Cookie Policy

Last updated: 12 July 2026

1) What are cookies?

Cookies and equivalent technologies (e.g. pixels or SDKs) are small files or identifiers stored on your device to enable technical functions, remember preferences, carry out aggregated measurements and, where applicable, personalise advertising. The installation and use of non-essential cookies require your informed consent in accordance with Article 22.2 of the LSSI and Article 5(3) of the ePrivacy Directive.

2) Who is the data controller?

The data controller responsible for processing data in connection with cookies on this website is identified in our Legal Notice and Privacy Policy. You will also find information there about your rights and the contact details of the Data Protection Officer, where applicable.

3) How do we obtain your consent?

We display a consent banner (Consent Management Platform – CMP) provided by Consentmo, which allows you to Accept all, Reject all or Save preferences by category (Necessary, Preferences, Statistics and Marketing). The accept and reject options are presented with the same prominence and format, with no pre-ticked boxes, and we do not use “cookie walls” that prevent access unless cookies are accepted (except where permitted by the AEPD).

4) Categories of cookies we use

  • Necessary (technical): These allow the website and checkout to function (e.g. fraud-prevention security, load balancing and remembering the contents of your basket). They do not require consent. On Shopify, they may include technologies such as hCaptcha to protect forms and processes. These cookies are essential for the website to function correctly and enable key features such as security, browsing and access to secure areas. They cannot be disabled.
  • Preferences: These cookies remember your choices, such as language preferences or login details, to provide a more personalised experience. They are not essential, but not using them may result in a poorer shopping experience.
  • Statistics (analytics): By collecting anonymous data, these cookies help us understand how visitors interact with the website, allowing us to improve performance and the user experience (e.g. Google Analytics 4).
  • Marketing: This includes cookies and other tracking technologies used for advertising, remarketing, audience creation, campaign measurement and attribution. We currently use advertising technologies from Google, Meta and Pinterest, including, depending on the provider and the applicable settings, Google Ads, Meta Pixel, the Meta Conversions API and Pinterest Tag. These technologies may record information about your interaction with our shop, such as pages and products viewed, searches, products added to the basket, commencement of the checkout process and purchases. Where required under applicable law, these technologies and the associated data processing will only be used with your consent. We may add other advertising platforms, such as TikTok, in the future, updating this Policy and our consent settings where appropriate.

Important: until you provide consent for non-essential categories, the relevant technologies are blocked, restricted or adjusted in accordance with the consent settings and the features technically available for each provider. In Google’s case, certain tags may operate in a cookieless measurement mode through Consent Mode v2. Please see the following sections for specific information about Google and Meta.

5) Which third parties are involved?

In addition to our own cookies, we may use third-party cookies and technologies:

  • Google (Analytics 4 and Google Ads): measurement and, where applicable, personalisation/remarketing. Managed through Google Tag Manager (GTM) and Google Consent Mode v2. google.com
  • Judge.me (reviews): may use cookies/identifiers to display widgets and link reviews. Judge.me
  • Zing Loyalty (loyalty programme): may use cookies/identifiers for points, referrals and the customer experience. zingloyalty.com
  • Back in Stock | Preorder (Doran): manages restock/pre-order notifications and may use cookies/identifiers associated with its features. doran.app
  • hCaptcha (Shopify anti-bot security): necessary technology used to protect forms (login, registration and contact) and prevent abuse. hcaptcha.com
  • Meta Platforms (Facebook and Instagram): we use Shopify’s Facebook & Instagram integration to synchronise our product catalogue and, where applicable in accordance with your consent, for measurement, attribution, audience creation, remarketing and personalised advertising. The integration may use Meta Pixel, the Meta Conversions API and other compatible advertising technologies. These technologies may process browsing and conversion events and, where applicable, certain identifiers and personal data intended to improve matching between activity carried out in our shop and users of Meta technologies. Technologies and processing activities subject to consent are managed through your privacy preferences. facebook.com
  • TikTok: we may use its measurement and advertising technologies in the future. If non-essential technologies are activated, they will be subject to the relevant consent and the information available in this Policy and the preferences panel will be updated. tiktok.com
  • Pinterest: We use Pinterest as a marketing channel, including synchronising our product catalogue and using Pinterest Tag for event measurement, conversion attribution, audience creation, remarketing and advertising. Non-essential tracking technologies are subject to your Marketing consent. pinterest.com

In the cookie table inserted below (generated by Consentmo), you will find the provider, purpose, category and expiry period for each cookie.


Name Description Category Provider Duration
cookieconsent_status This cookie is associated with the Consentmo GDPR Compliance app and is used to store the customer’s consent. Necessary Consentmo 1 year
cookieconsent_preferences_disabled This cookie is associated with the Consentmo GDPR Compliance app and is used to store the customer’s consent. Necessary Consentmo 1 day
_ab Used to control when the admin bar is displayed in the shop. Necessary Shopify 1 year
_abv Maintains the collapsed state of the admin bar. Necessary Shopify 1 year
_checkout_queue_token Used when there is a queue during checkout. Necessary Shopify 1 year
_identity_session Merchant authentication: primary session cookie for Identity authentication. It is the Rails session cookie. It contains the SID. Necessary Shopify 2 years
_master_udr Permanent device identifier. Necessary Shopify Session
_merchant_essential Contains information essential for merchant areas to function correctly, such as the admin area. Necessary Shopify 1 year
_pay_session Rails session cookie for Shopify Pay Necessary Shopify Session
_shopify_country Used in Plus shops where currency/country is configured through GeoIP, to avoid additional searches after the initial request. Necessary Shopify 30 minutes
_shopify_essential Contains information essential for the shop to function correctly, such as session, payment and tamper-protection data. Necessary Shopify 1 year
_shopify_essential_ Contains an opaque token used to identify a device for all essential purposes. Necessary Shopify 1 year
_shopify_test Used to test cookie capabilities on the client. Necessary Shopify 1 minute
_storefront_u Used to facilitate updates to the customer’s account information. Necessary Shopify 1 minute
_tracking_consent Used to store the user’s preferences where the merchant has configured privacy rules. Necessary Shopify 1 year
auth_state_* Stores the authentication state before redirecting the customer to third parties. Necessary Shopify 25 minutes
cart Contains information relating to the user’s basket. Necessary Shopify 2 weeks
cart_currency Used after checkout has been completed to start a new basket in the same currency. Necessary Shopify 2 weeks
checkout Used during checkout to identify the user. Necessary Shopify 21 days
checkout_token Used during checkout to identify the user. Necessary Shopify Session
customer_account_locale Used to track the customer account language when redirecting from the shop or checkout. Necessary Shopify 1 year
discount_code Stores a discount code received through a URL for the next checkout. Necessary Shopify Session
hide_shopify_pay_for_checkout Set when a shopper closes the Shop Pay login modal during checkout. Necessary Shopify Session
identity-state Stores a hash of the OAuth flow state between redirects. Necessary Shopify 1 day
identity_customer_account_number Stores an identifier that facilitates login between the customer account and the shop domain. Necessary Shopify 12 weeks
in_checkout_profile_preview Used to determine whether the merchant is previewing the checkout profile. Necessary Shopify Session
keep_alive Used when international redirection is enabled to determine whether this is the first request of the session. Necessary Shopify Session
localization Used to localise the basket to the correct country. Necessary Shopify 2 weeks
login_with_shop_finalize Used to facilitate login with Shop. Necessary Shopify 5 minutes
master_device_id Merchant authentication: permanent device identifier, public version. Necessary Shopify 1 year
order Enables access to the shopper’s order details page data. Necessary Shopify 3 weeks
profile_preview_token Used to preview checkout customisations. Necessary Shopify 5 minutes
shop_pay_accelerated Indicates whether a shopper is eligible for accelerated checkout with Shop Pay. Necessary Shopify 1 year
shopify_pay Used to log in to Shop Pay when the shopper returns to checkout in the same shop. Necessary Shopify 1 year
shopify_pay_redirect Speeds up checkout where the shopper has a Shop Pay account. Necessary Shopify 1 year
skip_shop_pay Disables Shop Pay as a payment method during checkout. Necessary Shopify 1 year
storefront_digest Stores a digest of the shop password, allowing the merchant to preview the password-protected shop. Necessary Shopify 1 year
theme Used to determine the shop theme. Necessary Shopify 1 week
user Used in connection with logging in to Shop. Necessary Shopify 1 year
user_cross_site Used in connection with logging in to Shop. Necessary Shopify 1 year
_landing_page Captures the visitor’s landing page when they arrive from other websites. Statistics Shopify 2 weeks
_merchant_analytics Contains analytics data for the merchant session. Statistics Shopify 1 year
_orig_referrer Allows the merchant to identify where visitors come from. Statistics Shopify 2 weeks
_shopify_analytics Contains analytics data for shopper interfaces such as the shop or checkout. Statistics Shopify 1 year
_shopify_ga Contains Google Analytics parameters that enable cross-domain measurement. Statistics Shopify Session
_shopify_s Used to identify a session/browser and shop combination. Valid for 30 minutes from the last use. Statistics Shopify 30 minutes
_shopify_y Shopify analytics. Statistics Shopify 1 year
shop_analytics Contains shopper information required for analytics in Shop. Statistics Shopify 1 year
_shopify_marketing Contains marketing data for shopper interfaces such as the shop or checkout. Marketing Shopify 1 year
shopify_override_user_locale Used as a mechanism to set the user’s language in the admin area. Preferences Shopify 1 year

6) Google measurement and tags with Consent Mode v2

We have enabled Google Consent Mode v2. This means that Google Ads/Analytics adjusts its behaviour according to your choice: if you refuse consent for advertising and/or analytics categories, cookieless pings are sent and personalised advertising is not enabled until you provide permission. The new ad_user_data and ad_personalization parameters are only granted when you accept Marketing; without them, there is no remarketing or advertising personalisation.

7) Meta measurement and advertising technologies

We use Shopify’s official Facebook & Instagram integration to synchronise our product catalogue with Meta and, where applicable in accordance with your consent, to measure activity associated with our advertising campaigns and improve their attribution and effectiveness.

The integration may use Meta Pixel, which records certain events from the browser, and the Meta Conversions API, which allows certain events and data to be transmitted from Shopify’s systems to Meta through server-to-server communications.

Depending on your interaction with the shop and the applicable settings, events such as page and product views, searches, products added to or removed from the basket, commencement of the checkout process and purchases may be processed. Online and technical identifiers, information relating to products and transactions and, where applicable, certain available personal data, such as your name, email address, telephone number, address or location information, may also be processed to improve matching, measurement and advertising attribution.

The use of the Conversions API does not mean that these technologies fall outside data protection rules or the applicable privacy preferences. Where processing requires consent, the transmission and use of data for these purposes will comply with the choice made through our consent management system.

You may withdraw or change your consent at any time using the “Manage cookies” option available on the website. Withdrawing your consent does not affect the lawfulness of processing carried out beforehand.

8) Managing your preferences and withdrawing consent

  • You can accept, reject or configure cookies by category from the initial consent banner. The Accept and Reject options are displayed at the same level and with the same prominence, in accordance with AEPD criteria. Spanish Data Protection Agency
  • You may change or withdraw your consent at any time using the “Manage cookies” button visible on the website, which reopens the preferences panel so that you can change your selection (for example, reject all cookies or adjust them by purpose). This permanent access ensures that withdrawing consent is as easy as giving it, as required by the AEPD guidance.
  • If, for any reason, you cannot see the button (e.g. because of blockers), you can contact us using the details provided in the Legal Notice and Privacy Policy so that we can provide alternative instructions.
  • Withdrawing your consent does not affect the lawfulness of processing based on consent before its withdrawal.

9) How can you delete cookies from your browser?

If you have already accepted cookies and wish to delete them (for example, so that our banner appears again or to reset your preferences), you can do so through your browser settings. Please note that deleting cookies may sign you out and remove saved preferences.

Google Chrome (computer)

  • Delete all cookies: Menu ⋮ → Settings → Privacy and security → Third-party cookies → See all site data and permissions → Delete all data → Delete. Google Help
  • Delete cookies from a specific website: Menu ⋮ → Settings → Privacy and security → Third-party cookies → See all site data and permissions → search for the domain → Delete.
  • By time period: Menu ⋮ → Delete browsing data → under Time range, select an option (e.g. “All time”) → tick Cookies and other site data → Delete data. Google Help

Google Chrome (Android)

  • Delete by time period: Menu ⋮ → Delete browsing data → select a time range → tick Cookies and site data → Delete data. Google Help
  • Delete cookies only from the website you are visiting: Open the website → tap the information icon to the left of the address bar → Cookies and site data → Delete. Google Help

Mozilla Firefox (computer)

  • Delete everything (cookies, site data and cache): Menu ☰ → Settings → Privacy & Security → Cookies and Site Data → Clear Data… → confirm. Mozilla Support
  • Delete cookies from a specific website: Settings → Privacy & Security → Cookies and Site Data → Manage Data… → search for the website → Remove Selected.
  • From the padlock (current website): padlock icon next to the URL → Clear Cookies and Site Data. Mozilla Support

Microsoft Edge (computer)

  • Delete all cookies: Settings and more … → Settings → Privacy, search and services → Clear browsing data → Choose what to clear → tick Cookies and other site data → Clear now. Microsoft Support
  • Delete cookies from a specific website: Settings → Cookies / Cookies and site data → See all cookies and site data → search for the domain → Delete. Microsoft Support

Apple Safari (macOS)

  • Delete cookies from one or more websites, or all cookies: Safari → Preferences/Settings → Privacy → Manage Website Data… → select websites → Remove or Remove All. Apple Help Library

Apple Safari (iPhone / iPad)

  • Clear history, cache and cookies: Settings → Safari → Clear History and Website Data (select the time period and confirm). Apple Support
  • Delete cookies/data only (while retaining history): Settings → Safari → Advanced → Website Data → Remove All Website Data. Apple Support

Opera (computer)

  • Delete cookies and other data: Settings (Alt+P) → Privacy and security → Delete browsing data → tick Cookies and other site data → Delete data. Opera Help
  • Optional – view/delete cookies by website: Settings → Privacy and security → Site settings → Cookies and site data → See all cookies and site data (search and delete). Opera News

10) International transfers

When third-party technologies are used, certain data and identifiers may be processed outside the European Economic Area. Some providers, including technology and advertising providers such as Google, Meta and Pinterest, may process information in the United States or other countries. Where applicable, international transfers will be carried out using mechanisms recognised under data protection law, such as adequacy decisions, the EU-U.S. Data Privacy Framework for certified organisations or Standard Contractual Clauses, together with any additional measures required. For specific information about each provider and its transfer mechanisms, please consult their respective privacy policies.

11) Retention of preferences and consent records

  • The AEPD considers it good practice not to retain the validity of cookie consent for more than 24 months, while storing the user’s selection during that period.
  • Consent records (evidence of what you accepted or rejected) are retained by our CMP (Consentmo) for 12 months from the date they are collected, after which they are automatically deleted. We may back them up in our systems where necessary for compliance purposes, up to a maximum of 24 months.

12) Essential Shopify cookies and hCaptcha

Our platform (Shopify) uses its own technical cookies and hCaptcha protection on forms and critical processes to prevent abuse and fraud. These technologies are considered necessary to provide the service.

13) Changes to the Cookie Policy

We will update this Policy and the cookie table whenever we introduce new features, change providers or change the purposes for which cookies are used. We will inform you of relevant changes in accordance with applicable law.

14) How to contact us

For any questions about this Cookie Policy or to exercise your rights, please refer to the contact details provided in our Legal Notice and Privacy Policy.