Cookies and Tracking Notice
Version: 2026-08-03
Effective date: 3 August 2026
This Notice explains browser cookies and similar storage used by MuthoCommerce and by merchants on MuthoCommerce-hosted storefronts. It must be read with the relevant MuthoCommerce Privacy Notice and the merchant's own store privacy notice.
1. Responsibility
MuthoCommerce sets essential cookies needed for platform authentication, security, onboarding, carts, checkout intent, and navigation preference. For a merchant's store analytics or advertising pixel, the merchant chooses the provider, purpose, events, and audience and is responsible for an accurate notice and any required consent. MuthoCommerce supplies the integration and must enforce the consent state before loading a non-essential script.
Until that consent control is implemented and verified, merchant-configured Google Analytics, Meta Pixel, TikTok Pixel, or any comparable non-essential tracker must remain disabled. A policy notice alone does not create consent.
2. Essential first-party cookies
Exact cookie suffixes may differ for secure host and environment, but their purposes and maximum lifetimes are:
| Cookie or family | Purpose | Maximum lifetime | Essential |
|---|---|---|---|
better-auth.* | Sign-in, authenticated session, account security | 30 days; removed or invalidated on sign-out/expiry | Yes |
platform_session | Secure MuthoCommerce administration session | 24 hours | Yes |
onboarding_token | Links an onboarding browser to server-side onboarding state; credentials are not stored in the cookie | 30 minutes | Yes |
__Host-mutho_google_state | Prevents request-forgery during a Google connection flow | Deleted after callback or short flow expiry | Yes |
mutho_cart_id | Associates an anonymous shopper with the correct cart | 30 days | Yes for cart use |
mutho_buy_now | Carries a selected item through an immediate checkout flow | 30 minutes or until used | Yes for requested checkout |
mutho_shared_cart | Carries a merchant-created shared cart into checkout and prevents unintended reuse | 7 days or until used | Yes for shared-cart use |
mutho_recovery_src | Attributes an order to a shopper-requested recovery/quick-buy route | 24 hours or until checkout | Yes for the requested flow |
mutho-active-surface | Remembers whether an authenticated user selected the account or admin surface; it does not grant permission | 30 days | Yes for the requested preference |
| Consent record cookie | Stores tracker category choices without storing an advertising identifier | No more than 6 months before renewal | Yes for recording choice |
Essential cookies are not used for unrelated advertising and cannot be disabled through the consent control without breaking the feature the visitor requested. A visitor can block them in browser settings, but sign-in, cart, checkout, or security flows may stop working.
3. First-party service analytics
MuthoCommerce may record server-side page, error, performance, conversion, and abuse events needed to operate and secure the Service. These events should use truncated or minimised identifiers where practicable, remain separated by tenant, and follow the Privacy Notice retention periods. They must not be repurposed into cross-store behavioural advertising profiles.
If MuthoCommerce introduces an optional client-side analytics identifier that is not strictly necessary, it must be listed here and held until the user chooses the analytics category.
4. Merchant-enabled third-party tracking
After valid consent where required, a merchant may enable:
- Google Analytics or Google Tag services for store traffic and conversion analysis;
- Meta Pixel for measurement, audience, and advertising functions;
- TikTok Pixel for measurement, audience, and advertising functions; or
- another integration expressly listed in the merchant's notice and consent panel.
These companies may set or read their own cookies and receive device, page, event, and account-linked information under their own terms. MuthoCommerce does not control their independent retention or advertising profiles. The consent panel must name the categories and providers actually configured for that store; it must not show an empty generic banner.
5. Consent standard
Where consent is required:
- all non-essential categories are off by default;
- “Accept all,” “Reject non-essential,” and granular choices are equally accessible;
- no box is pre-ticked and closing the panel does not mean consent;
- scripts, pixels, iframes, and their network preconnects wait for the relevant choice;
- consent is recorded by policy version, category, timestamp, and store, without collecting more identity than necessary;
- withdrawal is available from every page and takes effect before further optional events are sent; and
- consent is requested again after a material purpose/provider change and at least every 6 months for a continuing optional choice.
The essential storefront and the ability to buy ordinary goods must not be conditioned on advertising consent unless the merchant can document that the tracking is objectively necessary for the requested service and lawful.
6. Browser controls and Global Privacy Control
Visitors can delete or block cookies through browser settings. The consent control will honour a stored withdrawal across that store until the visitor clears browser storage. MuthoCommerce should treat a recognised Global Privacy Control signal as an opt-out of sale, sharing, or targeted advertising where applicable; it must not represent that this signal controls essential authentication or cart storage.
7. Changes
The production notice must be generated from the actual cookie and script register. A new non-essential tracker cannot be launched until its owner, purpose, recipient, data, duration, consent category, and removal behaviour have been approved and added to the register and notice.