Consent and storage

How Benson respects your cookie banner, what strict mode does, and every key it can store on your storefront.

Reference
Updated 26 September 20261 min

Benson follows the consent signal your store already has. You choose the mode in Site settings → Tracking; the default, auto, works for most stores.

ModeWhat it does
autoPicks for you: Shopify's Customer Privacy API on Shopify, else an IAB TCF v2 CMP if one is present, else Google Consent Mode if your dataLayer has consent commands, else no consent signal.
shopifyReads Shopify's Customer Privacy API and follows the shopper's choice in your Shopify cookie banner.
tcfReads an IAB TCF v2 CMP. Consent means purposes 1 and 8 are granted; outside GDPR scope it counts as not required.
gcmReads the latest Google Consent Mode analytics_storage value from your dataLayer.
manualWaits for your code to call Benson.consent(true) or Benson.consent(false).
noneNo consent signal: Benson behaves as if consent isn't required.
  • Consent given, or not required: Benson keeps the session in local storage (shared across tabs), an anonymous visitor id to count returning visitors, and a first-party cookie so the checkout can link an order to the session.
  • Waiting, or declined: Benson keeps only a session-only id in session storage, with no visitor id and no cookie. It still measures the session, without anything that outlives the tab.

Benson never uses third-party cookies, never stores IP addresses, and puts no personal details in events.

Strict mode#

With strict consent on, a shopper who hasn't agreed (or has declined) is measured in memory only: Benson stores nothing and sends nothing except the install check. Turn it on if most of your traffic is from the UK or EU and your legal advice says analytics needs opt-in. Benson recommends it in your tracking settings when that's likely.

Strict mode and sampling make one exception: a ?benson_test= link from your dashboard. Benson first confirms the token belongs to your store, and ignores the link otherwise. For that page view only, it runs the test in memory, stores nothing, and sends test events that are never kept. See Test Benson on your store.

Every storage key#

This is the complete list of what Benson can store on your storefront, from the same registry the script is tested against:

KeyWhereWhat it's forNeeds consent?
bn_sLocal storageSession storage until consent allows local storageCurrent session id and timing (ends after 30 minutes idle or 24 hours).No: session-scoped or functional
bn_vLocal storageAnonymous visitor id and first-seen time, to count returning visitors.Yes, where consent is required
bn_sidCookieSession id shared with the checkout pixel so orders can be attributed.Yes, where consent is required
bn_caSession storageWhich Benson cart attributes were already written to the current cart.Yes, where consent is required
bn_hbLocal storageSession storage until consent allows local storageWhen the install heartbeat was last sent (at most every 30 minutes).No: session-scoped or functional
bn_ctxSession storageMemory only until consent allows session storageLanding page, referrer site, and campaign parameters of the current session.No: session-scoped or functional
bn_debugSession storageDebug logging switch, set only when a developer calls Benson.debug().No: session-scoped or functional
bn_xLocal storageSession storage until consent allows local storageWhich shopping extensions were already reported in this session, so a page change doesn't report them twice.No: session-scoped or functional
bn_extCookieA signed note that a coupon extension was seen in this browser, so the store's checkout can apply its discount-code policy (30 days).Yes, where consent is required
bn_wSession storageHow often the discount widget opened itself in this session (and, without consent, when it was last closed).No: session-scoped or functional
bn_wfLocal storageSession storage until consent allows local storageWhen the discount widget was last closed and how often it opened itself, so it doesn't pop up again too soon.Yes, where consent is required
bn_pending_codeSession storageA discount code chosen in the widget, kept until a page with the store's promo box can fill it in.No: session-scoped or functional
bn_prSession storageMemory only until consent allows session storageWhich known coupon extensions are installed in this browser, checked once per visit on desktop Chrome and Edge, so later pages don't check again.Yes, where consent is required

With manual, Benson waits until your code calls:

Benson.consent(true);  // the shopper agreed
Benson.consent(false); // the shopper declined

Use it with any consent tool that exposes a callback. Until the call, Benson treats consent as pending.

Stuck? Email [email protected].

Find out what's leaking. 14 days of Own, no card.