Skip to main content

Cookie Policy

How we use cookies and similar technologies on our website

Introduction

This starter Cookie Policy explains the two storage paths a deployed site can use. First-party storage supports the requested service, security, preferences, and the site's own acquisition and order attribution. Separately configured third-party analytics, support, or referral services follow the optional-services choice described below.

The operator of each deployment must review this template against its actual configuration and applicable law before publishing it.

First-Party Storage

A deployment can use the following storage on its own domain:

  • Session and security storage maintains signed-in sessions and helps prevent fraud or abuse.
  • Optional-services preference records an explicit Allow all or Only essential choice for up to 180 days, so the site can apply that choice on later visits.
  • First-touch attribution uses a signed, HttpOnly, SameSite=Lax cookie for up to 30 days. It contains an anonymous identifier plus a validated first marketing touch and affiliate fallback. Raw advertising click identifiers are retained only in the site's database and are not placed in this cookie.
  • Product preferences can remember settings such as language or display choices.

The first-party attribution record is used for the site's internal acquisition and order records in every region, including Europe. It is separate from optional third-party services, so choosing Only essential, withdrawing an optional-services choice, or enabling Global Privacy Control does not erase or stop this first-party record. It does not by itself authorize a third-party script.

Optional Third-Party Services

Only services actually configured by a deployment apply. They can include external analytics, customer support, or referral integrations.

  • In the EEA, United Kingdom, Switzerland, or when the visitor's region cannot be determined, these services wait for Allow all.
  • In other regions, they can follow the deployment's regional default until the visitor makes an explicit choice.
  • An explicit Only essential choice or a later withdrawal prevents these optional services from loading in every region. Global Privacy Control prevents them only outside the consent-gated regions. In the EEA, United Kingdom, Switzerland, or when the visitor's region is unknown, the current site choice controls loading, so Allow all permits configured optional services even when GPC is enabled.
  • A self-hosted, cookieless Umami script can run outside this gate only when it is served from the site's own origin. Cross-origin or protocol-relative Umami URLs fail closed.

The site does not present an optional-services card when no gated service is configured.

Managing Your Choice

Where available, Cookie settings lets you reopen the card and change the optional-services choice without disabling the site's first-party acquisition or order records.

Your browser can also delete or block storage. Blocking session or preference storage may prevent some requested features from working. Deleting the first-party attribution cookie removes that browser copy, but does not rewrite attribution already preserved with an account, checkout, or order.

We may update this Cookie Policy when the deployed storage or service configuration changes. The current version and date will be posted on this page.

Contact Us

If you have questions about this Cookie Policy, please contact us.