When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies. The information does not usually directly identify you, but it can give you a more personalized web experience. Because we respect your privacy, you can choose not to allow some types of cookies. Below are the different cookie categories we use on pura.com. Blocking some types of cookies may impact your experience of the site and the services we are able to offer. Learn more about your cookie settings and management here.
Categorization Overview
| Shopify banner category | Our internal flag | What it controls on pura.com |
|---|---|---|
| Strictly necessary | none (always on) | Login, cart, checkout handoff, remembering the consent choice itself |
| Preferences | functional | Recorded, but no cookie depends on it yet. Turning off every category (Preferences included) stops the anonymous ID. |
| Analytics | analytics | FullStory session recording; whether the anonymous ID lives in a cookie or only for the tab session |
| Marketing | marketing | Meta Pixel, Trade Desk ID, server-set Meta cookies, ad attribution sent to our event pipeline |
| Sale of data | not mapped | Only forced off in the Pura app. The website doesn't read it separately. |
Strictly necessary
Required for the site to work. No consent needed.
| Cookie | Set by | Purpose | Duration | Consent handling |
|---|---|---|---|---|
| session | From code: Pura | Signed session holding per-visit state such as the cart reference | Browser session | Always set |
| __pat, __pit | From code: Pura | Signed login tokens (access and identity) for signed-in customers | 200 days | Only after sign-in |
| __prt | From code: Pura | Encrypted refresh token that keeps customers signed in | 200 days | Only after sign-in |
| _pura_consent | From code: Pura | Remembers the visitor's cookie choices | 1 year | Written when the visitor makes a choice |
| _pura_app_ctx | From code: Pura | Marks a visit that started in the Pura mobile app so marketing stays off | Browser session | App visitors only |
| rise_gifting_session | From code: Pura (for Rise) | Keeps the gift-card purchase flow together | 14 days | Only when someone uses gift-card gifting |
| _spice_preview | From code: Pura | Internal content-preview mode for Pura staff | 2 hours | Staff previews only. Not set for customers. |
| _tracking_consent | Vendor, scanned: Shopify | Shopify's copy of the visitor's consent choice | 1 year | Always set |
| _shopify_essential | Vendor, scanned: Shopify | Essential Shopify storefront functions | 1 year | Always set |
| __stripe_mid, __stripe_sid | Vendor, scanned: Stripe | Fraud prevention on pages that load Stripe's script | 1 year / 30 min | Not gated. Confirm which pages load Stripe. |
Preferences
Remembers choices that change how the site looks or behaves.
| Cookie | Set by | Purpose | Duration | Consent handling |
|---|---|---|---|---|
| theme | From code: Pura | Remembers light or dark display mode | 1 year | Always set |
Analytics
Measures how people use the site.
| Cookie | Set by | Purpose | Duration | Consent handling |
|---|---|---|---|---|
| _pura_anon | From code: Pura | Anonymous visitor ID for our own analytics and A/B tests | 400 days | Not set if the visitor turns off every category. Without analytics consent it's kept for the tab session only. |
| _pura_ga_cid | From code: Pura (for Google Analytics) | Durable copy of the Google Analytics client ID. It survives Safari's cookie limits. | 2 years | Set on first visit, not gated Review |
| _pura_exp_q | From code: Pura | Records which A/B tests the visitor qualified for, so they see a consistent version | 30 days | Built but not written anywhere yet. Classify it before it ships. |
| _ga, _ga_<ID> | Vendor, scanned: Google Analytics 4 | Distinguishes visitors and sessions | 2 years | Consent Mode defaults to granted and isn't updated on opt-out Review |
| fs_uid, fs_lua | Vendor, scanned: FullStory | Session recording and replay | 1 year / 30 min | Loads only with analytics consent. Stops immediately when consent is withdrawn. |
| _shopify_y, _shopify_s | Vendor, scanned: Shopify | Shopify storefront analytics. Also forwarded to Shopify so orders are credited to the visit. | 1 year / 30 min | Managed by Shopify's consent API |
Marketing
Ad measurement, attribution and audience matching.
| Cookie | Set by | Purpose | Duration | Consent handling |
|---|---|---|---|---|
| _pura_attr | From code: Pura | Stores ad click IDs from the landing URL (Google, Meta, TikTok, Reddit, Microsoft) and ad-platform IDs so a purchase is credited to the right ad | 400 days | Click IDs are captured even when marketing is off Review. The Meta ID inside it respects marketing consent |
| _fbp | From code: Pura server and Meta Pixel | Meta browser ID, shared by the Pixel and server-side conversions | 90 days | Only when marketing is allowed |
| _fbc | From code: Pura server and Meta Pixel | Meta ad-click ID | 90 days | Only when marketing is allowed |
| ttd_TDID | From code: Pura (for The Trade Desk) | Trade Desk ID used for ad attribution | 7 days | Only when marketing is allowed. Deleted immediately on opt-out. |
| TDID | Vendor, scanned: The Trade Desk (adsrvr.org) | Third-party ID set during the Trade Desk ID match | Vendor set | Only when marketing is allowed |
| Northbeam cookies | Vendor, scanned: Northbeam | Marketing attribution across ad channels | Vendor set | Loads for every website visitor, not gated Review |
Other browser storage
Not cookies, but often disclosed alongside them.
| Key | Storage | Set by | Purpose |
|---|---|---|---|
| _pura_ga_sid, _pura_ga_snum | Session storage | Pura | Google Analytics session ID and count, used to tie events to the visit |
| nb__region_code, nb__currency_code | Local storage | Pura (for Northbeam) | Region and currency passed to Northbeam |