URLs, requests and cookies
Every URL is cleaned in the browser before it is sent:
- Only the query parameters in Analytics settings → Kept URL parameters stay. The default list is
utm_*,gclid,fbclidandmsclkid. Wildcards likeutm_*work. Every other parameter is removed. - Email- and phone-like strings in the path are masked.
So https://example.com/search?q=rtx&utm_source=google&email=jan@example.com is stored as https://example.com/search?utm_source=google.
Search terms are not lost: the search page’s term is read separately (and masked) when a search is detected.
If you use other campaign parameters, such as ref or aff_id, add them to the list.
Network requests
Section titled “Network requests”The script watches fetch and XMLHttpRequest calls:
| Request | Recorded? |
|---|---|
| Failed, or status 400 and above, on any host | Yes, as a network error |
| Successful, to your shop’s own host or its subdomains | Yes, as a network request, for timing |
| Successful, to any other host (analytics, ads, payment widgets…) | No |
“Your shop’s own host” is the page’s host without www., and every subdomain of it. On www.example.com, requests to example.com, www.example.com and api.example.com are kept; requests to google-analytics.com are not. For each request, only the method, host, path (with emails and phone numbers masked), status and duration are stored. Never the query string, bodies or headers.
Cookies and storage
Section titled “Cookies and storage”With consent (or consent set to Not required), the script stores:
| Name | Kind | Contents | Lifetime |
|---|---|---|---|
_qm_sid |
First-party cookie | Session id (a random UUID) | 30 minutes, rolling, at most 24 hours |
_qm_vid |
First-party cookie | Visitor id (a random UUID) | 13 months |
Both cookies are SameSite=Lax. Set cookieDomain in init to share them across subdomains.
localStorage and sessionStorage hold the cached site settings, the session’s traffic source and a replay counter.
Without consent, nothing is written: the ids live in memory for one page load. Withdrawing consent deletes the _qm_* cookies.
Where data goes
Section titled “Where data goes”The script sends data only to ingest-prod.quomerce.com, the same host it loads from. It loads no third-party code.
See the Quomerce privacy policy for how Quomerce processes this data.