Cookie and Technology Schedule

Last updated September 14, 2026.

Retention descriptions below state the purpose or criterion that determines how long information is kept. A provider may use a fixed period when its contract, settings, or applicable law requires one.

Security and fraud

Provider Domains Data categories Purpose Retention criterion Recipients Before optional consent
Forter 7ce243a1e1a2.cdn4.forter.com
899e2c3adfe7436aa6acde5ed2459788-7ce243a1e1a2.cdn.forter.com
cdn0.forter.com
cdn3.forter.com
Device/browser/connection data, IP address, identifiers, site interactions, behavioral signals, contact/account data, order and payment metadata Fraud and abuse prevention, payment-risk assessment, transaction recommendations Fraud, chargeback, dispute, security, and contractual/legal needs Forter and authorized subprocessors Yes — necessary security
Kount ssl.kaptcha.com Device, browser, IP, connection, identifiers, risk signals Device collection and fraud detection Fraud and security needs under the Kount/payment configuration Kount and authorized security/payment providers Yes — necessary security
Google reCAPTCHA www.google.com Device/browser data, IP address, interaction and abuse signals Prevent automated abuse of the Boost claim form and other protected forms Security need and Google's configured retention Google and authorized subprocessors Yes — only on protected forms

Checkout and customer-selected services

Provider Domains Data categories Purpose Retention criterion Recipients Before optional consent
Shopify / Shop Pay shop.app and first-party Shopify storefront/checkout endpoints Contact, account, cart, order, payment metadata, device/browser, IP, session and checkout data Storefront, authentication, cart, checkout, accelerated checkout, payment, order administration Account/transaction lifecycle plus tax, accounting, dispute, fraud, and legal needs Shopify, selected payment providers, and authorized subprocessors Yes — necessary storefront/checkout
Global-e crossborder-integration.global-e.com
utils.global-e.com
webservices.global-e.com
Name, email, phone, billing/delivery address, payment data, IP/session data, order data, customs identification where required International checkout, payment, fraud screening, tax/duty calculation, customs, delivery, returns, support International transaction lifecycle plus customs, tax, refund, dispute, fraud, and legal needs Global-e affiliates, payment processors, carriers, customs brokers, fraud and fulfillment providers Yes — when international service is used
SureBright api2.surebright.com Contact, product/order data, plan selection, transaction history, device/browser data, claim/support communications Display eligible plans; issue and administer coverage; communicate plan details; process claims Offer/session need, then the plan, claim, dispute, and legal lifecycle SureBright, insurers/obligors, administrators, support and authorized subprocessors Yes — only when offering or delivering the protection service

Store functionality

Provider Domains Data categories Purpose Retention criterion Recipients Before optional consent
Swym Wishlist Plus swymstore-v3premium-01.swymrelay.com Wishlist choices, product identifiers, browser/device and customer/session identifiers Save and retrieve shopper-requested wishlists Until removed, account deletion, service termination, or provider expiry Swym and authorized subprocessors Yes — when wishlist is used
Junip api.juniphq.com
apid.juniphq.com
widgets.juniphq.com
Review content, ratings, product/order validation, device/browser and interaction data Display, submit, moderate, and validate product reviews Review lifecycle, moderation/dispute need, and legal obligations Junip and authorized subprocessors Yes — for requested review functionality
Richpanel cdn.richpanel.com
widgetconfig.richpanel.com
cdn-v2.richpanel.com
Device/browser data, session and support interaction data, contact/order details a shopper submits Load support tools and provide customer-requested assistance Support relationship and ticket/dispute/legal needs Richpanel and authorized subprocessors Yes — for support functionality
Videowise api-cdn.videowise.com
assets.videowise.com
cdn.videowise.com
cdn2.videowise.com
images.videowise.com
Device/browser, IP, product/page context, video requests and interactions Deliver requested product-video content and related interface assets Content-delivery logs and service configuration; interaction analytics must follow consent Videowise, CDN and authorized subprocessors Yes for content delivery; interaction analytics remain optional

Reliability and content delivery

Provider Domains Data categories Purpose Retention criterion Recipients Before optional consent
Sentry browser.sentry-cdn.com
o4510851763273728.ingest.us.sentry.io
Error details, route and runtime context, device/browser data, IP; configured scrubbing removes or redacts direct identifiers Detect and resolve technical failures Shortest operational debugging period under the configured Sentry project Sentry and authorized subprocessors Yes — necessary reliability
jsDelivr cdn.jsdelivr.net IP address, browser request headers, requested asset Deliver required Swiper CSS and other static libraries Transient delivery/security logs under CDN configuration jsDelivr/CDN operators Yes — required asset delivery
Google-hosted libraries ajax.googleapis.com IP address, browser request headers, requested library Deliver required site libraries Transient delivery/security logs under provider configuration Google and authorized subprocessors Yes — required asset delivery
Google Fonts fonts.googleapis.com
fonts.gstatic.com
IP address, browser request headers, font/style request Deliver required fonts and styles Transient delivery/security logs under provider configuration Google and authorized subprocessors Yes — required content delivery

Consent and permitted signal routing

Provider Domains Data categories Purpose Retention criterion Recipients Before optional consent
Blotout / EdgeTag zevdh.plug.tech Consent preferences, device/browser information, IP address, cookie/similar identifiers, website events and permitted transaction signals Record and enforce privacy choices; route events to destinations allowed by those choices and law Consent-record/legal-proof period; identifiers and event data only as long as necessary for routing, security, and configured service Blotout and authorized infrastructure providers; permitted destinations listed below Yes — necessary consent enforcement; optional destinations remain gated

Optional analytics and advertising

The systems below must not receive analytics or advertising events until the applicable consent or other legal condition is satisfied. Presence of a loader or consent-mode request is not permission to send event payloads.

Provider Domains Data categories when allowed Purpose Retention criterion Status
Google Analytics / Google Ads / Google Tag Manager www.googletagmanager.com
www.google-analytics.com
analytics.google.com
ad.doubleclick.net
www.merchant-center-analytics.goog
Cookie/device identifiers, IP-derived location, page/product/cart/order events, campaign/referral and conversion data Analytics, attribution, audience measurement, advertising, conversion reporting Configured property and advertising retention; deletion or consent withdrawal where applicable Optional — consent or another applicable legal condition required
Meta Pixel connect.facebook.net and Meta event endpoints Cookie/device identifiers, IP address, page/product/cart/order events, hashed contact data where configured Advertising, attribution, audience creation and measurement Meta configuration and applicable deletion/opt-out requirements Optional — consent or another applicable legal condition required
Microsoft Advertising bat.bing.com Cookie/device identifiers, IP address, page/product/cart/order and campaign events Advertising attribution, audience and conversion measurement Microsoft Ads configuration and applicable deletion/opt-out requirements Optional — consent or another applicable legal condition required
Snapchat intg.snapchat.com
sc-static.net
tr.snapchat.com
Cookie/device identifiers, IP address, page/product/cart/order and campaign events Advertising attribution, audience and conversion measurement Snapchat configuration and applicable deletion/opt-out requirements Optional — consent or another applicable legal condition required
Microsoft Clarity www.clarity.ms
scripts.clarity.ms
i.clarity.ms
Device/browser identifiers, IP-derived location, page events, clicks, scrolling and session interaction data Session analytics, usability and diagnostics Clarity project retention and applicable deletion/withdrawal requirements Optional — consent or another applicable legal condition required
PostHog us.i.posthog.com
us-assets.i.posthog.com
Device/session identifiers, page and product events, feature interactions, performance and error context Product analytics, performance measurement and debugging Plug's PostHog project retention and deletion configuration Optional — consent or another applicable legal condition required

Klaviyo: requested communications versus general tracking

Klaviyo is not globally necessary and is not approved for the necessary-services whitelist.

Use Domains Data categories Rule
Shopper-requested back-in-stock or comparable alert a.klaviyo.com or the configured submission endpoint Contact information and product/variant request submitted by the shopper May transmit only what is needed to fulfill the requested alert
General tracking, profiling, forms, and marketing static.klaviyo.com
fast.a.klaviyo.com
static-forms.klaviyo.com
static-tracking.klaviyo.com and Klaviyo event endpoints
Cookie/device identifiers, browsing and engagement data, contact/profile and campaign data Must remain subject to the applicable consent or legal condition; do not add to the necessary whitelist

Vendor notices