Skip to content
How it worksFeaturesAgentsWhat we checkPricingTrust
Install the appPartnersFree audit
How it worksFeaturesAgentsWhat we checkPricingTrust Center
Run the free auditInstall the appPartners

Legal

Cookie Policy

Last updated 2026-08-23

The short version: no advertising trackers, and everything we do store is in one table below, with our consent assessment and the part of it we are least sure about.

On this page

  1. What we use
  2. The full list
  3. The one third-party request
  4. No advertising trackers
  5. Where you came from
  6. Do we need a consent banner?
  7. Your choices

What we use

In plain words

Sign-in and security cookies, a theme preference, two short-lived measurement keys, and Shopify's own script.

Agentible uses a small number of cookies and similar browser storage. We do not use advertising cookies, we do not embed an advertising pixel or a third-party analytics SDK, and we do not track you across other sites.

The table below is the whole of it. It is generated from the same definition the code uses, so a cookie the app sets cannot be missing from this page.

The full list

In plain words

Every cookie, storage key and third-party script, with what it is for and how long it lasts.

NameTypePurposeLastsSet byParty
sb-<project-ref>-auth-tokenCookieKeeps you signed in. Cannot be read by scripts, and is only sent over HTTPS.7 daysAgentible, using Supabase AuthFirst party
sb-<project-ref>-auth-token-code-verifierCookieHolds the one-time secret that proves the sign-in link you opened is the one this browser asked for.Until the sign-in finishes, then deletedAgentible, using Supabase AuthFirst party
agentible_oauth_stateCookieDetects tampering while you are away at Shopify's install screen. Without it we cannot tell your install from someone else's forged one.10 minutesAgentibleFirst party
agentible_referral_claimCookieRemembers which partner's link brought you here, so the partner is credited if you install. Set only if you arrive on a partner link.60 daysAgentibleFirst party
arc-themeLocal storageRemembers whether you chose light or dark, so the page does not flash the wrong one.Until you clear your browser storageAgentibleFirst party
agentible.traffic-sourceSession storageRemembers which of our own links or adverts you arrived from, first one only, so we can tell which of our channels work. Sent to us only if you go on to give us your email address.Until you close the tabAgentibleFirst party
agentible:embeddedSession storageRemembers that this tab is the app running inside your Shopify admin, so it asks Shopify for a session token instead of looking for a cookie.Until you close the tabAgentibleFirst party
app-bridge.jsThird-party scriptShopify's own script, required for the app to run inside your Shopify admin. Since 2026-08-22 it is fetched only on app pages, or when a page is opened from Shopify with a shop or host parameter; ordinary marketing and legal pages no longer load it.Loaded on each page view, stores nothing of oursShopify (cdn.shopify.com)Third party

The sign-in cookie cannot be read by JavaScript, is only sent over HTTPS, and lasts seven days. The two session-storage keys are discarded the moment you close the tab and are never sent to any other company.

The one third-party request

In plain words

Shopify's App Bridge script loads on every page, including this one, and Shopify sees your IP address.

Agentible runs inside the Shopify admin, and Shopify requires its App Bridge script to be loaded for that to work. The script tag sits in the layout the whole site shares, so it also loads on the public pages, which means Shopify receives the IP address and browser details of anyone who reads this page, whether or not they are a merchant.

We would rather it loaded only inside the embedded app, and that is a change to make rather than a fact to defend. Until then, saying it plainly is the honest option. Shopify is listed on our subprocessors page for this reason as well as for the product data we audit.

No advertising trackers

In plain words

No ad pixels, no profiling. Analytics is cookieless and aggregate.

We do not embed advertising pixels or third-party marketing trackers. For analytics we use Vercel Web Analytics, which sets no cookies, does not profile you, and reports only aggregate numbers. Vercel is already our host and is listed on our subprocessors page.

Where you came from

In plain words

If you arrive from a link we advertised or shared, we remember which one until you close the tab, so we know which of our own channels work.

When you arrive from a link we published or paid for, that link carries a tag saying where it was (for example a campaign name, or an identifier the ad platform added). We store those tags in your browser's session storage under agentible.traffic-source, and we keep the first one, not the latest.

It is discarded when you close the tab. It is sent to us only if you go on to do something that already involves giving us your email address, such as requesting a free audit, and then it is stored next to that record so we can tell which of our own channels brought people in. It contains no name, no profile, and nothing about any other site you visit.

One thing it is fair to know, and the old version of this page did not say: if a click that carried a Google Ads identifier later becomes a paying customer, we upload that identifier and the value of the plan to Google Ads, by hand, as a file. That is how we measure our own advertising without placing a Google tag on this site. Google receives the click identifier it created and an amount. It does not receive your name, your email address or anything about your store.

Do we need a consent banner?

In plain words

Our reading is that the sign-in and security items are exempt and the two measurement items are arguable. We have written the reasoning down rather than assume the answer, and a lawyer has not yet confirmed it.

The rule is Article 5(3) of the ePrivacy Directive, brought into Portuguese law by Lei 41/2004. It covers storing anything on your device or reading anything from it, whether or not that thing is personal data, so session storage counts just as a cookie does. Consent is required unless the storage is strictly necessary for a service you asked for.

Applying that to the table above, item by item:

  • Sign-in, PKCE and OAuth state: strictly necessary. Without them you cannot sign in, and we cannot tell your install from a forged one.
  • Theme: a preference you set yourself, and the interpretation regulators publish treats a user-set display preference as exempt.
  • Referral code: set only if you follow a referral link, and it exists purely to finish the install you started. We read that as necessary to the thing you asked for, but it is a judgement, not an obvious answer.
  • Traffic source: this is measurement, not a service you asked for. National regulators do exempt first-party audience measurement, but that practice generally expects the data to stay aggregate and not be shared with anyone else.

The part that cuts against us. The Google Ads upload described above shares a click identifier and a revenue figure with a third party. That is exactly what the first-party measurement exemption is generally understood not to cover, so the traffic-source key is the weakest item on this page, and we are not going to argue otherwise. It is also worth saying that the Shopify script is loaded on public pages that do not need it, which is not storage we control but is a third-party request we chose to make.

Where that leaves us. We have not put a consent banner on this site. That is a decision nobody has formally taken rather than a conclusion this analysis compels, and this page exists so that the reasoning is on the record and can be checked, corrected or overruled. This assessment has not been reviewed by a lawyer. If your own counsel reads it differently, we would like to hear it: email privacy@agentibleapp.com.

Your choices

In plain words

You can clear or block cookies in your browser. The sign-in ones are needed to sign in.

You can clear or block cookies and site storage through your browser settings, and clearing them removes everything in the table above that we set. Blocking the sign-in cookies will stop you from signing in or using the app. Blocking the traffic-source key costs you nothing at all: it only makes our own advertising harder for us to measure.

Built openly. We never promise a ranking we cannot deliver.

Product

  • How it works
  • Features
  • What we check
  • Pricing
  • Free audit
  • Install the app
  • Partners

Verticals

  • Supplements
  • Skincare
  • Fashion
  • Electronics
  • Jewelry
  • Pet
  • Home & Living
  • Food & Beverage

Company

  • About
  • Customers
  • Resources
  • Trust Center

Legal

  • Legal notice
  • Terms
  • Privacy
  • DPA
  • Subprocessors
  • Cookies
  • Partner terms
  • Accessibility
© 2026 Agentible. Alcochete, Portugal.