Cookies and browser storage
Your privacy policy and your consent banner have to name the cookies your storefront sets, and the same consent rules apply to anything else it stores in the browser, such as localStorage. Some of them come from code you wrote; others come from Laioutr: Frontend Core, the connector apps you installed, and the Studio preview. This page lists the second group so you can copy it into your cookie declaration or your CMP's cookie scanner results.
You operate the storefront, so you are the controller and decide how each cookie is classified and disclosed. Laioutr acts as your processor (see Data Protection). The URL of this page is stable, so you can link to it from your records.
How to read the tables
Every cookie on this page is first-party: your storefront's own server or its client code writes it on your storefront's domain. Laioutr sets no cookies from a Laioutr domain.
The Gated on column names the consent purpose Laioutr checks before writing the cookie. "Not gated" means the code sets the cookie whenever the feature runs, without asking the consent store. Most of these are cart and login cookies that a visitor needs for a service they requested; whether you classify them as strictly necessary is your decision.
Two attributes follow platform rules rather than per-cookie choices:
Secureis set whenever the storefront runs on HTTPS (or on a loopback host such aslocalhost). You don't configure it.- Inside the Studio preview, every cookie on this page is rewritten to
SameSite=None; Secure; Partitioned.
Frontend Core
These cookies come from @laioutr-core/frontend-core, which every Laioutr storefront includes. The analytics cookies are written only after the visitor grants the purpose, and are deleted when the visitor revokes it.
| Cookie | Purpose | Gated on | Lifetime |
|---|---|---|---|
laioutr_vid | Random visitor ID. Recognizes a returning visitor across visits. | analytics | 393 days (13 months), not extended by activity |
laioutr_sid | Random session ID plus its start and last-activity times. Groups events into one visit. | analytics | 30 minutes of inactivity, at most 24 hours from the start of the visit |
laioutr_camp | The utm_* parameters of the landing URL that brought the visitor. | analytics | 90 days from capture (configurable) |
laioutr_clid | Ad click IDs from the landing URL, such as gclid, msclkid and fbclid. | advertising | 90 days from capture (configurable) |
laioutr_entry | Landing page and external referrer of the visit that started the current attribution. | analytics | 90 days from capture (configurable) |
__Host-laioutr-embed | Marks a request as coming from the Studio preview frame in Cockpit. | Not gated | Session |
laioutr_vid and laioutr_sid carry the identity described in Tracking. The three campaign cookies are explained in Campaign attribution, including how to shorten the 90-day window or narrow the captured parameters with config.campaign in the laioutrrc.
Attributes
| Cookie | Set by | HttpOnly | SameSite | Domain |
|---|---|---|---|---|
laioutr_vid, laioutr_sid, laioutr_camp, laioutr_clid, laioutr_entry | Client | No | Lax | Registrable domain of the market's host |
__Host-laioutr-embed | Server | Yes | None (with Partitioned) | Host-only |
The analytics cookies are scoped to the registrable domain, so shop.example.com writes them for example.com and a visitor keeps one identity across your subdomains. On a hostname Laioutr provisions (*.app.laioutr.tech, *.local.laioutr.tech), on an IP address and on localhost, they are host-only instead.
__Host-laioutr-embed only exists inside the Studio preview frame. A visitor opening your shop directly never receives it.
The i18n_redirected language cookie
Frontend Core uses @nuxtjs/i18n for translations. That module can detect the browser language and remember the result in a cookie named i18n_redirected. Frontend Core sets detectBrowserLanguage: false and resolves the language from the market's domain instead, so by default the cookie is not written.
When it is written, i18n_redirected stores the detected language code, lives for 365 days, and uses SameSite=Lax and Path=/. It is not HttpOnly, and no consent purpose gates it. With the module's default redirectOn: 'root' it is set when a visitor opens the start page or switches the language, so a scan that never does either may not find it.
Your project's i18n options in nuxt.config.ts take precedence over Frontend Core's. A project that sets i18n.detectBrowserLanguage to an options object turns the cookie back on. If your storefront writes i18n_redirected, check that option.
What Frontend Core does not store in cookies
Laioutr keeps no market, language or currency cookie. The consent store keeps no cookie of its own; it reads the decision your CMP stored. The content preview token travels as a query parameter.
Connector apps
A connector app sets cookies only when it is installed and the feature runs. The cookies below are written by the storefront's server, not by client-side scripts. The Shopify, Adobe Commerce, Shopware, commercetools, OXID, Sylius and Nimstrata cookies are HttpOnly, so client-side scripts cannot read them either.
Shopify
From @laioutr-app/shopify. All cookies use SameSite=Lax and Path=/.
| Cookie | Purpose | Gated on | Lifetime |
|---|---|---|---|
shopify-cart-id | ID of the visitor's Shopify cart. Set on the first add-to-cart. | Not gated | 30 days |
shopify-access-token | Customer Account API access token after login. | Not gated | The token's lifetime as returned by Shopify |
shopify-refresh-token | Refreshes the access token without a new login. | Not gated | 30 days |
shopify-id-token | OpenID Connect ID token, used to end the session at logout. | Not gated | The token's lifetime as returned by Shopify |
shopify-oauth-state | CSRF protection for the login redirect. | Not gated | 10 minutes |
shopify-oauth-nonce | Replay protection for the login redirect. | Not gated | 10 minutes |
shopify-oauth-redirect-uri | The callback URL used for the login, reused in the token exchange. | Not gated | 10 minutes |
shopify-oauth-return-to | The page to return the shopper to after login. | Not gated | 10 minutes |
The four shopify-oauth-* cookies exist only while a login is in progress and are deleted when the callback completes. The access, refresh and ID tokens are deleted at logout.
The app does not set Shopify's own _shopify_y or _shopify_s cookies. Shopify analytics events reuse the Frontend Core visitor and session IDs instead.
Adobe Commerce
From @laioutr-app/adobe-commerce.
| Cookie | Purpose | Gated on | Lifetime | SameSite |
|---|---|---|---|---|
cart-id | Masked ID of the visitor's Adobe Commerce cart. Set on the first add-to-cart. | Not gated | 30 days | Strict |
Shopware
From @laioutr-app/shopware.
| Cookie | Purpose | Gated on | Lifetime | SameSite |
|---|---|---|---|---|
sw-context-token | Shopware Store API context token, which identifies the cart and the logged-in customer. | Not gated | 1 year | Lax |
The cookie is written whenever Shopware returns a new token, for example after login or a cart change. A project that supplies the token from its own session store through the shopware:context-token:resolve hook uses this cookie only as a fallback.
commercetools
From @laioutr-app/commercetools. Both cookies use SameSite=Strict.
| Cookie | Purpose | Gated on |
|---|---|---|
ctp-anon-token | Access token of the visitor's anonymous commercetools session, used for the cart. | Not gated |
ctp-anon-refresh-token | Refreshes the anonymous session's access token. | Not gated |
Emporix
From @laioutr-app/emporix.
| Cookie | Purpose | Gated on |
|---|---|---|
accessToken | Emporix session token, anonymous or logged in. Set on the first request through an anonymous login. | Not gated |
OXID
From @laioutr-app/oxid.
| Cookie | Purpose | Gated on | Lifetime | SameSite |
|---|---|---|---|---|
oxid-basket-id | ID of the visitor's OXID basket. Set on the first request without one. | Not gated | 30 days | None |
Sylius
From @laioutr-app/sylius.
| Cookie | Purpose | Gated on | Lifetime | SameSite |
|---|---|---|---|---|
sylius-cart-token | Token of the visitor's Sylius cart. Set when the cart is created. | Not gated | 30 days | Lax |
Nimstrata
From @laioutr-app/nimstrata.
| Cookie | Purpose | Gated on | Lifetime | SameSite |
|---|---|---|---|---|
nimstrata-visitor-id | Random visitor ID (UUID v4) sent to Nimstrata for search personalization, recommendations and event attribution. | Not gated | 1 year | Lax |
Browser storage
Some Laioutr packages keep values in the browser's localStorage or Cache Storage instead of a cookie. These entries are never sent to the server. They stay until the visitor clears site data or the code removes them.
| Key | Set by | Purpose | Gated on | When it is written |
|---|---|---|---|---|
nuxt-color-mode (localStorage) | @laioutr-core/ui-kit through @nuxtjs/color-mode | The color scheme preference, light by default. | Not gated | On every page load |
isAnnualBilling (localStorage) | @laioutr-core/ui, in the Plan Card and Plan Card Slider sections | Whether the visitor switched pricing to annual billing. | Not gated | When a page with one of these sections renders |
vite-pwa:hide-install (localStorage) | @laioutr-app/pwa | Hides the "install app" prompt after the visitor dismissed it. | Not gated | When the visitor dismisses the prompt |
| Service worker precache (Cache Storage) | @laioutr-app/pwa | Copies of the storefront's scripts, styles, HTML and images so it loads offline. Holds no visitor data. | Not gated | When the service worker installs |
nuxt-color-mode is written even on storefronts that offer no theme switch, because the color-mode module stores its preference as soon as it starts.
Cookies set by third-party scripts
Some apps load a vendor's script into your storefront, for example a consent management platform or a tag manager. That script writes its own cookies and browser storage under the vendor's rules, not Laioutr's, and what it writes can depend on how you configure it in the vendor's tool. The Laioutr app only loads the script and, where it integrates with consent, passes the visitor's decision on.
These cookies are not listed on this page. Take their names, purposes and lifetimes from the vendor's documentation or from your CMP's cookie scanner.
Cookies Laioutr does not write
If your CMP's scanner reports a cookie that is not on this page, it comes from a script or package outside Laioutr. A common example is i18next, the cookie of the i18next language detector: no Laioutr package or connector app depends on i18next. Look for it in your own code, your CMP, or a third-party widget on the page.
Cookies in the Studio preview
When an editor opens your storefront in Studio, it renders inside an iframe on cockpit.laioutr.cloud. Every cookie in that frame is a third-party cookie from the browser's point of view, so the platform rewrites all cookies on this page to SameSite=None; Secure; Partitioned for requests from the frame.
Partitioned (CHIPS) gives the preview its own cookie jar keyed on Cockpit and your storefront. A cart an editor builds in the preview never appears in the same shop opened in a normal tab, and the other way round. Visitors of your live storefront never get these attributes.
If you write cookies in your own app code, use setManagedCookie so they behave the same way. The identity cookies recipe shows how.
Scope of this page
This page covers the storefront's cookies and browser storage. Cockpit, Laioutr's management application, sets its own login and session cookies on cockpit.laioutr.cloud; those concern your team's accounts, not your storefront's visitors.
Cookies written by your own code or by apps that are not listed here are outside this list. If you build a connector app, document its cookies in the app's "Cookies and context" section so they can be added here.
Questions about this list: datenschutz@laioutr.com.