Legal
Cookie Policy
What Cookies Are
Cookies are small text files a website stores on your device. They let a site remember things between page loads: that you are logged in, what is in your cart, which language you chose.
We also use technologies that work like cookies: local storage and session storage (data held in your browser), and pixels (tiny images that record that a page or email was opened). Where this policy says "cookies", it covers all of these.
Your Choices
When you first visit, a banner asks for your consent. Analytics cookies are not set until you accept them. Strictly necessary cookies are set regardless, because the Store cannot work without them.
You can change your mind at any time using the Cookie settings link in the footer of every page. Withdrawing consent is as easy as giving it, and takes effect immediately.
You can also control cookies in your browser: block all, block third-party only, delete on close, or be warned before one is set. Instructions are in your browser's help pages. Blocking strictly necessary cookies will break checkout and login.
Strictly Necessary
These make the Store work. They cannot be switched off and do not require consent.
| Cookie | Purpose | Duration | Provider | Type |
|---|---|---|---|---|
sb-access-token | Keeps you signed in | 1 hour | Supabase (first-party) | HTTP cookie |
sb-refresh-token | Renews your session without re-login | 30 days | Supabase (first-party) | HTTP cookie |
rove_cart | Remembers items in your cart | 30 days | Rove Setups (first-party) | HTTP cookie |
rove_csrf | Protects forms against cross-site request forgery | Session | Rove Setups (first-party) | HTTP cookie |
rove_consent | Stores your cookie choices so we stop asking | 12 months | Rove Setups (first-party) | HTTP cookie |
__stripe_mid | Fraud prevention, identifies the device across sessions | 12 months | Stripe | HTTP cookie |
__stripe_sid | Fraud prevention, identifies the current checkout session | 30 minutes | Stripe | HTTP cookie |
Stripe's cookies are set when a checkout or payment element loads. They are used to detect fraudulent payments and are necessary for us to accept card payments. See stripe.com/legal/cookies-policy.
Functional
These remember your preferences. They are set only if you accept functional cookies.
| Cookie | Purpose | Duration | Provider | Type |
|---|---|---|---|---|
rove_locale | Remembers your language (/en, /de) | 12 months | Rove Setups (first-party) | HTTP cookie |
rove_currency | Remembers your display currency | 12 months | Rove Setups (first-party) | HTTP cookie |
rove_theme | Remembers light or dark mode | 12 months | Rove Setups (first-party) | Local storage |
rove_recently_viewed | Shows products you looked at recently | 30 days | Rove Setups (first-party) | Local storage |
Rejecting these means the Store will not remember your language or currency between visits.
Analytics
These help us see which pages and products people use, where they drop off, and what to fix. They are set only after you consent.
| Cookie | Purpose | Duration | Provider | Type |
|---|---|---|---|---|
_ga | Distinguishes unique visitors | 2 years | Google Analytics 4 | HTTP cookie |
_ga_XJL9F46PLG | Maintains the analytics session state | 2 years | Google Analytics 4 | HTTP cookie |
These tags load through Google's gtag.js (not Google Tag Manager). gtag.js itself does not set cookies until you accept analytics.
We have enabled IP anonymisation, so Google truncates your IP address before storing it. Analytics data is retained for 14 months. We do not use Google Signals, and we do not link analytics data to your account or order history.
You can also install Google's opt-out browser add-on: tools.google.com/dlpage/gaoptout.
Marketing
We currently use no marketing or advertising cookies. We do not run a Meta Pixel, Google Ads conversion tracking, TikTok Pixel or any other cross-site advertising tag on the Store.
If that changes, we will update this policy, add a marketing category to the consent banner, and ask for your consent before any such cookie is set.
Email Tracking
Our emails are sent through Resend and contain a tracking pixel and tagged links that tell us whether a message was opened and which links were clicked. We use this to see whether our emails are useful and to stop sending to addresses that never open them.
To prevent it, turn off automatic image loading in your email client, or unsubscribe from marketing emails using the link in any message. Transactional emails about your orders will still be sent.
Do Not Track and Global Privacy Control
Browsers send inconsistent "Do Not Track" signals and there is no agreed standard, so we do not respond to DNT.
We do respond to Global Privacy Control (GPC). If your browser sends a GPC signal, we treat it as a withdrawal of consent for analytics cookies and as an opt-out of sale or sharing under US state privacy laws.
Changes
We will update this policy when we add or remove a cookie. The "Last updated" date at the top shows when it last changed. If we add a category that requires consent, we will ask you again before setting it.
Contact
Questions about cookies: support@rovesetups.com