1. What this policy covers
This policy describes cookies, local storage, and similar browser technologies used by the public BRDG website, the embedded Shopify admin app, and BRDG's SDK when a merchant installs it on a storefront. The merchant's own cookie policy must also describe BRDG where required.
2. Public website and app storage
| Context | Technology | Purpose | Duration |
|---|---|---|---|
| getbrdg.ai and app | brdg-theme local storage | Remembers a light-theme preference. It is not used for advertising or identity. | Until the user clears site storage or changes the preference. |
| Embedded Shopify app | Essential Shopify and session technologies | Authenticates the merchant, protects requests, and maintains the embedded session. | Session or provider-configured expiry. |
Normal web requests also produce server logs containing IP address, user agent, timestamp, path, and error or security information. Those logs are not cookies but are described in our Privacy Policy.
3. Merchant storefront SDK
| Name | Type | Purpose | Typical duration |
|---|---|---|---|
_brdg_vid | First-party cookie and local-storage mirror | Pseudonymous visitor continuity, stable assignment, and frequency controls. | Up to 365 days after affirmative analytics consent. |
_brdg_sid | First-party cookie and local-storage mirror | Groups events and decisions into the current storefront session. | Approximately 30 minutes after affirmative analytics consent. |
_brdg_acquisition | Local storage | Retains declared acquisition parameters for merchant attribution. | Until cleared, consent is revoked, or the storefront removes it. |
_brdg_intervention_state | Local storage | Remembers completed interventions and related suppression or frequency state. | Until cleared, consent is revoked, or the storefront removes it. |
_brdg_event_queue and _brdg_event_inflight | Local storage | Recovers consented event batches across navigation or a transient network failure. | Removed after delivery or recovery, or when consent is revoked. |
4. Consent behavior
The SDK reads Shopify's Customer Privacy API. Persistent SDK storage opens only when analytics processing is affirmatively allowed. If the API is unavailable, unresolved, or reports denial, BRDG uses session-scoped in-memory identifiers for the render-decision path and suppresses behavioral transmission. An affirmative choice can upgrade the same session to durable identity. Revocation rotates the in-memory identity and attempts to delete BRDG's cookies, storage mirrors, acquisition state, intervention state, and queued event data.
A merchant may use a storefront tool for an operational workflow without using BRDG's behavioral analytics storage, but contact or marketing processing still requires the notices and consent declared for that tool.
5. Your controls
- Use the merchant's Shopify consent banner to grant or withdraw analytics consent.
- Clear cookies or site data in browser settings.
- Disable the light-theme preference by clearing local storage or changing theme.
- Merchants can disable BRDG's app embed, pause deployments, or uninstall the app, subject to the consequences shown in BRDG's blast-radius and runtime controls.
Blocking essential authentication technology may prevent the embedded app from working. Denying analytics consent must not block the storefront's ordinary shopping functionality.
6. Changes and contact
We will update this policy when storage behavior materially changes. Questions can be sent to hello@getbrdg.ai.