Cookie & Tracking Policy
Draft — not yet in force. These documents are shared for transparency and are pending legal review. They are not the final, binding terms until published at launch.
DRAFT for legal review — not final, not in force. See 00-README. Read with the Privacy Policy. For Turkish visitors, see the TR overlay. `` /
[PLACEHOLDER]as defined there.
Controller (CIQRA websites, e.g. ciqra.com and dashboards): CIQRA OÜ, registry code 16465907, Tallinn, Estonia · privacy@ciqra.com Version: 1.0-draft · Last updated: 2026-07-08
1. What this covers
This Policy explains how cookies and similar technologies (local storage, pixels, SDKs, device identifiers, and server-side event tracking) are used on CIQRA's own websites and dashboards. On a Merchant's Storefront, the Merchant is the controller for its own cookies/tracking and must publish its own cookie notice; CIQRA provides the consent-management tooling and the default configuration described here. ``
2. What cookies and similar technologies are
Cookies are small files stored on your device. We also use equivalent technologies (HTML local/session storage, pixels/beacons, and server-side tracking that forwards events from our server to a third party). Under EU/EEA law (ePrivacy + GDPR), storing or reading non-essential information on your device, and equivalent server-side tracking that shares your personal data with third parties, requires your consent.
3. Consent model
3.1 Essential (strictly necessary) technologies run without consent — they are required to deliver the service you requested (security, load balancing, session, CSRF, consent state, cart, checkout, fraud prevention).
3.2 All non-essential technologies (analytics, advertising, personalisation) run only after you opt in via our consent banner. You can accept all, reject all, or choose by category, and you can change or withdraw consent at any time via the "Cookie settings" link. Rejecting non-essential cookies does not affect access to essential functionality.
3.3 Server-side tracking does not bypass consent. Where we (or a Merchant) use server-side event forwarding / conversion APIs (e.g. Meta CAPI), that sharing is gated on the same consent: if advertising/analytics consent is not given or is withdrawn, personal data is not forwarded to those platforms. ``
4. Categories we use
| Category | Purpose | Consent? | Examples / providers |
|---|---|---|---|
| Strictly necessary | Security, session, cart, checkout, load balancing, consent storage, fraud prevention | No (essential) | CIQRA session, CSRF token, Cloudflare, Stripe (checkout/anti-fraud) |
| Functional / preferences | Remember language, theme, region, recently viewed | Consent | CIQRA preference cookies |
| Analytics / performance | Understand usage to improve the Services | Consent | Google Analytics 4 / Google Tag Manager (incl. server-side GA4) |
| Advertising / marketing | Measure campaigns, retargeting, conversion tracking (incl. server-side/CAPI) | Consent | Meta Pixel + Conversions API; Google Ads; TikTok |
A live, itemised cookie table — each cookie's name, provider, purpose, first/third-party type, and duration — is generated and kept current by our consent-management tool and shown in the "Cookie settings" panel. (Populated at runtime by the consent tool.)
5. Third-party tracking specifics
- Google Consent Mode v2. Where Google tags are used, we implement Consent Mode v2 and pass the consent state via the signals
ad_storage,analytics_storage,ad_user_dataandad_personalization. When consent is denied, Google tags fire only in a cookieless / aggregated manner (no identifying storage). `` - Google Analytics 4 / Google Tag Manager — analytics; loads (with storage) only with analytics consent; IP/data handling per Google's controls and Consent Mode state. ``
- Meta Pixel & Conversions API (CAPI) — advertising measurement. Both the browser pixel and the server-side CAPI event forwarding (which may share hashed identifiers such as email/phone, plus IP and event data) run only with advertising consent — server-side transmission does not bypass consent. Client and server events are deduplicated via a shared event ID, and data is minimised/filtered before any third party receives it. ``
- TikTok / other ad platforms — advertising; consent-gated (browser + any server-side events).
- Controller allocation & joint controllership. On a Merchant's Storefront, the Merchant is the controller for its own analytics/ad-tech and is responsible for its consent banner, its DPAs with Google/Meta, and its lawful basis; CIQRA provides the integration and consent gating. For certain ad-platform collection (e.g. Meta Pixel), the ad platform may act as a joint controller for the collection/transmission stage under applicable case law (Fashion ID). ``
Transfers to these providers outside the EEA rely on the safeguards in the Privacy Policy §7 (SCCs / adequacy). ``
6. Managing cookies
- Use our "Cookie settings" control to change categories at any time.
- Most browsers let you block/delete cookies; blocking essential cookies may break the Services.
- Global signals (e.g. Global Privacy Control) are honoured where legally required. ``
7. Do Not Track / GPC
We aim to honour recognised opt-out signals where required by applicable law. ``
8. Changes
We may update this Policy; the "last updated" date reflects the latest version, and material changes are notified via the banner.
End of Cookie Policy (draft). See: Privacy Policy · TR overlay.