1. Audited application storage
The application currently uses functional authentication and preference storage. No optional marketing pixels or product-analytics trackers were found in the audited Scly UI. Merchant storefront tracking and third-party websites are separate and must be assessed by their operators.
- scly_session: signed, HTTP-only sign-in cookie; expires after seven days. Secure transport is required in production.
- scly_oauth_state, scly_oauth_owner and scly_oauth_shop: HTTP-only cookies used during Shopify connection, with a ten-minute maximum age.
- scly.appearance: browser local storage holding Light, Dark or System appearance; no automatic expiry. Clearing site data removes it.
2. Your controls
Sign out to clear the application session; use your browser settings to remove stored site data. Blocking authentication cookies may prevent sign-in or store connection. Appearance can be changed in the account menu or Settings.
Production must classify the preference storage under the applicable ePrivacy rules. A tracking-consent banner must not imply optional trackers exist when they do not. If optional analytics or marketing storage is introduced, assess and implement prior consent where required, with an equally accessible refusal and withdrawal control, before loading those services.