Free delivery on orders of $100 CAD or more · 5-day returns
Last updated 16 September 2026

Cookie policy

CodedCart sets only strictly necessary cookies: ones that sign you in, protect your account, or complete a payment. None track you across sites or build a profile of you, which is why there is nothing to accept or decline.

Cookies we set

SESSION_ID keeps you signed in. It is HttpOnly, so scripts on the page cannot read it, and it lasts up to 30 days or until you sign out.

XSRF-TOKEN protects your account from forged requests sent by other websites. It lasts for your browsing session.

CODEDCART_OAUTH is set for up to 10 minutes while you sign in with Google, Apple, Facebook, X or GitHub, to prove the reply came back to the same browser. It is deleted as soon as sign-in finishes.

Cookies set by Stripe

On the checkout page, Stripe sets __stripe_mid and __stripe_sid to detect payment fraud. They are set only when you check out and are governed by Stripe's privacy policy.

The mobile app

The app does not use cookies. It keeps your sign-in in your device's secure storage instead.

Controlling cookies

You can block or delete cookies in your browser settings. Blocking the ones above signs you out and stops checkout from working, because none of them are optional.