Skip to content

URLs, requests and cookies

Every URL is cleaned in the browser before it is sent:

  • Only the query parameters in Analytics settings → Kept URL parameters stay. The default list is utm_*, gclid, fbclid and msclkid. Wildcards like utm_* work. Every other parameter is removed.
  • Email- and phone-like strings in the path are masked.

So https://example.com/search?q=rtx&utm_source=google&email=jan@example.com is stored as https://example.com/search?utm_source=google.

Search terms are not lost: the search page’s term is read separately (and masked) when a search is detected.

If you use other campaign parameters, such as ref or aff_id, add them to the list.

The script watches fetch and XMLHttpRequest calls:

Request Recorded?
Failed, or status 400 and above, on any host Yes, as a network error
Successful, to your shop’s own host or its subdomains Yes, as a network request, for timing
Successful, to any other host (analytics, ads, payment widgets…) No

“Your shop’s own host” is the page’s host without www., and every subdomain of it. On www.example.com, requests to example.com, www.example.com and api.example.com are kept; requests to google-analytics.com are not. For each request, only the method, host, path (with emails and phone numbers masked), status and duration are stored. Never the query string, bodies or headers.

With consent (or consent set to Not required), the script stores:

Name Kind Contents Lifetime
_qm_sid First-party cookie Session id (a random UUID) 30 minutes, rolling, at most 24 hours
_qm_vid First-party cookie Visitor id (a random UUID) 13 months

Both cookies are SameSite=Lax. Set cookieDomain in init to share them across subdomains.

localStorage and sessionStorage hold the cached site settings, the session’s traffic source and a replay counter.

Without consent, nothing is written: the ids live in memory for one page load. Withdrawing consent deletes the _qm_* cookies.

The script sends data only to ingest-prod.quomerce.com, the same host it loads from. It loads no third-party code.

See the Quomerce privacy policy for how Quomerce processes this data.