Cookie Policy
Last updated: August 2026
1. What Are Cookies
Cookies are small text files stored on your device when you visit a website. They are used to keep you logged in, remember your preferences, process payments, secure the site, and – with your consent – to analyse site usage and personalise advertising.
2. Cookies We Use
2.1 Strictly Necessary
These cookies are required for the platform to function or to keep it secure. They are set automatically and cannot be disabled.
| Cookie | Purpose | Duration |
|---|---|---|
wordpress_logged_in_* | Keeps you logged into your account | Session / 2 weeks |
wordpress_sec_* | Security for admin area | Session |
woocommerce_cart_hash | Remembers cart contents | Session |
woocommerce_session_* | Stores session data | 2 days |
wp-settings-* | Display preferences | 1 year |
wc_fragments_* | Keeps cart data consistent | Session |
wp_woocommerce_session_* | Maintains checkout session | 2 days |
moove_gdpr_popup | Stores your cookie consent choice | 1 year |
2.2 Spam and Abuse Protection (Cloudflare Turnstile)
We use Cloudflare Turnstile to protect our forms, login pages, and checkout against spam and automated abuse. When a Turnstile check runs, the widget is loaded from Cloudflare and the following cookies are set by Cloudflare as a third party in the context of that check. They are strictly necessary for the protection you request when submitting a form or signing in.
| Cookie | Provider | Purpose | Duration |
|---|---|---|---|
__cf_bm | Cloudflare (challenges.cloudflare.com) | Distinguishes automated traffic from human visitors during the Turnstile check | 30 minutes |
cf_clearance | Cloudflare (challenges.cloudflare.com) | Records that a Turnstile challenge was passed, so it is not repeated unnecessarily | Varies |
Cloudflare may process this data outside the EU under the European Commission's Standard Contractual Clauses. See our Privacy Policy for details.
2.3 Payment (Stripe)
Stripe sets the following cookies when a checkout page loads, so that it can process your payment securely and assess the risk of fraudulent transactions. They are strictly necessary for the payment service you are requesting and are set regardless of whether you use Stripe Link.
| Cookie | Provider | Purpose | Duration |
|---|---|---|---|
__stripe_mid | Stripe | Fraud prevention; helps Stripe assess the risk of a transaction | 1 year |
__stripe_sid | Stripe | Fraud prevention within the current checkout session | 30 minutes |
Stripe may set further cookies or storage within its own payment frames, on its own domain. That processing is described in Stripe's Cookie Policy. If you choose to sign up for Stripe Link, Stripe processes your data as an independent controller under the Link Privacy Policy.
2.4 Affiliate Tracking (consent required)
Where our Affiliate Program is active and you arrive through an affiliate link, AffiliateWP sets a cookie that is used solely to attribute a possible purchase to the referring affiliate and to calculate the corresponding commission. These cookies are not used for behavioural advertising or cross-site tracking. Because their purpose is commercial, they fall under the marketing category of our cookie banner and are set only after you accept marketing cookies. If you do not accept marketing cookies, no affiliate cookie is set and no referral is recorded.
| Cookie | Provider | Purpose | Duration |
|---|---|---|---|
affwp_ref_visit_id | AffiliateWP | Links your visit to a referring affiliate | 30 days |
affwp_ref | AffiliateWP | Stores the referring affiliate identifier | 30 days |
2.5 Analytics (consent required)
Set only after you accept analytics cookies.
| Cookie | Provider | Purpose | Duration |
|---|---|---|---|
_ga | Google Analytics 4 | Distinguishes unique visitors | 2 years |
_ga_* | Google Analytics 4 | Session tracking | 2 years |
_gtm_* | Google Tag Manager | Tag management | Session |
Google Analytics data may be processed outside the EU under the European Commission's Standard Contractual Clauses. Google Privacy Policy.
Order attribution. WooCommerce records which channel an order came from, such as a search engine, a referring site, or a direct visit. This is recorded on the order and is used only by us; the data is not shared with a third party and no profile is built across other websites. These cookies are set only after you accept analytics cookies.
| Cookie | Provider | Purpose | Duration |
|---|---|---|---|
sbjs_first, sbjs_first_add | WooCommerce | Records the first traffic source of your visit | Session |
sbjs_current, sbjs_current_add | WooCommerce | Records the most recent traffic source | Session |
sbjs_udata | WooCommerce | Stores basic browser information for attribution | Session |
sbjs_migrations | WooCommerce | Internal versioning of the attribution data | Session |
sbjs_session | WooCommerce | Links page views within one visit | 1 day |
2.6 Marketing & Retargeting (consent required)
Set only after you accept marketing cookies. This category also covers the affiliate cookies described in section 2.4.
| Cookie | Provider | Purpose | Duration |
|---|---|---|---|
_fbp | Meta Pixel | Tracks visits for ad measurement and retargeting | 3 months |
_fbc | Meta Pixel | Stores click identifier from Meta ads | 3 months |
pys_first_visit | PixelYourSite | Records whether this is your first visit | 7 days |
pysTrafficSource, last_pysTrafficSource | PixelYourSite | Records the traffic source for ad measurement | 7 days |
pys_landing_page, last_pys_landing_page | PixelYourSite | Records the page you arrived on | 7 days |
pys_start_session | PixelYourSite | Marks the start of a visit | Session |
pys_session_limit | PixelYourSite | Limits how often session events are sent | 1 day |
pys_advanced_form_data | PixelYourSite | Stores form and order data for event matching | Session |
pys_event_referrer | PixelYourSite | Records the internal page you came from within a visit | Session |
pbid | PixelYourSite | Identifies your browser across visits for ad measurement | About 180 days |
Meta data may be processed outside the EU under the European Commission's Standard Contractual Clauses. For the Meta Pixel, Colrs.io and Meta act as joint controllers; this is explained in our Privacy Policy. Meta Privacy Policy.
2.7 Newsletter Form (Brevo)
If you interact with an embedded newsletter form powered by Brevo, Brevo may load Google reCAPTCHA to prevent spam. reCAPTCHA can set Google cookies, subject to the Google Privacy Policy. This applies only to the Brevo form itself. Brevo does not set tracking cookies for the delivery of our transactional emails.
3. Cookie Consent
When you first visit Colrs.io, our cookie banner (powered by Moove GDPR Cookie Compliance) asks for your consent to analytics and marketing cookies. Google Consent Mode v2 is integrated, which means Google's tools respect your consent choice automatically.
You can change your preferences at any time via the Cookie Settings link in the footer.
No analytics or marketing cookies are placed before you give consent, except cookies that are strictly necessary for the service you request.
Strictly necessary cookies are always active.
4. Managing Cookies via Your Browser
You can manage or delete cookies through your browser settings. Disabling strictly necessary cookies may prevent login, checkout, or purchases from working correctly.
Most browsers allow you to view, delete, or block cookies. Visit your browser's help pages for instructions.
5. Contact
For questions about our use of cookies, contact us at privacy@colrs.io. For information about how we process personal data, please see our Privacy Policy.