Cookie Policy
Effective: 2026-06-05 · Last updated: 2026-07-21
This page explains the cookies and similar storage Sumzy uses on sumzy.io (our marketing site and account dashboard). It is written to match what the site actually does, and aligns with the choice offered in our cookie banner. The Sumzy WooCommerce plugin and the Sumzy Shopify app are separate surfaces; what they do is described in "Sumzy inside your store" below.
Our approach
We keep cookies to a minimum. We use essential storage to run the site, and (only with your consent) a little analytics to understand how the site is used and improve it. You choose between "Accept all" and "Essential only" in the banner the first time you visit, and your choice is remembered.
Essential (always on)
These are required for the site to function and do not need consent:
- A small record of your cookie choice (stored locally in your browser) so we don't ask again on every visit.
- Security and session storage needed to keep you signed in to your account dashboard and to protect against abuse.
- A short-lived campaign reference (
sumzy_utm, stored in your browser's session storage) that carries the campaign parameters from the link you arrived on through to checkout, so we can tell which campaign a sign-up came from. It holds no personal data and it is cleared when you close the tab.
Analytics (only with your consent)
If you choose "Accept all", we set privacy-respecting analytics storage to measure aggregate, non-identifying usage (for example, which pages are visited). If you choose "Essential only", no analytics storage is set. You can change your mind at any time by clearing the site's storage in your browser.
We use two tools for this, both under the same consent gate:
- Google Analytics 4. The analytics script (
gtag.js) is provided by Google, but it runs under Google Consent Mode: until you accept, it operates in a cookieless mode that sets no analytics cookies and sends only aggregate, modeled measurement. - PostHog (EU Cloud). PostHog is not loaded at all until you accept, so before that it sets no cookie and captures nothing. Its requests are routed through a first-party path on
sumzy.io, and the data is processed on PostHog's EU infrastructure.
The cookies below are set only after you choose "Accept all".
| Cookie | Purpose | Set when | Typical retention |
|---|---|---|---|
_ga | Google Analytics: distinguishes one browser from another to measure aggregate site usage. | Only after you accept analytics. | Up to 2 years |
_ga_* (for example _ga_20PNYLLW9K) | Google Analytics 4: persists session state for the specific measurement property. | Only after you accept analytics. | Up to 2 years |
ph_*_posthog | PostHog: a pseudonymous browser identifier plus basic session state, used to count visits and page paths. | Only after you accept analytics. | Up to 1 year |
__ph_opt_in_out_* | PostHog: records that you opted in to analytics capture, and records a later withdrawal so the choice is honored. | Only after you accept analytics. | Up to 1 year |
We run Google Analytics with IP-address anonymization enabled and we do not enable any Google advertising signals (no ad personalization, no ad storage, no cross-site advertising). PostHog runs with autocapture, session recording, and visitor profiling switched off, so it records only the specific events we author. Sumzy is the controller for the analytics data collected on sumzy.io; Google LLC and PostHog, Inc. act as our processors for it. For more on how Google uses cookies, see Google's cookie usage information. For how the analytics data is processed and your right to withdraw consent, see our Privacy Policy and Sub-processors list.
Sumzy inside your store
The Sumzy plugin and app run on your store, not on sumzy.io, and this banner does not apply to them:
- WooCommerce. The plugin and the storefront widget set no tracking cookies on your shoppers. Summaries render from the copy stored in your own WordPress database.
- Shopify. The storefront app block sets no cookies and no browser storage on your shoppers. It renders from a summary stored in an app-owned product metafield in your shop. The Sumzy app inside your Shopify admin uses the session cookie that Shopify's app framework requires to keep you signed in while you use the app. That cookie is strictly necessary, and we set no analytics cookie there.
We also receive a small amount of product-usage information about the plugin and the app itself, for example that an install happened or that a first summary was generated. That is sent from our own systems, not from a cookie in a shopper's browser, and it is described in the Privacy Policy.
What we do not do
- We do not use advertising or cross-site tracking cookies.
- We do not sell data collected through cookies.
- We do not place any Sumzy cookie or tracker on your shoppers, on either platform.
More information
For how we handle personal data generally, see our Privacy Policy, which covers both WooCommerce and Shopify. Questions about cookies can go to our support contact listed on the Contact page.