Cookie Policy
Last updated: September 1st, 2026
This page explains the cookies and similar technologies used on Dynojerky.com — what each one does, how long it sticks around, and how to turn off the ones that aren't essential. It sits alongside our Privacy Policy, which covers the bigger question of what we do with personal information generally. If the two ever seem to disagree, the Privacy Policy governs.
They're not the edible kind. We checked.
What a cookie actually is
A cookie is a small text file a website asks your browser to store. The next time you load a page, the browser hands it back, which is how the site knows your cart still has three bags of teriyaki in it.
A few related technologies do similar jobs, and this policy covers all of them:
Local storage — like a cookie but bigger and not sent to the server automatically. Shopify uses it for cart state and interface preferences. Pixels and web beacons — a 1×1 invisible image or a snippet of script that loads from another company's server. Loading it tells that company you were here. Ad pixels work this way. Software development kits (SDKs) — code from another company embedded in a page, doing roughly what a pixel does with more capability. Server-side tracking — where our store platform sends event data directly to an ad platform rather than through your browser. It's not a cookie at all, but it accomplishes something similar, so it belongs in an honest disclosure. We [do / do not] use Shopify's Customer Events / Conversions API integration with Meta.Cookies set by Dyno Jerky™ are first-party. Cookies set by another company whose code runs on our pages — an analytics provider, an ad platform — are third-party. The distinction matters because third-party cookies can, in principle, follow you across unrelated sites. First-party ones can't.
The four categories
Strictly necessary
These make the store function. Without them there's no cart, no login, no checkout, and no fraud protection at payment. They can't be switched off through our cookie controls, because the site genuinely doesn't work without them. In most jurisdictions they don't require consent for exactly that reason.
Functional
These remember preferences — your region and currency, your language, whether you dismissed a banner, whether you already saw a popup. Turning them off won't break anything; you'll just get asked the same things repeatedly.
Analytics
These count. Page views, session length, which product pages people actually open, where in checkout people give up. We use this to decide what to photograph better and which flavors to keep making. The data we look at is aggregated — we're reading charts, not individual browsing histories.
Advertising
These let ad platforms know that someone who saw our ad later visited the site or bought something, and let us show ads to people who browsed but didn't check out. This is the category that involves your data leaving for another company's systems, and it's the one most worth thinking about before you accept.
The actual cookies
Strictly necessary
Cookie Set by What it does Lasts cart, cart_ts, cart_sig Shopify (first-party) Holds your cart contents and verifies they haven't been tampered with 2 weeks _secure_session_id Shopify (first-party) Tracks your session through checkout 24 hours secure_customer_sig Shopify (first-party) Keeps you logged into your account 1 year _shopify_essential Shopify (first-party) Core store functionality and security 1 year keep_alive Shopify (first-party) Remembers your region during checkout 30 minutes _tracking_consent, _cmp_a Shopify (first-party) Stores your cookie choices — including a choice to refuse everything else 1 yearThat second-to-last row is worth noticing: refusing cookies requires a cookie to remember that you refused.
Functional
Cookie Set by What it does Lasts localization Shopify (first-party) Remembers your country and currency 1 yearAnalytics
Cookie Set by What it does Lasts _shopify_y, _shopify_s Shopify (first-party) Shopify's own store analytics — unique visitors and sessions 1 year / 30 min _shopify_sa_t, _shopify_sa_p Shopify (first-party) Attributes a visit to its marketing source 30 minutes _landing_page, _orig_referrer Shopify (first-party) Records which page you entered on and where you came from 2 weeks _ga Google Analytics 4 Distinguishes one visitor from another 2 years _ga_[container ID] Google Analytics 4 Maintains session state 2 yearsAdvertising
Cookie Set by What it does Lasts _fbp Meta Identifies a browser for ad delivery and conversion measurement 3 months fbc Meta Records that you arrived via a Facebook or Instagram ad click 3 months _gcl_au Google Ads Links a Google ad click to a purchase 3 monthsMeta, and Google each also set cookies on their own domains when you're logged into them. Those are governed by their policies, not ours: Meta and Google.
Email tracking
Most companies leave this out of their cookie policy. It uses the same technology, so we'll include it.
Our marketing emails contain a small invisible image hosted by [Klaviyo]. When your email client loads it, we learn that the message was opened, roughly when, and on what kind of device. Links in those emails are wrapped so we can count clicks.
To stop it: turn off automatic image loading in your email client (Gmail, Apple Mail, and Outlook all support this), or use a client with built-in privacy protection — Apple Mail Privacy Protection defeats open tracking entirely. Or unsubscribe, and we'll stop sending them.
Order confirmations and shipping notices are handled the same way technically. Those we send whether or not you've subscribed to marketing, because you need them.
Your controls
Our cookie banner. You can change your mind at any time, and the change takes effect immediately. We'll ask again after [12] months, or sooner if we add a tool that falls into a category you'd declined.
Global Privacy Control. We honor GPC. If your browser or an extension sends the signal, we treat it as a valid opt-out of advertising cookies and of "sale"/"sharing" under US state privacy laws — automatically, for that browser, with no banner interaction needed. [Brave, DuckDuckGo, and Firefox with the setting enabled] all send it.
Do Not Track. DNT was never standardized and browsers send it inconsistently, so most sites — ours included — don't act on it. GPC is the signal that actually works. Use that one.
Your browser. Every major browser lets you block or delete cookies:
Google Chrome — Settings → Privacy and security → Third-party cookies Apple Safari — Settings → Privacy → Prevent cross-site tracking (on by default) Mozilla Firefox — Settings → Privacy & Security → Enhanced Tracking Protection Microsoft Edge — Settings → Cookies and site permissions Mobile — the same options live under Settings for the browser appBlocking all cookies site-wide will break your cart and checkout. Blocking third-party cookies alone won't.
Opting out at the source: Google Analytics has a [browser opt-out add-on]. Meta ad preferences live in your Facebook or Instagram account settings. Industry-wide opt-outs are at [optout.aboutads.info] and [youronlinechoices.eu], though they're cookie-based themselves, so clearing your cookies clears the opt-out. Which is a real design flaw and not our doing.
A note on in-app browsers. If you tapped a link from Instagram or TikTok, you may be reading this inside that app's built-in browser rather than your normal one. Your browser's privacy settings may not apply there, and the app may collect its own data about the visit. Opening the site in Safari or Chrome gives you the settings you configured.
What we don't do
We don't use cookies to build a profile of your activity on sites unrelated to ours. We don't buy behavioral data about you from data brokers. We don't fingerprint devices to work around cookie blocking. We don't sell cookie data for money — though under California, Colorado, Connecticut, Oregon, and Texas privacy laws, letting advertising pixels pass data to ad platforms may legally count as "selling" or "sharing," which is exactly what the advertising toggle turns off.
Changes
We update this page when we add or remove a tool. The date at the top reflects the current version. If we add anything in the analytics or advertising categories, we'll re-request consent rather than quietly extending your old answer to cover it.
Questions
Questions, requests or comments concerning this privacy policy are welcomed and should be addressed to privacy@dynojerky.com or Attn: Privacy We Are Dyno Jerky Snacks LLC.