Current setting
The public storefront does not set its own HTTP cookies. It uses the four first-party storage entries listed below. There is no advertising, cross-site advertising tracker, fingerprinting, social-media pixel or embedded marketing form.
Google Analytics is available as an optional service and remains completely unloaded until you accept analytics. Because optional analytics can create identifiers in your browser, a consent choice is shown. Rejecting analytics does not limit the shop.
The necessary-service exception is set out in section 165(3) TKG 2021. Optional Google Analytics is instead based on your consent under section 165(3) TKG 2021 and Article 6(1)(a) GDPR.
This notice covers cookies and comparable access to a device, including localStorage and sessionStorage. The related processing of personal data is explained in the privacy information.
Optional Google Analytics
After you select Accept analytics, the storefront loads Google Analytics 4 under measurement ID G-W601RG38PN. It records page views and selected shop events such as viewing a work, adding or removing it from the bag, viewing the bag, starting checkout and a purchase confirmed by the shop’s signed server status.
The integration keeps Google Signals, advertising storage, advertising user data and advertising personalisation disabled. It never sends names, email addresses, postal addresses, payment details, confirmation tokens or complete order-status URLs. URL parameters are removed before collection except the standard utm_* campaign parameters.
_ga and _ga_*
- Technology
- First-party HTTP cookies created by Google Analytics only after consent.
- Category
- Optional audience and ecommerce analytics.
- Contents
- Pseudonymous browser, user and session identifiers. They contain no customer name or email address.
- Purpose
- Distinguishes consenting visits and connects page and shop events into aggregate reports and funnels.
- Duration
- Up to 2 years, subject to browser limits and earlier deletion when you reject analytics or clear site data.
Exact storage register
simon-simons-cart
- Technology
- First-party localStorage
- Category
- Necessary shopping function
- When used
- Read when the bag interface opens; written only when you add or remove a work or clear the bag.
- Contents
- Storage format version, last update time, artwork SKU and quantity. It contains no name, address, email or authoritative price.
- Purpose
- Keeps the shopping bag available while you move between pages.
- Duration
- Until you remove the items or clear this site’s browser data. No automatic expiry is currently applied.
simon-simons-theme
- Technology
- First-party localStorage
- Category
- User-requested preference
- When used
- Written only after you use the Light/Dark control.
- Contents
- The value “light” or “dark”.
- Purpose
- Remembers the appearance you explicitly selected.
- Duration
- Until you choose the other appearance or clear this site’s browser data.
simon-simons-checkout-attempt
- Technology
- First-party sessionStorage
- Category
- Necessary checkout protection
- When used
- Created only when you select Continue to secure checkout.
- Contents
- A random attempt UUID and a signature of the selected SKUs, quantities and any applied welcome code.
- Purpose
- Prevents repeated clicks or retries from creating duplicate checkout sessions.
- Duration
- For the current browser tab/session. A browser that restores a session may retain it until that restored session ends.
simon-simons-analytics-consent
- Technology
- First-party localStorage
- Category
- Necessary consent record
- When used
- Written only after you accept or reject optional Google Analytics.
- Contents
- The cookie-policy version, the choice “granted” or “denied”, and the time of that choice.
- Purpose
- Remembers and proves your analytics choice so that the site does not ask on every page and never loads analytics contrary to that choice.
- Duration
- Up to 12 months, until the policy version changes, or until you change the choice or clear this site’s browser data.
Cloudflare
Cloudflare delivers and protects the site. An ordinary public storefront response does not set an application cookie. If Cloudflare has to present an abuse or security challenge, it may use limited security cookies such as cf_clearance or __cf_bm to remember the result and distinguish legitimate traffic. These are conditional, not used by the studio for advertising, and described in Cloudflare’s cookie documentation.
Cloudflare may also send Network Error Logging instructions that a supporting browser retains temporarily so failure-only diagnostics can be reported. This is not an HTTP cookie or a storefront identifier. Its purpose is connection reliability; Cloudflare documents the process in its Network Error Logging notice.
Cloudflare Turnstile is disabled and its browser script is not loaded in the current storefront. It will not be activated without a renewed technical and legal assessment; if its use requires consent, it must remain blocked until that consent is given.
External services
Adobe Fonts: Licensed fonts are requested from Adobe when a page is displayed. Adobe states that its web-font service does not set or use cookies to serve fonts. The request still supplies technical delivery and project information; details are in the Adobe Fonts privacy notice and this site’s privacy information.
Stripe: Stripe is not embedded in the storefront. Only after you select Continue to secure checkout does the shop redirect the top-level browser to Stripe’s hosted payment page. Stripe may then use cookies and similar technology on its own domain for checkout, security, fraud prevention and the choices described in Stripe’s Cookies Policy.
Google Analytics: Google’s browser script is optional and blocked until analytics consent. When accepted, Google Ireland Limited processes the analytics data described above; transfers to the United States may occur under the EU-U.S. Data Privacy Framework and Standard Contractual Clauses. See Google’s Privacy Policy.
Brevo and sevdesk: Their email and invoice integrations run server to server. No Brevo or sevdesk browser script, pixel or embedded form is loaded by the storefront.
Private operator portal: The separate, non-customer operator subdomain uses Cloudflare Access cookies such as CF_Authorization and CF_AppSession solely to authenticate the authorised operator and protect customer data.
Your controls
You can remove the bag entry through the bag interface and change the theme through the Light/Dark control. Your browser’s site-data settings can delete all four entries. Deleting simon-simons-cart empties the bag; deleting simon-simons-theme restores the default appearance; closing the tab or browser session normally removes simon-simons-checkout-attempt.
Select Cookie settings in the footer at any time to accept or reject analytics. Rejecting updates simon-simons-analytics-consent, tells an already loaded Google tag to stop analytics storage and removes the Google Analytics cookies visible to the storefront. You can also clear all site data in your browser. Newsletter consent is separate and can be withdrawn through the unsubscribe link in every studio email.
Future changes
Before advertising, social embeds, another analytics provider or any other non-necessary device access is introduced, it must be blocked by default and subjected to a renewed inventory and legal assessment. Where consent is required, Reject and Accept must be equally easy, optional categories must start off, and withdrawal must remain available at any time.
This notice will be updated before such technology is activated. Questions can be sent to mail@simon-simons.com.
Effective: 24 July 2026 · Version: cookie-storage-2026-07-24-v1