Skip to main content
The Privacy page holds cookie preference settings for your Online Store and for an Embedded Store (your store embedded on another website).
These settings persist to a legacy storage path and the current storefront does not read them — it ships no built-in cookie consent banner. Changing the options on this page has no effect on what visitors see.
Each context offers the same three choices: If your store needs cookie consent — for example under GDPR or ePrivacy rules — bring your own consent manager. Load it through Custom scripts: add the consent manager’s script tag as an external script, and it runs in your storefront’s <head> on every page except the payment pages. Consent managers such as Cookiebot, Usercentrics, or OneTrust work this way; configure blocking of your analytics and marketing scripts inside the consent manager itself.

Scripts on payment pages

Your consent manager loads through Custom scripts, and Custom scripts do not run on the checkout, checkout links, or the subscription portal. Your consent manager therefore never loads on those pages and cannot gate what runs there. One third-party script does run on them: a client-side script monitor TWICE Commerce loads from csidetm.com. Its purpose is PCI DSS v4.0 compliance — keeping an inventory of the scripts on a payment page and detecting tampering with them or with the page’s HTTP headers. TWICE Commerce operates it under a single platform account shared across all merchants, and it is outside your consent manager’s reach. Account for it when you write your privacy policy or answer a security questionnaire. See Payment pages for which paths this covers and why.

Custom scripts

Load a consent manager and other third-party scripts.

Terms & Policies

Manage your published policy documents.