Legal
Cookies
Last updated: 2026-05-27
We use a small set of essential cookies that are required for the Store to function. We do not use advertising cookies, cross-site trackers, or third-party fingerprinting. Because our cookies are strictly necessary under the ePrivacy Directive (art. 5(3)), no consent banner is shown — you accept these cookies by using the site.
What we set
- wwp_cart_id — links your browser to a shopping bag on the server. HttpOnly, Secure, SameSite=Lax. Expires after 30 days of inactivity.
- authjs.session-token — keeps you signed in if you create an account. HttpOnly, Secure, SameSite=Lax. Expires after 30 days.
- wwp_unlocked — set only when the coming-soon password gate is active and you have entered the password. Cleared once the public store launches.
- __Host-csrf-token (Auth.js) — protects sign-in forms against CSRF. Session cookie.
What we don't set
No Google Analytics, no Meta Pixel, no advertising cookies, no remarketing tags. If we ever introduce analytics, we will use a privacy-respecting cookieless tool (such as Plausible) and update this page before deploying it.
How to remove cookies
You can delete cookies in your browser settings at any time. Removing wwp_cart_id empties your bag; removing the session token signs you out.