Last updated: 8/25/2026
This page explains which cookies this website uses, what each one does, and how you can control them.
What cookies are
Cookies are small text files a website stores in your browser. Some are needed for the site to work at all — keeping items in your basket, or processing a payment securely. Others help us understand how people find and use the shop.
How we use them
We group cookies into four categories, and you choose which to allow:
Strictly necessary — required for the site to function. These include the cookie that remembers your consent choices, cookies that keep your shopping basket working, and fraud-prevention cookies set by our payment provider. They cannot be switched off.
Functional — remember small preferences, such as whether you have already dismissed a pop-up.
Analytics — help us understand which pages people visit and how they found us. These are only set if you allow them.
Marketing — we do not currently use any marketing or advertising cookies.
No cookie on this site is used to build an advertising profile of you.
Cookies we use
Necessary
| Cookie |
Duration |
Category |
Description |
|
__stripe_mid |
1 year |
Necessary |
Stripe fraud prevention cookie for payment processing. |
|
__ssid |
session |
Necessary |
Set by Sift, the fraud-detection service loaded alongside Stripe at checkout, to recognise the device during a payment session. |
|
woocommerce_items_in_cart |
session |
Necessary |
WooCommerce cookie to track items in cart. |
|
woocommerce_cart_hash |
session |
Necessary |
WooCommerce cookie to determine cart contents changes. |
|
__stripe_sid |
30 minutes |
Necessary |
Stripe fraud prevention session cookie for payment processing. |
|
m |
1 year 1 month |
Necessary |
Set by Stripe for fraud prevention. Identifies the device used to reach
the site so payment forms behave correctly. |
|
wp_woocommerce_session_* |
2 days |
Necessary |
Gives each shopper a unique code so WooCommerce can find their cart data in the database. |
|
fazcookie-consent |
1 year |
Necessary |
Stores your cookie consent choices so the banner is not shown again on later visits. |
|
wfwaf-authcookie-* |
Session |
Necessary |
Set by the Wordfence firewall to recognise a signed-in administrator so the correct firewall rules are applied. Only set for logged-in users. |
Functional
| Cookie |
Duration |
Category |
Description |
|
pum-810 |
1 month |
Functional |
Remembers that you have already seen or closed the newsletter pop-up, so it is not shown to you again. |
Analytics
| Cookie |
Duration |
Category |
Description |
|
sbjs_migrations |
session |
Analytics |
Technical data to help with migrations between different versions of the tracking feature |
|
sbjs_current_add |
session |
Analytics |
Timestamp, referring URL, and entry page for your visitor’s current visit to your store |
|
sbjs_first_add |
session |
Analytics |
Timestamp, referring URL, and entry page for your visitor’s first visit to your store (only applicable if the visitor returns before the session expires) |
|
sbjs_current |
session |
Analytics |
Traffic origin information for the visitor’s current visit to your store |
|
sbjs_first |
session |
Analytics |
Traffic origin information for the visitor’s first visit to your store (only applicable if the visitor returns before the session expires) |
|
sbjs_udata |
session |
Analytics |
Information about the visitor’s user agent, such as IP, the browser, and the device type |
|
sbjs_session |
30 minutes |
Analytics |
The number of page views in this session and the current page path |
|
tk_ai |
session |
Analytics |
Set by Jetpack Stats. Stores a randomly-generated anonymous ID used to count visits. |
|
tk_qs |
30 minutes |
Analytics |
Set by Jetpack Stats. Stores a randomly-generated anonymous ID for the current session. |
|
tk_or |
5 years |
Analytics |
Set by Jetpack Stats. Stores a unique identifier for the publisher. |
Where your data goes
Some of the services above are operated by companies based in the United States, so allowing them means data is transferred outside the UK and EEA:
– Stripe — payment processing and fraud prevention. Stripe, Inc. is self-certified under the EU-US Data Privacy Framework, with EU Standard Contractual Clauses applying as a fallback under Stripe’s Data Transfers Addendum.
– Sift — device-based fraud detection, loaded by Stripe during checkout, covered by Standard Contractual Clauses.
– Automattic — website statistics, covered by Standard Contractual Clauses under Automattic’s Data Processing Agreement.
The table above marks which cookies involve a transfer of this kind.
Changing your mind
You can change or withdraw your consent at any time using the consent preferences icon in the corner of any page. Your choice is remembered for one year.
You can also block or delete cookies through your browser settings. Blocking strictly necessary cookies will prevent the shop’s basket and checkout from working.
Questions
Contact us at lizamills950@gmail.com with any questions about this policy or the data we hold.