Cookie Policy

Effective from: 21 July 2026

This Cookie Policy explains how Bonideco uses cookies, pixels, local storage and similar technologies, why they are used, how long they operate and how you can manage your choices.

Website: bonideco.lv

1. Controller

Seller / data controller
MB “Bonideco”
Company code
306048688
Registered address
Servečės g. 2, LT-02121 Vilnius, Lithuania

2. What these technologies are

Cookies are small text files stored by a browser. Similar technologies include local or session storage, pixels, tags, SDKs and server-side events. They may be first-party, set by this domain, or third-party, controlled by an external provider.

A technology’s actual name and duration may vary with the Website, browser and provider configuration. The consent-management list shown on the Website is the most specific current inventory for your device.

3. Legal basis and categories

Strictly necessary technologies are used without consent only where objectively required to provide a service you requested, secure the Website, maintain a basket, authenticate a session or remember privacy choices. Where applicable, this is also supported by contract-related necessity or legitimate interests.

Functional, analytics and marketing technologies are activated only after the required consent. Rejecting them does not prevent core browsing and purchasing. New non-essential technologies are not activated merely because they are mentioned in this Policy; they must first be assessed, categorised and added to consent controls.

4. Managing consent

You can accept, reject or customise non-essential categories using the cookie settings available on the Website and change your choice later. Withdrawal does not affect processing already lawfully carried out. We stop setting or using the relevant technologies as far as technically possible; providers may retain earlier data under their own retention rules and data-subject procedures.

5. Essential Magento technologies

ExamplesPurpose
PHPSESSID, form_keySession continuity and protection against forged requests
X-Magento-Vary, private_content_version, section_data_idsCorrect customer-specific content and cache updates
mage-cache-storage, mage-cache-storage-section-invalidation, mage-cache-sessidLocal storage and refresh of basket and customer sections
recently_viewed_product, product_data_storageRequested product-navigation functions where enabled
user_allowed_save_cookie, storeRemembering consent capability and selected store/language

Some entries are session technologies; others remain only as long as technically necessary or according to the current Magento configuration.

6. Analytics and advertising partners

Provider / examplesPurposeTypical maximum
Google Analytics: _ga, _ga_<ID>Audience and session statisticsUp to 2 years
_gid, _gat, _dc_gtm_<ID>Visitor distinction, request throttling and tag operation24 hours / 1 minute
Google Ads: _gcl_au, _gcl_aw, _gac_*Click and conversion attributionUsually up to 90 days
Google / DoubleClick: IDEAdvertising, frequency and campaign measurementUsually up to 13 months in the EEA/UK
Meta Pixel: _fbp, _fbcConversion measurement, audiences and remarketingUsually up to 90 days
TikTok / Pangle: _ttp, ttcsid_*, ttclid, _pangleCampaign measurement, optimisation and audiencesUp to 13 months from last use

These providers may receive IP address, page URL, browser or device data, identifiers and consented event data. Depending on configuration and consent, pseudonymised or hashed contact and conversion identifiers may be sent for matching. We do not send card security data, account passwords or customer-support correspondence to advertising partners.

7. Omnisend, forms and newsletters

Omnisend may be used for subscription forms, newsletters and consented behavioural automation. The email address itself is not a cookie. Browser technologies may remember that a form was closed or completed, or—with the required consent—recognise a contact and record events.

  • omnisend-form-{id}-closed-at, -filled-at and -teaser-closed-at: form display choices, up to 365 days where configured.
  • omnisendSessionID: session recognition, typically about 30 minutes.
  • omnisendContactID and page-view/event storage: identification and behavioural automation only with the required consent; duration follows the active configuration and consent inventory.

8. Embedded content and transfers

Payments, finance, maps, video, social posts, reviews, chat, recommendations or CAPTCHA may involve third-party technology. Non-essential embedded content is blocked until consent where required. A tool strictly necessary for a function you request receives only data needed for that function.

Providers may process data outside the EEA. Relevant transfers are handled as explained in the Privacy Policy, using an adequacy decision or appropriate safeguards such as standard contractual clauses where required.

9. Browser controls and consequences

You may also delete or block cookies in browser settings. Blocking essential technologies can prevent login, basket, language selection, checkout or other core functions. Rejecting analytics or marketing technologies should not prevent ordinary browsing or purchasing. Browser privacy signals are honoured where legally required and technically supported.

10. Rights, contact and updates

Your data-protection rights and complaint channels are described in the Privacy Policy. Questions may be sent to [email protected].

We update this Policy and the consent inventory when providers, names, purposes, recipients, retention or configuration change. The current consent interface is reviewed alongside this document.