiz_csrf |
StoreWiz | Prevents Cross-Site Request Forgery | Session | First-party HTTP cookie |
sw-consent |
StoreWiz | Records your cookie-consent preferences (value: accepted or rejected) |
6 months | First-party HTTP cookie (SameSite=Lax, Secure) |
hcaptcha_* |
hCaptcha | Provides bot protection on the Free Audit, sign-up, and login forms | Session to 30 days | Third-party (set by hCaptcha) |
__cf_* / load-balancer cookies |
Vercel | Edge routing and load balancing | Session | First-party HTTP cookie |
3.2 Preferences (available from Module M3)
| Name | Set by | Purpose | Duration | Type |
|---|---|---|---|---|
__storewiz_theme |
StoreWiz | Remembers light/dark theme | 12 months | First-party local storage |
__storewiz_region |
StoreWiz | Remembers your selected data residency region (where applicable) | 12 months | First-party local storage |
__storewiz_dismissed_* |
StoreWiz | Remembers banners/onboarding tips you've dismissed | 12 months | First-party local storage |
3.3 Analytics (available from Module M3; opt-in only)
| Name | Set by | Purpose | Duration | Type |
|---|---|---|---|---|
| First-party analytics cookies | StoreWiz (via Vercel Analytics where applicable) | Counts unique visitors, page views, page-load performance, error rate | Up to 24 months | First-party |
We use server-side, privacy-respecting analytics where feasible, and we strip IP addresses to coarse geolocation. We do not transmit analytics data to third parties for advertising purposes.
3.4 Marketing (marketing site only; opt-in only; M3+)
| Name | Set by | Purpose | Duration | Type |
|---|---|---|---|---|
| Email-attribution cookies | StoreWiz | Attributes a sign-up to a specific email campaign you clicked through from | Up to 90 days | First-party |
| UTM-parameter cookies | StoreWiz | Records the campaign source you arrived from (paid or organic) | Up to 90 days | First-party |
We do not integrate Google Ads remarketing tags, Meta Pixels, TikTok Pixels, or similar cross-context behavioral-advertising trackers on our own marketing site at the time of this policy. If we add any in the future, this policy will be updated and consent re-prompted.
4. Cookies set by our sub-processors
A small number of our sub-processors set cookies in connection with the Services. These are governed by the relevant sub-processor's own cookie policy in addition to ours:
- hCaptcha — sets anti-bot cookies on pages where the CAPTCHA widget appears. See
https://www.hcaptcha.com/privacy. - Vercel — sets edge-routing / load-balancing cookies. See
https://vercel.com/legal/privacy-policy. - Statuspage (on
status.storewiz.ai) — sets functional cookies for the status page. See Atlassian's cookie policy. - Clerk (Module M2+, on authentication pages) — sets session/security cookies. See
https://clerk.com/legal/privacy-policy. - Lemon Squeezy (Module M2+, on checkout pages) — sets payment/session cookies for the checkout flow. See
https://www.lemonsqueezy.com/privacy.
We list these for transparency. None of these vendors place advertising cookies via the StoreWiz Services.
5. Legal basis
For Strictly Necessary cookies, our legal basis is our legitimate interest in providing a secure, functional service (GDPR Art. 6(1)(f)) and, where applicable, performance of contract (Art. 6(1)(b)). These cookies are essential and are set without your consent, but we provide notice.
For Preferences, Analytics, and Marketing cookies, our legal basis is your consent (Art. 6(1)(a) and equivalent provisions in UK GDPR, Swiss FADP, Brazilian LGPD, Quebec Law 25). We obtain consent through the cookie banner before setting any non-strictly-necessary cookie in consent-required jurisdictions (see §6). Today we set only Strictly Necessary cookies on this marketing site; the banner stores your future preference for when Preferences, Analytics, and Marketing cookies begin shipping in later modules (see §3.2–§3.4).
In jurisdictions that do not require pre-consent for analytics (e.g., the United States generally), we still provide a clear opt-out mechanism (see §7).
6. Cookie banner behavior
The first time you visit our marketing site from a consent-required jurisdiction (EEA, UK, Switzerland), you see a cookie banner with the following options:
- Accept all — consent to all categories.
- Reject all — only Strictly Necessary cookies are set.
- Customize — granular per-category consent. Ships with Module M2 alongside the authenticated Admin Console. Until then, you can choose Accept all or Reject all; we will not set Preferences, Analytics, or Marketing cookies on the marketing site in M0/M1 regardless of your choice (see §3.2–§3.4).
Inside the paid product, we will generally not present a marketing-cookie banner because we do not set marketing cookies there. We will present a notice for Preference/Analytics cookies in consent-required jurisdictions when those cookies begin shipping (Module M3).
We treat no choice as rejection of non-strictly-necessary cookies in consent-required jurisdictions (no implied consent).
The banner is intended to respect the Global Privacy Control (GPC) signal: if your browser sends a GPC signal, we will treat it as an opt-out request for Analytics and Marketing cookies. Programmatic GPC handling ships with Module M2; until Analytics and Marketing cookies actually begin shipping (Module M3), the practical effect is the same as having no Analytics/Marketing cookies to opt out of.
We do not use cookie walls (i.e., we will not require you to accept non-strictly-necessary cookies in order to access content).
7. Managing your preferences
You can manage your cookie preferences in several ways:
- From the StoreWiz cookie preferences widget (Ships with Module M2) — a "Cookie preferences" link will be available in the footer of every page on
storewiz.aiand inside the Admin Console. Until then, you can change your choice by clearing thesw-consentcookie in your browser (DevTools → Application → Cookies) to be re-prompted on your next visit from a consent-required jurisdiction. - From your browser — most browsers let you block, delete, or be notified about cookies. The browser help docs explain how. Be aware that blocking Strictly Necessary cookies will break authentication and other essential functions.
- From a Do Not Track / Global Privacy Control signal — your browser may support a privacy signal. We are committed to honoring GPC and will respect it programmatically once Analytics and Marketing cookies begin shipping (Module M3). Today this site sets only Strictly Necessary cookies, so the practical effect is the same as a GPC opt-out (see §6).
- From your operating system / mobile device — mobile devices have privacy controls for advertising IDs; we do not use mobile advertising IDs.
Withdrawing consent has no retroactive effect on processing that already occurred but stops further processing under that consent.
8. Tracking technologies we do not use
For clarity:
- We do not use third-party advertising cookies on our marketing site.
- We do not use cross-site tracking pixels for advertising (no Meta Pixel, no Google Ads remarketing tag, no TikTok Pixel) at the time of this policy.
- We do not use device fingerprinting for advertising. hCaptcha collects minimal anti-bot signals on public forms — this is a security function, not an advertising function.
- We do not sell or share Personal Data collected through cookies for cross-context behavioral advertising (see Privacy Policy §7.5).
If we add any of the above in the future, this policy will be updated, consent re-prompted in consent-required jurisdictions, and we will publish a 30-day advance notice.
9. Children
Our marketing site and the paid product are not directed to children under 16 (or under 13 in the United States under COPPA). We do not knowingly set cookies on the devices of children outside legitimate B2B contexts.
10. International data transfers via cookies
Where cookies cause Personal Data to be transferred outside your country of residence (e.g., a US-based sub-processor reads a cookie set in the EEA), the transfer is covered by the mechanisms described in Privacy Policy §9 (SCCs, UK IDTA, FADP supplement, TIAs).
11. Changes to this Cookies Policy
We may update this Cookies Policy from time to time. The "Last updated" date at the top of this page reflects the most recent change. For material changes (e.g., adding a new tracking technology), we will:
- Re-prompt for consent in consent-required jurisdictions where consent is required for the new technology;
- Post a clear notice on our marketing site and in the Admin Console at least 30 days before the change takes effect.
Previous versions are archived at storewiz.ai/legal/archive.
12. Governing law
[TODO[entity-pending]: This Cookies Policy is governed by the laws of [JURISDICTION TBD]; disputes resolved in [VENUE TBD], subject to mandatory consumer-protection and data-protection law of your country of residence.]
Contact. Privacy: privacy@storewiz.ai. DPO matters: dpo@storewiz.ai. Legal: legal@storewiz.ai.