Cookie policy
Last updated on
Short version: the shop runs on a handful of necessary cookies. We only measure for advertising if you say yes in the cookie banner, and you can undo that choice at any time.
Version 3 · 3 October 2026
Why you see a cookie banner
To measure whether an ad on Facebook, Instagram or Google leads to an order, we use two scripts: the Meta pixel and the Google Ads tag. They set cookies on your device and send data about your visit to Meta and Google. The shop does not need that in order to work, so it is only allowed with your consent.
That is why you get a question with two buttons that look exactly the same: Decline and Allow. The question says straight away who is involved (Meta and Google), that they also use your visit for their own ads, that everything works without it and where to change your choice later. As long as you have not chosen, neither script loads, and after “Decline” it stays that way. The shop works fully either way: no feature depends on your choice.
In the studio the question sits in a row under the top bar: on a large screen right away, on a phone as soon as something is on your garment, so it never pushes the prompt field away. You can dismiss it there without choosing; then nothing is measured, and we ask again as soon as you open a page outside the studio or reload the studio.
A choice applies to the question as it was asked at the time. If the question changes materially — a party or a purpose added — we ask again; a “Decline” stays in place.
What always runs, even without consent
Three things: a visitor counter that puts nothing on your device, a count per ad, and the cookies and storage the shop needs in order to work.
With our host’s visitor counter (Vercel) we count how many people visit the shop, which pages they look at and which steps they take: that a size was chosen or something went into the basket, never what you typed or designed. The counter puts nothing on your device: no cookie and no storage in your browser. Visitors are told apart by a code that is calculated from the request itself and expires after 24 hours, so a day later it no longer recognises you. What we see are numbers, not people. It gets the address of each page without what you typed, without the number of your payment and without the click code Meta or Google attaches to an ad link. That is why no consent is required for it — and why it is not in the table below, as there is nothing to place.
If you arrive through one of our ad links, our own server counts that too: the name of the campaign and of the ad that we put in the link ourselves, the page and the day — without the time, without a cookie, without a number and without an IP address. The page then keeps those names in its own memory, not in a cookie or in your browser’s storage. They only go to our server if you choose “Allow” (see below).
What we set ourselves
Below is everything we ourselves put on your device — cookies as well as what stays in your browser without being called a cookie. The law makes no distinction there, so neither does this list.
| Name | What for | Retention |
|---|---|---|
iw_visitor | A random number by which the shop recognises your browser. We use it to count your free designs and to keep your designs, your credit, your basket and your orders tied to you. No name or profile. With your consent we also keep with it which ad you came from and what you did next (see below). Not readable by scripts in your browser. | 1 year |
iw_locale | Remembers which language you’re viewing the site in, so you don’t have to choose again on every visit. Contains only “nl”, “en” or “fr”. | 1 year |
iw_consent | Remembers what you chose in the cookie question (allow or decline), for which version of the question and when. Without this cookie we would have to ask you again on every page. It is only there once you have chosen. | 6 months |
iw_account | Only if you log in: keeps you logged in after you clicked the link in the login email. Contains your account number with a signature underneath, not your email address. Not readable by scripts in your browser. | 30 days, or until you log out |
iw_studio_, iw_studio_, iw_studio_ | Temporarily keep what you’re working on in the studio in your own browser: the layers of your design, and which designs and texts you’ve already made during this visit. That way everything is still there if you reload, pop over to the basket or abandon a payment. | Until you close the tab |
iw_foto_ | If you pick a photo on the homepage, it waits here in your own browser until the studio opens and collects it. After that it is gone from here. | Until the studio collects it |
iw_prompt_ | If you type a sentence on the homepage or in the gift helper, it waits here in your own browser until the studio opens and collects it. After that it is gone from here. That way your sentence never appears in the page address. | Until the studio collects it |
iw_bedankt | Only after a payment: the number of your payment, so the thank-you page can show your order without that number being in the address. Not readable by scripts in your browser. | 1 hour |
iw_afmelden | Only when you click the unsubscribe link in an email: the token from that link, so the unsubscribe page can unsubscribe you without your email address appearing in the page address. Not readable by scripts in your browser. | 10 minutes |
iw_deel | Only when you open the link to share your design: the signature from that link, so the page works without that signature being in the address. Not readable by scripts in your browser. | 1 hour |
iw_cart | Your basket, stored in your own browser, so it’s still there when you come back later. Not a cookie but local storage. Once there is something in it, we also keep a copy on our server, under the number from iw_visitor: that lets us remind you once of a basket you left behind, if you gave us your email address. | Until you clear it or check out |
iw_test, iw_testmodus | For our own testing only: they switch off the daily limits for the administrator’s browser. An ordinary visitor never receives them, and they contain nothing about you. | 12 hours |
iw_team | For our own devices only: it says that what happens in this browser comes from our team, so it is left out of the visitor figures. An ordinary visitor never receives it, and it contains nothing about you. | 400 days |
What only loads if you choose “Allow”
Two scripts, on every page of the shop:
- the Meta pixel, from Meta (Facebook and Instagram);
- the Google Ads tag, from Google.
We use them to measure whether an ad leads to an order. This is what Meta and Google get to see in the process:
- which pages of the shop you look at (the address of the page; Google also gets the title), and which site or ad you came from;
- data about your browser and your device, such as your IP address, the type of browser and the size of your screen;
- Google only: an email address you type into a form on our site, or that is shown on the thank-you page after your order. Not the address itself, but a code derived from it (a “hash”). Whoever already knows that address — Google, if you have an account with them under it — can recognise you by it;
- Meta only: that you put something on a garment in the studio, add something to your basket and go to checkout — at checkout with the total and the number of items, nothing else;
- after an order: the amount, the currency and a number derived from your payment, so the same order is not counted twice. Not the number of the payment itself: that opens your thank-you page.
Your delivery address and your payment details are entered on Stripe’s payment page, not with us, so they do not reach Meta or Google. We don’t send your design or the description you type either.
If you had already put something on a garment or in your basket before choosing “Allow”, we report those steps to Meta once afterwards: they waited in the page’s memory, not in a cookie, and are gone as soon as you reload or close the page. If you choose “Decline”, they are never sent.
Meta and Google also process what they receive this way for their own purposes, under their own policies: that of Meta and that of Google.
In doing so they can read or set cookies on their own domains, such as facebook.com, google.com and doubleclick.net, if your browser allows it. If you are logged in to Facebook, Instagram or Google in the same browser, they can link your visit to our shop to your account that way. Which cookies those are and how long they stay is set out in Meta’s cookie policy and in Google’s.
For collecting and sending data through the Meta pixel, we and Meta are jointly responsible; what that means for your rights, and how you can also opt out of targeted ads, is set out in our privacy policy.
And with us: which ad you came from is then kept with your browser’s number (iw_visitor), together with when you first designed something, added something to your basket and went to checkout. Twelve months, and gone at once if you withdraw. It stays with us; see the privacy policy.
On our own domain, this is what then ends up on your device:
| Name | What for | Retention |
|---|---|---|
_fbp | Cookie from Meta. A random number by which the pixel recognises your browser on a later visit. At checkout our server reads this number and _fbc once, to report your purchase to Meta from the server as well; we keep them no longer than needed (seven days at most). | 90 days |
_fbc | Cookie from Meta, only if you arrived through an ad on Facebook or Instagram: remembers which ad you clicked. | 90 days |
_gcl_au | Cookie from Google. A random number by which the tag recognises your browser on a later visit. | 90 days |
_gcl_aw, _gcl_gb, _gcl_gs | Cookies from Google, only if you arrived through a Google ad: remember which ad you clicked. | 90 days |
lastExternal, lastExternal, multiFbc | Local storage from Meta: which site you came from and when, and after an ad click a copy of that click. | Until you clear them |
_gcl_ls | Local storage from Google: a counter and, after an ad click, a copy of that click. | Until you clear it |
iw_, iw_ | Our own, on the thank-you page: remember that your order has already been reported, so that reloading does not count it twice. | Until you close the tab |
Changing or withdrawing your choice
Once you have chosen, the link Change cookie choice appears at the bottom of every page and in the menu on your phone — in the studio too. Click it and your choice is cleared: the two scripts no longer load and we ask you again. Then choose “Decline”, and we won’t ask again for six months. Withdrawing is as little effort as allowing.
After you withdraw, nothing more goes to Meta or Google, and we immediately delete the cookies and storage their scripts set on our site (_fbp, _fbc, the _gcl cookies and their local storage): the numbers by which they recognised your browser are gone. What Meta and Google have already received we cannot take back: for that you can turn to them.
We remember a yes for six months too. After that we ask again.
Cookies on the payment page
When you click through to checkout, you go to the secure payment page of Stripe. Stripe sets its own cookies there to make the payment work and to prevent fraud. That happens on their page, under their policy — you’ll find it at stripe.com/privacy.
Refusing or clearing cookies
You can always block or delete cookies through your browser settings. Take care with iw_visitor: if you clear it, the shop no longer recognises your browser. Your free-design counter then starts over, and credit you bought and orders you placed without an account can no longer be found from that browser.
More information
What other data we keep and why is set out in our privacy policy.
This text is a translation of the Dutch version. Where the language versions differ in interpretation, the Dutch text prevails.
Questions about this text? Get in touch via our contact page or hello@imaginewear.eu.