Cookie Policy
About cookies
To ensure that our website is optimized and functions correctly, we and our service providers utilize cookies, HTML Local Storage, IndexedDB, and Pixels to collect data. These technologies enable us to count visitors, analyze behavior, and ensure technical stability. Please read our cookie policy and privacy policy for further information regarding our processing of personal data.
This list is the Cookiebot declaration for the Goodiebox webshop at shop.bygoodiebox.com (scan dated 12 August 2026). Where Cookiebot had no category or purpose, we assigned one based on how the tracker is used in the shop. Cookiebot on the shop always shows the cookies used on your current visit.
What are cookies and trackers?
A cookie is a small file stored on your device. We also use Local Storage and IndexedDB to store settings directly in your browser, as well as Pixels to measure the effectiveness of our marketing. None of these technologies contain malicious software or viruses.
Necessary cookies (Necessary)
These trackers are fundamental for security, network administration, and basic functions such as payment and consent management.
Provider: Cloudflare
Purpose: This cookie is used to distinguish between humans and bots. This is beneficial for the website, in order to make valid reports on the use of their website.
Names: __cf_bm.
Expiry: 1 day.
Type: HTTP cookie.
Provider: Cookiebot
Purpose: Stores the user's cookie consent state for the current domain.
Names: consentHeader, CookieConsent.
Expiry: Session / 1 year.
Type: HTML Local Storage / HTTP cookie.
Provider: Good Apps (product add-ons)
Purpose: Maintains the state of selected product add-ons or upsell items within the shopping cart during the current session.
Names: product_addons_session.
Expiry: Session.
Type: HTTP cookie.
Provider: Goodiebox webshop / Shopify
Purpose: Stores the user's cookie consent state for the current domain. This cookie determines whether the browser accepts cookies. Necessary for the checkout function on the website. Necessary for the shopping cart functionality on the website. The cookie is necessary for the secure checkout and payment function on the website. This function is provided by shopify.com. Manages access control permissions to ensure that restricted content or member-only products are only visible to authorized users. This cookie is used in conjunction with the payment window. The cookie is necessary for making secure transactions on the website. Used to sync the shopping cart when signing in with Shop.
Names: __mp_opt_in_out_#, _shopify_test, _shopify_essential, cart, cart_currency, locksmith-params, login_with_shop_finalize, signInWithShop:cartSyncTransferAttemptedAt, signInWithShop:cartSyncTransferCompletedAt.
Expiry: Session / 1 year / 3 months / 1 day / Persistent.
Type: HTTP cookie / HTML Local Storage.
Provider: PayPal
Purpose: Used in context with the PayPal payment function on the website. The cookie is necessary for making a safe transaction through PayPal.
Names: __paypal_storage__, __paypal-…_storage__.
Expiry: Persistent.
Type: HTML Local Storage.
Provider: Shopify
Purpose: Used to track which product bundles have been added to the cart to ensure correct pricing and inventory management. This cookie is used to detect errors on the website. This information is sent to the website's support staff in order to optimize the visitor's experience. Technical cookie. Used to implement third-party widgets onto the website. Necessary for the checkout function on the website. Stores shop configuration used by the mix-and-match bundle feature so product options load correctly. Keeps mix-and-match bundle selections in the shopping cart during the current session. Caches product data for the mix-and-match bundle feature so the page loads correctly.
Names: _gbbExtBundlesAddedOnCart, bugsnag-anonymous-id, epb_payload, _shopify_essential, gbbMix.utilis.shopDomain, gbbMix.utilis.storeFrontAccessToken, gbbMixAndMatchBundleAddedToCart, gbbMix-cart-#, gbbMixSdk-cart-#, gbbMixDefaultProductsData, gbbMixProductsCachedData.
Expiry: Persistent / Session.
Type: HTML Local Storage / HTTP cookie.
Provider: Shopify (Shop app)
Purpose: Necessary for the integration with the Shop app, facilitating features like Shop Pay and seamless login across Shopify stores. Necessary for the checkout function on the website.
Names: _shop_app_essential, _shopify_essential.
Expiry: 1 year / Session.
Type: HTTP cookie.
Functional cookies (Preferences)
These trackers remember your choices to improve your experience.
Provider: Goodiebox webshop / Shopify
Purpose: Preserves the state of search filters and interface elements to improve the user experience during navigation. Holds the user's timezone. Remembers the scroll position on a product page so the page can restore it during navigation. Stores recently viewed products so they can be shown again on the website.
Names: _shs_state, localization, nextsky:scroll-position:#, recently-viewed-products.
Expiry: Session / 1 year / Persistent.
Type: HTML Local Storage / HTTP cookie.
Provider: Klaviyo
Purpose: The cookie is used to manage the mailing list, if the visitor has subscribed to any newsletters or blog posts.
Names: klaviyoOnsite.
Expiry: Persistent.
Type: HTML Local Storage.
Provider: LangShop
Purpose: Saves the visitor's currency preferences. Necessary for maintaining language settings across subpages on the website. The cookie determines the preferred language and country setting of the visitor. This allows the website to show content most relevant to that region and language.
Names: ls-currency, ls-locale, ls-state-session.
Expiry: Persistent / Session.
Type: HTML Local Storage.
Provider: Shopify
Purpose: Remembers the selected country and language for the mix-and-match bundle feature. Stores pending country or language actions after a geo-location check, so the correct market is shown.
Names: gbbMix_currentSelectedCountry, gbbMix_currentSelectedLocale, geoip-pending-actions.
Expiry: Session / Persistent.
Type: HTML Local Storage.
Statistical cookies (Statistics)
Helps us understand how visitors interact with the website through anonymous data collection.
Provider: Goodiebox webshop / Shopify
Purpose: Collects data on the user’s navigation and behavior on the website. This is used to compile statistical reports and heatmaps for the website owner. Registers statistical data on users' behaviour on the website. Used for internal analytics by the website operator. Used to send data to Google Analytics about the visitor's device and behavior. Tracks the visitor across devices and marketing channels. This cookie is used to collect information on the visitor's behavior. This information is stored for internal analytics, to optimize the website or to register if the visitor has subscribed to a newsletter. Used by Shopify to store storefront event context for analytics. Counts page views after a geo-location check, used for internal analytics. Used by Shopify’s web pixel manager to identify requests for analytics and marketing pixels. Assigns a unique ID to the visitor so Shopify can recognise the browser on return visits.
Names: _clck, _clsk, _shopify_analytics, _ga, _ga_#, __kla_id, __shopify_agent_context_events, el-geoip-pageview-count, ri-#, wpm-ri-#, shopify_client_id.
Expiry: 1 year / 1 day / 2 years / Session / Persistent.
Type: HTTP cookie / HTML Local Storage.
Provider: Microsoft Clarity
Purpose: Collects data on the user’s navigation and behavior on the website. This is used to compile statistical reports and heatmaps for the website owner. Registers statistical data on users' behaviour on the website. Used for internal analytics by the website operator.
Names: c.gif, _cltk.
Expiry: Session.
Type: Pixel tracker / HTML Local Storage.
Provider: Mixpanel
Purpose: Used by Mixpanel to identify the visitor for internal analytics. Used by Mixpanel to identify browser tabs for internal analytics. Used by Mixpanel to record session activity for internal analytics. Used by Mixpanel to store feature-flag values for analytics and site experiments.
Names: mp_#_mixpanel, mp_gen_new_tab_id_#, mp_tab_id_#, mixpanelBrowserDb#mixpanelRecordingEvents, mixpanelBrowserDb#mixpanelRecordingRegistry, mixpanelFlagsDb#mixpanelFlags.
Expiry: 1 year / Session / Persistent.
Type: HTTP cookie / HTML Local Storage / IndexedDB.
Provider: Shopify
Purpose: Registers statistical data on users' behaviour on the website. Used for internal analytics by the website operator. Used by the product-bundle widget to record page path and whether the widget was shown, for internal analytics. Tracks the visitor’s path through the mix-and-match bundle flow for internal analytics. Stores tracking data for the mix-and-match bundle feature, used for internal analytics.
Names: _shopify_analytics, epb_previous_pathname, epb_render_beaconed, gbbMix_pagefunnel_#, gbbMix_tracking_#.
Expiry: Session.
Type: HTTP cookie / HTML Local Storage.
Marketing cookies (Marketing)
Used to track visitors across websites to display relevant and engaging advertisements.
Provider: Facebook (Meta)
Purpose: Detects how the user reached the website by registering their last URL-address.
Names: lastExternalReferrer, lastExternalReferrerTime.
Expiry: Persistent.
Type: HTML Local Storage.
Provider: Goodiebox webshop / Shopify
Purpose: Used by Facebook to deliver a series of advertisement products such as real time bidding from third party advertisers. Collects data on user behaviour and interaction in order to optimize the website and make advertisement on the website more relevant. Contains data on the content of the shopping cart. This data is used for marketing purposes by promoting related products or for retargeting purposes. Used by the social networking service TikTok for tracking the use of embedded services. Controls the frequency of pop-ups or promotional overlays to ensure they are not shown to the user too often. Sets the start date for tracking monthly views of promotional pop-ups to ensure they are not displayed too frequently to the user. Used to track visitors on multiple websites, in order to present relevant advertisement based on the visitor's preferences. Tracks the conversion rate between the user and the advertisement banners on the website. This serves to optimise the relevance of the advertisements on the website.
Names: _fbp, _shopify_s, _shopify_y, _shopify_marketing, _ttp, tt_sessionId, tt_appInfo_v2, tt_s_pixel_session_index, goodpaCurrentShownPerDay, goodpaCurrentShownPerMonth, goodpaStartDatePerDay, goodpaStartDatePerMonth, ttcsid, ttcsid_#.
Expiry: 3 months / 1 day / 1 year / Session / 25 days.
Type: HTTP cookie / HTML Local Storage.
Provider: Klaviyo
Purpose: This cookie is used to determine which products the visitor has viewed. This information is used to promote related products and optimize ad-efficiency. Tracks user browsing behavior, identification data, and traffic sources to optimize marketing campaigns and attribution. Collects information on the user's website navigation and preferences. This is used to target potential newsletter based upon this information. Collects information on the user's navigation and viewed products. This data is used to personalize marketing content, such as product recommendations.
Names: klaviyoPagesVisitCountV2, __kl_key, $last_referrer, $referrer, kl-post-identification-sync, __kla_viewed, __kla_viewed_reviewed_items.
Expiry: Session / Persistent.
Type: HTML Local Storage.
Provider: Microsoft Advertising / Bing
Purpose: Used to track visitors on multiple websites, in order to present relevant advertisement based on the visitor's preferences. Used widely by Microsoft as a unique user ID. The cookie enables user tracking by synchronising the ID across many Microsoft domains. Tracks the user’s interaction with the website’s search-bar function. This data can be used to present the user with relevant products or services.
Names: MR, MUID, SRM_B.
Expiry: 7 days / 1 year.
Type: HTTP cookie.
Provider: Microsoft Clarity
Purpose: Registers data on visitors from multiple visits and on multiple websites. This information is used to measure the efficiency of advertisement on websites. Used to track visitors on multiple websites, in order to present relevant advertisement based on the visitor's preferences. Registers a unique ID that identifies the user's device during return visits across websites that use the same ad network. The ID is used to allow targeted ads. Used widely by Microsoft as a unique user ID. The cookie enables user tracking by synchronising the ID across many Microsoft domains.
Names: ANONCHK, MR, SM, MUID.
Expiry: 1 day / 7 days / Session / 1 year.
Type: HTTP cookie.
Provider: Pop Convert
Purpose: Used by Pop Convert to decide when to show promotional pop-ups and to measure their performance.
Names: __pcjs__production, pc_session_registered.
Expiry: Persistent / Session.
Type: HTML Local Storage.
Provider: Shopify
Purpose: Contains data on the content of the shopping cart. This data is used for marketing purposes by promoting related products or for retargeting purposes. Collects data on user behaviour and interaction in order to optimize the website and make advertisement on the website more relevant.
Names: _shopify_marketing, _shopify_s, _shopify_y.
Expiry: Session / 1 day / 1 year.
Type: HTTP cookie.
Overview
This overview is based on the Cookiebot technical scan of shop.bygoodiebox.com dated 12 August 2026. We update the list when we add features or when providers change their trackers.
How do I change my cookie settings?
You can change or withdraw your consent at any time by clicking the cookie icon in the bottom left corner. You may need to refresh your page before your settings take effect.
Cookies that you have already accepted can also be deleted manually. The method depends on your device and browser:
Windows / PC: Use the shortcut CTRL + SHIFT + DELETE in your browser.
Macbook / Mac: Use the shortcut CMD + SHIFT + DELETE (in Chrome/Firefox) or go to Settings > Privacy in Safari.
iPhone / iPad: Go to Settings > Safari > Clear History and Website Data.
Android phones: Open the Chrome app, tap the three dots in the corner, select History > Clear browsing data.
Please note: If you use multiple different internet browsers, you must delete cookies in each browser.
Do you have questions?
If you have any questions regarding our processing of personal data or our use of cookies, you are always welcome to contact us. Our cookie policy is continuously updated to ensure it always reflects the technologies and legal requirements we comply with.