This article explains, in full, what information Wishlist Plus stores in a shopper's web browser, how it responds to a shopper's cookie choices, and the two mechanisms Wishlist Plus uses to stay usable and compliant for shoppers who haven't consented to cookies yet. It is written for merchants using Wishlist Plus, and for agencies configuring it on behalf of a client. Last verified against the current product on 27 July 2026.
What this article covers, and what it doesn't: this article is specific to Wishlist Plus running on Shopify. It supplements, and does not replace, the Swym Privacy Policy, which is the governing legal document across all Swym products and platforms. If you need a formal compliance opinion for your own legal team, use this article as a factual reference and have your own counsel review it against your specific obligations — this isn't legal advice.
What Wishlist Plus stores in the shopper's browser, and why
Wishlist Plus uses small pieces of information called cookies, stored in the shopper's web browser, to do things like remember an anonymous visitor's wishlist contents, recognize whether they're logged in, and remember contact details they've provided for alerts such as back-in-stock notifications. All of these are named starting with "swym-".
Each cookie below is marked as Necessary, Functional, or Marketing — the categories commonly used in cookie banners and consent management tools. If you use a consent management platform, you can use this table directly. If you need this categorization confirmed for a legal filing or audit, have your own privacy counsel review it against your specific obligations.
Cookie | What it does | How long it lasts | Category |
swym-pid | Identifies your store to Swym's backend systems | Up to 365 days | Necessary |
swym-swymRegid | Anonymous visitor identifier — lets a guest shopper's wishlist follow them across visits on the same browser, without requiring a login | Up to 365 days | Necessary |
swym-session-id | Keeps track of the shopper's current browsing session | 30 minutes | Necessary |
swym-o_s | Caches whether your store has multi-market functionality enabled, for the current session | 30 minutes | Necessary |
swym-isCheckedForMisauth | An internal record used to avoid repeating a one-time account-authentication cleanup step | Up to 365 days | Necessary |
swym-email | Stores an email address the shopper has provided, for Save-for-Later or watchlist features | Up to 365 days (unless the shopper logs out or manually disconnects) | Functional |
swym-weml | Stores an email address specifically tied to watchlist alerts | Up to 365 days | Functional |
swym-productCartAction | Records the state of a cart action for a specific product | Up to 365 days | Functional |
swym-validatedUserContactNo | Stores a phone number the shopper has confirmed, for back-in-stock text message alerts | Up to 365 days | Functional |
swym-tpermts | Records when it is next appropriate to show the shopper a permission prompt again, so they are not asked repeatedly | Up to 365 days | Functional |
swym-u_pref | Stores a shopper's saved wishlist and notification preferences | Up to 365 days | Functional |
swym-remoteAuth | Tracks whether a passwordless login request is pending, completed, or should be cleared | Up to 365 days | Functional |
swym-clctmap | Internal record avoiding duplicate identity-detection calls to the same source | Up to 365 days | Functional |
swym-ol_ct | Tracks the last-synced shopping cart token, used only if the optional cart-attribute-sync feature is enabled | 30 minutes | Functional |
swym-_oid | Internal record preventing an order confirmation from being reported more than once | 30 minutes | Functional |
swym-pstlgnrd | Remembers which page to return the shopper to after they are required to log in | 30 minutes | Functional |
swym-ignach | A short-lived internal marker used immediately after a passwordless login request | 30 minutes | Functional |
swym-nf_svd | Records that the shopper added an item to their wishlist during the current browsing session | 30 minutes | Functional |
swym-t_m | An internal record ensuring a technical mismatch is only reported once per session | 30 minutes | Functional |
swym-v-ckd | An internal record ensuring a software version check only runs once per session | 30 minutes | Functional |
swym-badrid | Counts repeated technical errors related to a visitor's identifier, used to decide when that identifier should be reset | 30 minutes | Functional |
swym-shutm | Records marketing campaign attribution information (which campaign brought the shopper to your store) | Up to 365 days | Marketing |
For the complete, continuously maintained version of this table — including any local storage entries not listed here — see Cookie Consent and Learn How Swym Uses Cookies and Local Storage. This article's table is kept in step with those, but the help center articles are the ones actively updated first if anything changes.
None of the other Wishlist Plus features — Add to Wishlist alerts, Back in Stock alerts, Low Stock alerts, Price Drop alerts, Removed from Wishlist notices, Save-for-Later reminders, and Wishlist Reminder emails — set any cookies of their own. These work by sending emails or triggering automated workflows behind the scenes, with no footprint in the shopper's browser.
Wishlist Plus also includes an optional analytics tool called a web pixel. This tool only reads the cookies listed above, along with Shopify's own shopping cart cookie, to measure activity. It never sets any cookies of its own, and it only runs if the shopper has given consent for analytics, marketing, or preference tracking through Shopify's own consent system.
Default behavior — and it isn't the same everywhere on your storefront
By default, Wishlist Plus relies entirely on Shopify's own consent system, the Customer Privacy Application Programming Interface, to decide when it's allowed to operate. If Shopify determines no consent banner is required for a shopper's region, Wishlist Plus loads and works normally right away. If a banner is required, Wishlist Plus waits until Shopify confirms the shopper has given consent.
What the shopper actually sees while consent is undecided depends on which type of wishlist button your theme uses — this is not uniform, and it's worth understanding precisely:
Classic (non-Advanced) Add to Wishlist button: hidden until consent is confirmed, and removed from the page entirely if the shopper explicitly declines.
Advanced Product Detail Page button, Advanced Collections button, and the header wishlist icon: these stay visible either way. Clicking one triggers a consent prompt instead of the button hiding. There are two different mechanisms behind that prompt, described next — they look similar but behave differently.
Two distinct consent mechanisms — easy to mistake for one, and worth telling apart
Both mechanisms below can appear on the Advanced Product Detail Page button, the Advanced Collections button, and the header icon. They use a similar-looking prompt, which makes them easy to conflate — but they answer a shopper's decline very differently.
Contextual GDPR Consent
This mechanism checks Shopify's real consent status at the exact moment a shopper clicks. If consent has already been given, the item is added instantly. If not, a prompt appears asking the shopper to consent. If the shopper declines this prompt, no wishlist action is taken and no data is stored anywhere — not as a cookie, and not on the shopper's own device. The button stays visible for them to try again later; declining doesn't lock anything.
This flow is designed to work alongside your store's main cookie banner. If a shopper has already accepted cookies through your banner, they will never see this prompt at all.
Full detail: Contextual GDPR Consent for Wishlist.
Privacy-First Wishlist
This is a separate, optional feature. Where enabled, it lets the wishlist keep working for a shopper who declines cookies, by saving their wishlist items to their own device instead of using cookies. No cookies are set, and no personal information reaches Swym unless and until the shopper later chooses to log in.
The two mechanisms don't hand off to each other. Declining the Contextual GDPR Consent prompt does not activate Privacy-First Wishlist's device-only saving — they're independent systems that happen to share a visual design. If your store has both active on the same button, contact Swym support to confirm exactly what a shopper will see and what happens if they decline, since the exact behavior depends on your specific configuration.
Full detail and configuration steps: Privacy-First Wishlist for Stores with Cookie Consent Banners and Privacy-First Wishlist — Configuration Guide.
Privacy-First Wishlist — where it actually applies
This is the most important scope fact in this article: Privacy-First Wishlist's device-only saving only works on two specific storefront components — the Advanced Product Detail Page wishlist button, and the Advanced Collections wishlist button.
If your theme uses the classic (non-Advanced) Add to Wishlist button or classic Collections button instead, turning on Privacy-First Wishlist has no effect on those blocks. A shopper who declines cookies there sees the same non-functional heart icon described in Section 2 (Default behavior — and it isn't the same everywhere on your storefront) — whether or not the feature is enabled.
The header wishlist icon is a partial case. It can show the Contextual GDPR Consent prompt on click, and it can open a preview panel showing items already saved locally by one of the two Advanced buttons elsewhere on your storefront — but it cannot itself save an item locally. Its own item-count badge always reflects server-side data requiring real consent, so it will not include anything saved under Privacy-First Wishlist.
Before enabling this setting and telling shoppers or clients it's active, confirm which wishlist button blocks your theme actually uses. Contact Swym support or your theme developer if you're unsure.
If you've built a custom wishlist experience rather than using either Swym-provided block, contact Swym support before assuming either mechanism described above applies automatically — custom implementations may need additional configuration to behave the same way.
Configuring Privacy-First Wishlist
Configuration lives in Settings → Compliance and Accessibility, with two controls: Works without cookies (turns the feature on or off) and Ask for Permission (controls whether the consent prompt appears on the first click or the third). Full step-by-step instructions, including a check for which button blocks your theme uses before enabling anything, are in the Configuration Guide.
Working alongside your existing consent management tool
If your store uses a separate consent management platform — OneTrust, Cookiebot, Consentmo, or similar — both mechanisms above are designed to work alongside it, not in conflict with it. Your consent management platform continues to control whether Wishlist Plus's standard, cookie-based version loads at all. No special configuration is required beyond correctly categorizing the cookies listed in Section 1 (What Wishlist Plus stores in the shopper's browser, and why) within that tool.
Self-check before relying on this for compliance purposes
Confirm whether your theme uses the Advanced Product Detail Page and/or Advanced Collections blocks. If it doesn't, Privacy-First Wishlist's device-only saving won't activate anywhere on your store.
If you serve shoppers in the European Union or European Economic Area, we recommend keeping "Ask for Permission" turned on.
If you use a consent management platform, confirm the cookies in Section 1 (What Wishlist Plus stores in the shopper's browser, and why) are categorized correctly within it.
If your theme or wishlist blocks ever change, re-check that Privacy-First Wishlist still applies where you expect.
If you've confirmed your theme uses the Advanced blocks and Privacy-First Wishlist still doesn't seem to be working as described, contact Swym support directly rather than assuming the setup is wrong — there may be a store-specific factor that isn't visible from the settings panel.
Frequently asked questions
Does this apply automatically based on my store's region? No. Your store's region is only used to suggest a sensible default the first time you open the settings page. Your own configuration choice always governs, regardless of region.
Does declining cookies affect anything else on my store, like analytics or advertising pixels? No. These mechanisms only affect wishlist functionality. Everything else on your store continues to be governed by your main cookie consent banner.
Can a shopper access their locally-saved wishlist on a different device? Not unless they log in. Items saved locally are tied to the specific browser and device they were saved on.
Does the shopper need to create a new account to sync? No — they can use an existing account, or create one through your store's normal sign-up process.
I've confirmed my theme uses the Advanced blocks, and Privacy-First Wishlist still isn't working. What should I do? Contact Swym support directly. There are store-specific configuration factors that aren't always visible from the settings panel, and our team can check your specific setup.
This article reflects Wishlist Plus product behavior as verified on 27 July 2026. If something described here doesn't match what you're seeing on your store, contact Swym support ([email protected]) so we can look into it.
