Last updated: October 5, 2026
1. What we set
- Session cookie — keeps you signed in as you move between pages. Without it you would have to type your password on every screen.
- Security token (CSRF) — proves a form was really submitted from our site, not from someone else's page pretending to be you.
- Cart and language — remembers what a shopper put in a basket on a store, and the language chosen.
- Cookie notice — remembers that you have seen the notice, so it is not shown again.
These are needed for the site to work, and are set for everyone who uses it.
2. Cookies set by other people
When a shopper pays, the payment provider's own page may set cookies to spot fraud. When a merchant adds an analytics or advertising pixel to their store, that company sets its own cookies on their storefront. We do not control those; their own policies apply, and merchants are responsible for telling their shoppers about any pixel they add.
3. Turning them off
Your browser can block or clear cookies. If you block ours, signing in and checking out will not work, because those depend on the session cookie.
4. In the mobile app
The Shagofy Merchant app does not use cookies. It keeps a sign-in token in the phone's secure storage, and small settings such as your theme on the device itself. Signing out removes the token.
Questions about this policy? Write to support@shagofy.com.