Cookie Policy

Last updated: August 6, 2026

Three different surfaces store three different things, so they are listed separately. If you run a shop using StorePilot, the third table is the one to copy into your consent banner — it is what our collector puts in your visitors' browsers.

1. This marketing website

store-pilot.net sets no cookies at all. It runs no analytics, no advertising pixels and no social plugins, and it loads fonts and other assets from our own servers rather than a third-party CDN — so simply reading a page here discloses nothing about you to anyone else. There is no consent banner because there is nothing to consent to.

2. The dashboard

dashboard.store-pilot.net stores what it needs to keep you signed in. These are strictly necessary for a service you asked for, so they do not require consent — but you should know they exist.

KeyWhereLifetimePurpose
access_tokenlocalStorage15 minutesAuthenticates your dashboard requests
refresh_tokenlocalStorage7 days, rotated on useRenews the access token so you are not signed out mid-session

Signing out deletes both. No analytics or advertising storage is used in the dashboard.

3. Our collector, on our customers' websites

When a shop installs StorePilot, our script stores an identifier in each visitor's browser so that separate page views can be recognised as one visit and repeat visits as one browser. This is what a shop must disclose to its own visitors.

KeyTypeLifetimePurpose
sp_vidFirst-party cookie2 years, renewed on each visitRandom identifier for the browser, so returning visits are recognised. Contains no personal data and is not readable by any other website.
wpelVisitorIdlocalStorageUntil clearedA duplicate of the same identifier. The two stores are cleared by different browser actions; keeping both prevents one visitor being counted as two.
wpelRecordingSessionIdsessionStorageThe visit (30 min of inactivity ends it)Groups page views into a single visit
wpelRecordingSessionActivity
wpelRecordingSessionSequence
sessionStorageThe visitThe inactivity clock and the recording's segment counter
wpelEnrSentsessionStorageThe visitMarks that browser and screen details were already sent, so they are transmitted once per visit rather than on every page

Consent

These identifiers are not strictly necessary for a shop's website to work — they exist for analytics. Under the EU ePrivacy Directive and equivalent UK rules, that means the shop must obtain consent before our script runs, and must be able to switch it off if consent is refused. The shop is the controller and makes that call; we provide the facts in this table so it can be described accurately in a banner.

None of these identifiers is shared across websites. A visitor to two different shops that both use StorePilot receives two unrelated identifiers, and neither shop can see the other's data. We do not operate an advertising network and never build cross-site profiles.

4. Refusing or removing them

  • Any browser can block or delete cookies and site data; the collector then treats each visit as a new browser, which costs accuracy and nothing else.
  • Browser "Do Not Track" and Global Privacy Control signals are not a substitute for a shop's own consent mechanism, which is where the decision belongs.
  • To be removed from a specific shop's data entirely, contact that shop — it can erase a visitor and everything recorded about them.

5. Changes

If we add or change a stored key we update this table before the change ships, so that a shop's consent banner can never be describing a version we no longer run. Questions: contact@store-pilot.net.