Cookie Notice
The cookies and similar technologies this store uses, and how to control them.
Last updated: 2026-09-11
Template policy — review before launch
This page is standard-practice scaffolding, not legal advice. It has not been reviewed by a lawyer, and it still contains placeholders that the store operator must replace with their own verified details.
Store operator: replace the placeholders, have this page reviewed by your own counsel, then set review_status to "reviewed" in its source file to remove this notice.
This notice explains the cookies and similar technologies used by this store, operated by the merchant identified on the contact page (the store operator, we, us). Read it together with our Privacy Policy.
Cookies, browser local storage, and session storage can keep information on your device. The inventory below describes the built-in functions; optional providers and their actual settings must also be checked before publication.
Shopping, account, and preference cookies
-
ecnext_privacystores your three optional categories, notice version and choice time for 180 days. It is necessary to remember a privacy choice. Clearing it, expiry or a notice-version change returns optional features to off. This record is held in this browser, not a server-side consent history. -
ecnext_cartlinks this browser to a guest shopping bag. It contains a random identifier whose one-way hash is stored on the server. Page scripts cannot read thisHttpOnlycookie. Its configured lifetime is 30 days. This cookie is separate from the browser's local shopping-bag copy. -
better-auth.session_tokenand related authentication cookies support sessions, sign-in, verification, and security checks. Some can be created during an authentication flow before sign-in completes. Names may include a secure prefix in HTTPS deployments. Lifetimes depend on the cookie and authentication settings; signing out invalidates the active session, but does not delete every kind of site data. -
ecnext_storefront_contextremembers a chosen personal or company purchasing context for 84 days. It is a preference, not proof of company membership: the server checks access before applying company pricing. -
ecnext_invite_intentcarries a short-lived invitation intent during an invitation-gated sign-up flow for 15 minutes. -
sidebar_stateremembers whether an account or administration sidebar is expanded for 7 days.
The language is carried in the page address, such as /en/… or /zh/…; the built-in locale routing does not set a language-detection cookie. Whether a storage use needs consent or falls within an applicable exception depends on its purpose, configuration, and the visitor's market. A preference is not automatically exempt simply because it is first-party.
Browser local storage and session storage
- Shopping bag and synchronization records (
ecnext.storefront.cart.*and related adoption records) keep device copies, separate guest and account contexts, and recover interrupted synchronization. The server holds the persistent shopping bag after synchronization. - Saved products (
ecnext.storefront.saved-products.v1:*) retain up to 100 selected products per browser context. They are device storage, not a promise of cross-device account synchronization. - Recently viewed products (
ecnext:recent-products:v1:*) retain up to 8 product records per browser context only after you allow browsing history. Withdrawing that choice clears these records on this device. - Checkout handoff records (
ecnext.storefront.checkout-cart-handoff.v1:*) help reconcile the shopping bag with a submitted order. Pending checkout records (ecnext.storefront.pending-checkout.v2:*) use session storage to retry an uncertain submission without creating another order; they can include the submitted contact and delivery details. - Theme and interface preferences use local storage where those features are available.
Local storage has no general automatic expiry in this application; individual actions can replace or remove records, and you can clear them through your browser. Session storage normally lasts for a browsing tab's session and may be restored by the browser. Signing out does not erase all guest, saved-product, recent-product, or other device records. Clear site data when using a shared device. Clearing device data does not delete orders or other records already held on the server.
Optional analytics, chat, and payment providers
The operator must publish an inventory of the integrations actually enabled, their purposes, providers, storage lifetimes, and any required choices.
- Google Analytics 4: a configured measurement ID loads Google's analytics script only after you allow analytics. Its cookies, identifiers, and retention depend on the provider and configuration.
- Plausible or a custom analytics script: the administrator can configure the script URL. The store cannot guarantee that every configured script is cookieless; verify the actual implementation and provider notice.
- Crisp or Tawk.to live chat: an enabled integration loads only after you allow external services; it can then load even if you never open the chat window. It may contact the provider and use cookies or local storage before you start a conversation.
- Hosted payment pages: when you proceed to a payment provider, its page may use additional technologies for payment security and fraud prevention. Consult the provider notice shown there.
The Privacy choices control offers equally accessible rejection and acceptance, as well as separate analytics, external-service and browsing-history choices. External services also cover the optional Google sign-in prompt. Normal sign-in, shopping and account support tickets do not require optional consent. A Global Privacy Control signal disables analytics and optional external services even if previously allowed.
Your controls
Use Privacy choices at the bottom of storefront pages to change or withdraw a choice. Withdrawal reloads the page to stop running integrations and removes known first-party provider cookies and storage. Third-party-domain storage may also need to be cleared in browser settings; withdrawal does not erase data already received by a provider.
Your browser can display, block, and delete cookies and clear local or session storage. Blocking shopping or authentication storage may disrupt shopping-bag recovery or sign-in. Browser script blocking can also prevent optional integrations from loading. Merely leaving a live-chat window closed does not prevent its script or storage.
Contact the operator through the contact page for privacy requests or questions about enabled integrations. Browser controls alone do not replace any choices the operator is required to offer.
Changes and contact
We update this notice when the storage uses or integrations change. The date above identifies this text's latest update. See the Privacy Policy for information about records held beyond your device.
A submitted withdrawal notice may be retained in session storage solely to retry an interrupted submission with the same request key. It is removed after confirmation or when the browser session ends.