Localization cookie missing Secure and SameSite attributes on HTTPS stores

The audit noise is partly a classification problem. The localization cookie stores country/language selection, so in your consent or cookie-scanning tool it should sit under strictly necessary/functional, not marketing. That stops it counting as a tracking cookie, even though the missing Secure/SameSite attributes remain a real finding for Shopify to fix. Keep the platform finding separate from theme debt: verify in DevTools > Network that the Set-Cookie response header is served with the document response, before any theme JS runs, and note that no app or Liquid change can add those flags. When you send it to Shopify Support, include the exact header value and store URL so it can be routed to the platform team.