Cookie Policy

Last updated: July 2026.

Essential cart cookie

When you add a product, the site creates the fb_cart cookie so it can retrieve the same cart on later pages and visits. It contains a random cart identifier, not the product choices themselves. It is HTTP-only, Secure in production, SameSite=Lax, available across the site and expires after 30 days. The store cannot provide a persistent guest cart without it.

Essential account cookies

If you sign in, Better Auth uses a session cookie named better-auth.session_token or its Secure-prefixed production equivalent. It is HTTP-only and is used to authenticate the requested account and protect account or administration pages. Related short-lived authentication cookies may also be used during a sign-in or verification flow. These cookies are not used for advertising.

Necessary preference storage

The site stores fb_cookie_consent_v1 in local browser storage—not in a cookie—when storage is available. It contains the consent version, whether optional analytics is enabled and the time the choice was updated. It is necessary to remember your choice, expires after 180 days and is not sent to our server; you can replace it at any time through Privacy choices or clear it in your browser.

Optional analytics

After you opt in, the site may send allow-listed aggregate events to its same-origin analytics endpoint: pages, product and product-list views, product-list selections, cart and checkout steps, completed purchases, search length and result count, and newsletter or contact conversion. No third-party analytics script, marketing tag or pixel is loaded by this implementation. Names, emails, addresses, payment information, free-text messages, personalization values and raw search terms are not part of these events.

Signals and withdrawal

Do Not Track and Global Privacy Control override optional analytics. You can accept or refuse optional analytics when the dialog appears, or replace a previous choice at any time through Privacy choices. Withdrawing stops future analytics requests; it does not retroactively alter aggregate records already retained under the 90-day schedule.

Provider changes

A dataLayer can be enabled only after a separate approved provider configuration. It does not load a provider by itself. Any future provider must be assessed and reflected in this policy before it is activated.

Manage your choice

Read our Privacy Policy for information about other personal data processing.