Trust Center

Cookies and browser storage

Every cookie and browser storage entry a Laioutr storefront and its connector apps can write in a visitor's browser, with its purpose, lifetime, attributes and the consent purpose that gates it.

Your privacy policy and your consent banner have to name the cookies your storefront sets, and the same consent rules apply to anything else it stores in the browser, such as localStorage. Some of them come from code you wrote; others come from Laioutr: Frontend Core, the connector apps you installed, and the Studio preview. This page lists the second group so you can copy it into your cookie declaration or your CMP's cookie scanner results.

You operate the storefront, so you are the controller and decide how each cookie is classified and disclosed. Laioutr acts as your processor (see Data Protection). The URL of this page is stable, so you can link to it from your records.

How to read the tables

Every cookie on this page is first-party: your storefront's own server or its client code writes it on your storefront's domain. Laioutr sets no cookies from a Laioutr domain.

The Gated on column names the consent purpose Laioutr checks before writing the cookie. "Not gated" means the code sets the cookie whenever the feature runs, without asking the consent store. Most of these are cart and login cookies that a visitor needs for a service they requested; whether you classify them as strictly necessary is your decision.

Two attributes follow platform rules rather than per-cookie choices:

  • Secure is set whenever the storefront runs on HTTPS (or on a loopback host such as localhost). You don't configure it.
  • Inside the Studio preview, every cookie on this page is rewritten to SameSite=None; Secure; Partitioned.

Frontend Core

These cookies come from @laioutr-core/frontend-core, which every Laioutr storefront includes. The analytics cookies are written only after the visitor grants the purpose, and are deleted when the visitor revokes it.

CookiePurposeGated onLifetime
laioutr_vidRandom visitor ID. Recognizes a returning visitor across visits.analytics393 days (13 months), not extended by activity
laioutr_sidRandom session ID plus its start and last-activity times. Groups events into one visit.analytics30 minutes of inactivity, at most 24 hours from the start of the visit
laioutr_campThe utm_* parameters of the landing URL that brought the visitor.analytics90 days from capture (configurable)
laioutr_clidAd click IDs from the landing URL, such as gclid, msclkid and fbclid.advertising90 days from capture (configurable)
laioutr_entryLanding page and external referrer of the visit that started the current attribution.analytics90 days from capture (configurable)
__Host-laioutr-embedMarks a request as coming from the Studio preview frame in Cockpit.Not gatedSession

laioutr_vid and laioutr_sid carry the identity described in Tracking. The three campaign cookies are explained in Campaign attribution, including how to shorten the 90-day window or narrow the captured parameters with config.campaign in the laioutrrc.

Attributes

CookieSet byHttpOnlySameSiteDomain
laioutr_vid, laioutr_sid, laioutr_camp, laioutr_clid, laioutr_entryClientNoLaxRegistrable domain of the market's host
__Host-laioutr-embedServerYesNone (with Partitioned)Host-only

The analytics cookies are scoped to the registrable domain, so shop.example.com writes them for example.com and a visitor keeps one identity across your subdomains. On a hostname Laioutr provisions (*.app.laioutr.tech, *.local.laioutr.tech), on an IP address and on localhost, they are host-only instead.

__Host-laioutr-embed only exists inside the Studio preview frame. A visitor opening your shop directly never receives it.

Frontend Core uses @nuxtjs/i18n for translations. That module can detect the browser language and remember the result in a cookie named i18n_redirected. Frontend Core sets detectBrowserLanguage: false and resolves the language from the market's domain instead, so by default the cookie is not written.

When it is written, i18n_redirected stores the detected language code, lives for 365 days, and uses SameSite=Lax and Path=/. It is not HttpOnly, and no consent purpose gates it. With the module's default redirectOn: 'root' it is set when a visitor opens the start page or switches the language, so a scan that never does either may not find it.

Your project's i18n options in nuxt.config.ts take precedence over Frontend Core's. A project that sets i18n.detectBrowserLanguage to an options object turns the cookie back on. If your storefront writes i18n_redirected, check that option.

What Frontend Core does not store in cookies

Laioutr keeps no market, language or currency cookie. The consent store keeps no cookie of its own; it reads the decision your CMP stored. The content preview token travels as a query parameter.

Connector apps

A connector app sets cookies only when it is installed and the feature runs. The cookies below are written by the storefront's server, not by client-side scripts. The Shopify, Adobe Commerce, Shopware, commercetools, OXID, Sylius and Nimstrata cookies are HttpOnly, so client-side scripts cannot read them either.

Shopify

From @laioutr-app/shopify. All cookies use SameSite=Lax and Path=/.

CookiePurposeGated onLifetime
shopify-cart-idID of the visitor's Shopify cart. Set on the first add-to-cart.Not gated30 days
shopify-access-tokenCustomer Account API access token after login.Not gatedThe token's lifetime as returned by Shopify
shopify-refresh-tokenRefreshes the access token without a new login.Not gated30 days
shopify-id-tokenOpenID Connect ID token, used to end the session at logout.Not gatedThe token's lifetime as returned by Shopify
shopify-oauth-stateCSRF protection for the login redirect.Not gated10 minutes
shopify-oauth-nonceReplay protection for the login redirect.Not gated10 minutes
shopify-oauth-redirect-uriThe callback URL used for the login, reused in the token exchange.Not gated10 minutes
shopify-oauth-return-toThe page to return the shopper to after login.Not gated10 minutes

The four shopify-oauth-* cookies exist only while a login is in progress and are deleted when the callback completes. The access, refresh and ID tokens are deleted at logout.

The app does not set Shopify's own _shopify_y or _shopify_s cookies. Shopify analytics events reuse the Frontend Core visitor and session IDs instead.

Adobe Commerce

From @laioutr-app/adobe-commerce.

CookiePurposeGated onLifetimeSameSite
cart-idMasked ID of the visitor's Adobe Commerce cart. Set on the first add-to-cart.Not gated30 daysStrict

Shopware

From @laioutr-app/shopware.

CookiePurposeGated onLifetimeSameSite
sw-context-tokenShopware Store API context token, which identifies the cart and the logged-in customer.Not gated1 yearLax

The cookie is written whenever Shopware returns a new token, for example after login or a cart change. A project that supplies the token from its own session store through the shopware:context-token:resolve hook uses this cookie only as a fallback.

commercetools

From @laioutr-app/commercetools. Both cookies use SameSite=Strict.

CookiePurposeGated on
ctp-anon-tokenAccess token of the visitor's anonymous commercetools session, used for the cart.Not gated
ctp-anon-refresh-tokenRefreshes the anonymous session's access token.Not gated

Emporix

From @laioutr-app/emporix.

CookiePurposeGated on
accessTokenEmporix session token, anonymous or logged in. Set on the first request through an anonymous login.Not gated

OXID

From @laioutr-app/oxid.

CookiePurposeGated onLifetimeSameSite
oxid-basket-idID of the visitor's OXID basket. Set on the first request without one.Not gated30 daysNone

Sylius

From @laioutr-app/sylius.

CookiePurposeGated onLifetimeSameSite
sylius-cart-tokenToken of the visitor's Sylius cart. Set when the cart is created.Not gated30 daysLax

Nimstrata

From @laioutr-app/nimstrata.

CookiePurposeGated onLifetimeSameSite
nimstrata-visitor-idRandom visitor ID (UUID v4) sent to Nimstrata for search personalization, recommendations and event attribution.Not gated1 yearLax

Browser storage

Some Laioutr packages keep values in the browser's localStorage or Cache Storage instead of a cookie. These entries are never sent to the server. They stay until the visitor clears site data or the code removes them.

KeySet byPurposeGated onWhen it is written
nuxt-color-mode (localStorage)@laioutr-core/ui-kit through @nuxtjs/color-modeThe color scheme preference, light by default.Not gatedOn every page load
isAnnualBilling (localStorage)@laioutr-core/ui, in the Plan Card and Plan Card Slider sectionsWhether the visitor switched pricing to annual billing.Not gatedWhen a page with one of these sections renders
vite-pwa:hide-install (localStorage)@laioutr-app/pwaHides the "install app" prompt after the visitor dismissed it.Not gatedWhen the visitor dismisses the prompt
Service worker precache (Cache Storage)@laioutr-app/pwaCopies of the storefront's scripts, styles, HTML and images so it loads offline. Holds no visitor data.Not gatedWhen the service worker installs

nuxt-color-mode is written even on storefronts that offer no theme switch, because the color-mode module stores its preference as soon as it starts.

Cookies set by third-party scripts

Some apps load a vendor's script into your storefront, for example a consent management platform or a tag manager. That script writes its own cookies and browser storage under the vendor's rules, not Laioutr's, and what it writes can depend on how you configure it in the vendor's tool. The Laioutr app only loads the script and, where it integrates with consent, passes the visitor's decision on.

These cookies are not listed on this page. Take their names, purposes and lifetimes from the vendor's documentation or from your CMP's cookie scanner.

Cookies Laioutr does not write

If your CMP's scanner reports a cookie that is not on this page, it comes from a script or package outside Laioutr. A common example is i18next, the cookie of the i18next language detector: no Laioutr package or connector app depends on i18next. Look for it in your own code, your CMP, or a third-party widget on the page.

Cookies in the Studio preview

When an editor opens your storefront in Studio, it renders inside an iframe on cockpit.laioutr.cloud. Every cookie in that frame is a third-party cookie from the browser's point of view, so the platform rewrites all cookies on this page to SameSite=None; Secure; Partitioned for requests from the frame.

Partitioned (CHIPS) gives the preview its own cookie jar keyed on Cockpit and your storefront. A cart an editor builds in the preview never appears in the same shop opened in a normal tab, and the other way round. Visitors of your live storefront never get these attributes.

If you write cookies in your own app code, use setManagedCookie so they behave the same way. The identity cookies recipe shows how.

Scope of this page

This page covers the storefront's cookies and browser storage. Cockpit, Laioutr's management application, sets its own login and session cookies on cockpit.laioutr.cloud; those concern your team's accounts, not your storefront's visitors.

Cookies written by your own code or by apps that are not listed here are outside this list. If you build a connector app, document its cookies in the app's "Cookies and context" section so they can be added here.

Questions about this list: datenschutz@laioutr.com.

Copyright © 2026 Laioutr GmbH