Legal
The cookies we set, and the ones we don't.
The cookies that keep a merchant signed in, the ones Clerk sets for sign-in, and the ones Liftable's pixel sets on a store once a shopper allows analytics. That is the whole list.
Last updated 16 September 2026
On this site
This site sets no analytics cookies and no advertising cookies, and loads no third-party trackers, so there is no banner asking for consent.
Its pages do load Clerk, the service merchants sign in with, so a merchant who is signed in stays signed in between this site and the app. Clerk's cookies are listed below.
The cookies the app sets
Inside the app, at app.liftable.dev, we set only what is needed to keep a merchant signed in to the right store. Each is HTTP-only and sent over HTTPS only:
- __Host-liftable_session — identifies the signed-in merchant and their store. Lasts 24 hours, and is cleared on sign-out.
- __Host-liftable_shop — names the shop the app was opened from, so the embedded app can be framed by that store's admin and no other. Lasts 24 hours, and is cleared on sign-out.
- __Host-liftable_oauth_state — protects a Shopify sign-in against forgery. Lasts 10 minutes, and is cleared once the sign-in completes.
- __Host-liftable_install_shop_hint — a second, weaker check alongside the one above: which shop a Shopify install was started for, so a sign-in link cannot be replayed into someone else's browser. Lasts 10 minutes.
- __Host-liftable_install_return — remembers which app page to return to after reconnecting Shopify. Lasts 10 minutes.
- __Host-liftable_resume — stops the app retrying the same store reconnection in a loop. Lasts 30 seconds.
- __Host-liftable_demo — set only when someone opens the demo store, so the demo never replaces their own store. Lasts 2 hours.
Clerk's sign-in cookies
When a merchant signs in, Clerk sets its own cookies on liftable.dev to keep them signed in:
- __session — a short-lived token saying who is signed in.
- __client_uat — when the merchant last signed in or out, so the site knows whether to refresh the session.
- The same two names followed by a short code (for example __session_ and a few characters), which tie them to Liftable's Clerk account.
- clerk_active_context — which of the merchant's sign-in sessions is in use.
None of these are optional
Each is strictly necessary: without them a merchant cannot sign in, or the app cannot tell which store's data to show. There is no version of the app that works without them, which is also why there is nothing here to opt out of.
Cookies on a merchant's own storefront
Where a merchant turns on Liftable's storefront pixel, it sets these first-party cookies on their store, for testing and measurement. It sets none of them until Shopify's Customer Privacy API says the shopper has allowed analytics, and if the shopper withdraws that consent, the pixel removes them.
- _lift_vid — a random visitor id, so a shopper sees the same side of a test on each visit. Lasts 400 days.
- _lift_sid — a random session id, linking the pages of one visit. Lasts 30 minutes, renewed while the shopper keeps browsing.
- lift_ followed by a test's code (for example lift_exp_012) — which side of that test the shopper is on, so the store can show it before the page appears. Lasts 30 days.
- lift_hb_ followed by a test's code — after a winning change ships, whether the shopper is in the small group that still sees the old version, so the result can be measured. Lasts 30 days.
Contact
Questions about anything on this page go to privacy@liftable.dev.