Cookie Notice
Last updated September 03, 2026.
What cookies does Crate use?
Crate sets cookies for three jobs and no others: keeping you signed in, remembering a choice you made such as language, currency or region, and telling a merchant which share link brought a buyer to their store. There is no advertising cookie, no analytics cookie and no session recording script anywhere on the Crate marketing site or the Crate dashboard. Non-essential cookies stay off until you switch them on, and the choice itself is stored in a cookie lasting one hundred and eighty-two days so you are not asked again on every visit. A merchant may add their own analytics or advertising tag to their own storefront, and when they do those are the merchant's cookies under the merchant's own notice.
The four things people actually want to know
Each is stated again in full below, and the complete list follows by name.
-
Nothing is set before you choose
Non-essential cookies stay off until you turn them on. The only cookies set before a choice is made are the ones that make signing in and a cart work at all.
-
No advertising, no analytics
Crate loads no advertising, analytics, heatmap or session recording script on the marketing site or the dashboard. There is no third party cookie to disclose because there is no third party script.
-
Every cookie is named
The full list below carries the actual cookie name, so you can open a browser dev-tools panel and check this page against what your browser holds.
-
A merchant's own tags are theirs
A store owner can add Google Analytics or a Meta Pixel to their own storefront. Those are the merchant's cookies, disclosed in the merchant's own notice, not in this one.
What a cookie is, and how Crate uses them
Two short sections, then the list.
What a cookie is
A cookie is a small piece of text a website asks your browser to keep and send back on the next request. It is how a website can tell that the person loading this page is the same person who signed in a moment ago, or chose a currency, or put something in a cart. Without them every page load would be a stranger arriving.
Similar technologies do the same job by other means, including local storage in the browser and a tiny image loaded to record that a message was opened. Where this notice says cookie, it means all of them.
The three jobs Crate uses them for
Keeping you signed in. The dashboard session and the storefront session are what let a merchant stay signed in and a buyer keep a cart across page loads. These cannot be switched off, because switching them off is the same as switching off signing in.
Remembering a choice you made. Your language, your currency and market, which regional site you picked, and whether you already answered the cookie question. Each of these exists so the site stops asking you the same thing on every visit.
Telling a merchant which link brought a buyer. When a merchant shares a product link to a channel such as WhatsApp or Instagram, a cookie records which link the visit came from so the sale can be attributed to it. It records the channel, not the person, and it lasts thirty days.
There is no fourth job. Crate does not build a profile of you, does not sell what it holds, and does not share it for advertising.
Every cookie Crate sets, by name
Read out of the source rather than described in categories, so you can check it against your own browser. Not all of them apply to you: dashboard cookies are set only for a signed-in merchant, and storefront cookies only on a merchant's shop.
| Cookie | What it does | How long it lasts |
|---|---|---|
| _crate_session | Keeps a merchant signed in to the Crate dashboard. Signed and encrypted, readable only by the server, and it cannot be switched off without switching off signing in. | Until you close the browser |
| _crate_store_session | Keeps a buyer's cart and checkout progress on a merchant's storefront. Without it a cart empties on every page load. | Until the browser is closed |
| _crate_merchant_session | Lets a merchant who is signed in be recognised while looking at their own storefront, so the preview and the editing controls appear. | Until the browser is closed |
| crate_consent | Stores the cookie choice you made on this site, and the version of the notice you made it against, so you are not asked again on every visit and so a changed notice can ask again. | 182 days |
| crate_mkt_region | Remembers the region you selected on the Crate marketing site, so prices and tax examples are shown in your own currency rather than in a default one. | 1 year |
| crate_locale | Remembers the language you chose. Readable only by the server, and deliberately not signed, so the preference survives the session change that signing in performs. | 1 year |
| cms_locale | Remembers the language chosen on a merchant's storefront, which is a separate choice from the one made on the Crate site. | 30 days |
| cms_market | Remembers the market chosen on a merchant's storefront, which determines the currency, the shipping options and the tax treatment shown. | 30 days |
| crate_site | Remembers which regional Crate site you chose when more than one was available for your location. | 1 year |
| crate_site_suggestion_dismissed | Records that you dismissed the suggestion to switch to a different regional site, so it is not offered again on every page. | 180 days |
| _crate_share_channel | Records which shared link brought you to a storefront, such as a WhatsApp or Instagram share, so the merchant can see which channel produced the sale. It records the channel, not you. | 30 days |
| _crate_site_seen | Records that this browser has already been counted as a visit to a storefront today, so a merchant's visit count is not inflated by page reloads. | Until the end of the day |
| _crate_gate_preview | Set only on a password-protected storefront, and only after the password is entered, so a merchant sharing a private preview does not have to type it on every page. | Until the browser is closed |
| _crate_view_as_visitor | Set only when a merchant chooses to view their own storefront as an ordinary visitor would see it, and cleared when they switch back. | Until the browser is closed |
What Crate deliberately does not set
-
No advertising or retargeting cookie
Crate runs no advertising pixel on the marketing site or the dashboard, and does not share what it holds for cross-context behavioural advertising as that term is defined in law.
-
No analytics or session recording
No analytics script, no heatmap, no session replay. Server logs stay on Crate's own infrastructure and are kept for ninety days. There is no third party cookie to disclose here because there is no third party script.
-
No cross-site profile
Nothing Crate sets follows you to another company's website. Third party cookies are blocked by default in every current browser, and Crate has never depended on one.
How to change what is set
Three routes that work without asking us, and one that needs the merchant rather than Crate.
- Change your choice on this site
- Use the cookie preferences control in the site footer. It writes your new choice immediately, and the old one is replaced rather than added to.
- Clear what is already there
- Every browser can delete the cookies a site has set, from its own privacy or site data settings. Doing so signs you out and forgets your language and region, which is the trade.
- Block them at the browser
- Every browser can refuse cookies from a site entirely. Signing in and carts stop working, because those are the cookies being refused. That is a supported outcome rather than a broken one.
- Ask a merchant about their own store
- If a storefront running on Crate sets a tag the merchant added, that merchant is who to ask, and their own privacy notice is the one that covers it.
Questions about cookies
Short answers, and none of them hedge. If yours is not here, ask us on the contact page.
Does Crate use advertising or analytics cookies?
No. Crate loads no advertising, analytics, heatmap or session recording script on the marketing site or the dashboard. A merchant may add one to their own storefront, and when they do it is their tag under their own notice.
What happens if I refuse cookies?
Non-essential cookies are off until you turn them on, so refusing them changes nothing about how the site works. Refusing all cookies at the browser stops signing in and carts working, because those are the cookies being refused.
How long is my choice remembered?
One hundred and eighty-two days, stored in a cookie called crate_consent along with the version of this notice you agreed to. If the notice changes materially, the version changes and you are asked again.
Is this list complete?
It is every cookie Crate's own code sets, read out of the source. You can check it in your browser's dev-tools panel in about ten seconds, which is why it is published by name rather than by category.
A store on Crate set a cookie that is not on this list.
Then the merchant added it themselves, most commonly Google Analytics or a Meta Pixel. It is their cookie, disclosed in their own notice, and they are who to ask about it.
Who do I contact about this notice?
Email [email protected]. If the question is about a specific store rather than about Crate, the store owner is the controller and is who to ask first.
Trust and legal
Every document a security or procurement review asks for, in one place.
Questions about what we hold?
The privacy policy says what is collected, why, who it goes to and how long it is kept. This notice covers only the cookies.
14-day free trial · No card required