Our cookie policy
We use browser storage for your cart, for your own recently viewed history and, if you choose it yourself, for your customer account. Visitor statistics are measured without cookies; only for measurement by Google, Meta and Microsoft Clarity do we first ask your consent. Where your visit came from is remembered without an ID until you close the tab.
Last updated: 25 September 2026
Visitor Statistics Without Cookies
We total store use by hour: page and product views, language, market and device category, plus steps such as searching, adding to or removing from the basket and starting checkout. For an add we also count the product, Shopify variant and quantity; for an explicit banner click we count yes or no once. Ordinary events are not segmented by your measurement choice. This hourly count stores no raw events, IP address, search text, cookie, or visitor, session, basket or order ID. In addition, for each visit we store, under a visit hash (see below), the steps of that visit and the origin it started with: the referring website (domain name only), the source, medium, campaign, content and term from the link, whether you arrived through an ad click from Google or Meta (only yes or no, never the click ID itself) and the first page of your visit. That way we count visits and steps per day, market and origin, see which origin brings orders and revenue, and see what helps without following a person from one day to the next.
We do not ask for separate consent for this data-minimal measurement; it applies to every visitor, with or without a yes in the banner. The measurement component does not itself create or read cookies; it only keeps the origin of your visit, without an ID, in the tab storage (sm:herkomst, see below). The functional consent banner reads the already stored yes/no choice only to honour it; only when you click does it publish one separate yes or no category. Our server, never your browser, calculates the visit hash for every event: a SHA-256 hash of a random secret that our own dashboard issues for each day, your IP address, your browser's user agent and the address of this website. No cookie and nothing on your device is used for this. The server uses your IP address and user agent only in memory for that calculation; they are never stored, logged or passed on. The secret changes every day (UTC), and our dashboard keeps at most today's and yesterday's secret and destroys older ones. So the same browser gets a different hash the next day, visits cannot be linked across days, and the hash cannot be turned back into an IP address. The event payload contains no IP address, user agent, full referrer URL or full URL. No visitor profile is built across days, and we do not link a visit to your name, account or order. Which company stores this data for us is listed in our Privacy Policy.
With this measurement we want to understand which channels bring visits and orders, and improve the store. We base this processing on our legitimate interest under Article 6(1)(f) GDPR. We keep each visit's data and steps for 90 days and the daily totals for 400 days; a day's secret exists at most until the end of the following day. None of this goes to Google or Meta. Questions, or do you want to use your right to object? Email hello@studiomiron.com.
Measurement by Google, Meta and Microsoft Clarity, With Your Consent
If you say yes, Google's measurement code may load on our site. Google Analytics then measures how our site is used, with its own cookies _ga and _ga_<id> (lifetime around two years). Through the same code, Google Ads can see which ad brought you to us and whether that visit leads to a purchase, with cookies such as _gcl_au (lifetime around 90 days), so we can pay for advertising by its results. The measurement code loads with every consent set to denied, and in the same step we switch the consents for statistics and advertising to granted, as Google prescribes. Google can combine that data within your own Google account, according to Google's privacy policy.
With the same yes, Meta's pixel loads too. It tells Meta which pages you view (PageView), which product you look at (ViewContent), what you add to your cart (AddToCart) and when you start checkout (InitiateCheckout), with the product IDs, the value and the currency. The pixel sets the cookie _fbp (lifetime around 90 days) and, only if you arrived through a Meta ad link, _fbc (also around 90 days). If you use Facebook or Instagram, Meta may also use its own cookies on its own domains, for example the fr cookie. After your yes we also measure through our own server whether a visit leads to a purchase: with an order we pass Google and Meta the order number, the amount and the pseudonymous click and browser IDs from the two attribution cookies below, without name, email address, postal address or IP address, not even in hashed form. Neither Google's measurement code nor Meta's pixel receives a name, email address or other contact details from us. Without a yes, no purchase goes to Google Ads or Meta; Google Analytics then only receives the order itself, without a cookie or ID that points to you.
With the same yes, Microsoft Clarity loads too, for session recordings and heatmaps: it records where you click, how far you scroll and how you move the mouse, so we can see where visitors get stuck and improve the site. What you type into fields and your personalisation texts are masked in those recordings, and we never load Clarity on the pages of your customer account. Clarity sets two cookies on our site: _clck, which remembers for about a year that this is the same browser, and _clsk, which lasts one day and links the steps within one visit. Microsoft also documents five cookies on its own domains (CLID, MUID, MR, SM and ANONCHK), which Microsoft services use to recognise your browser. We explicitly signal to Microsoft that there is no consent for advertising use: your yes here only covers improving the site.
These are the only parts of our site where real tracking cookies could appear, and they stay completely off until you switch them on. If you say no, or have not chosen yet, we do not load any code from Google, Meta or Microsoft: there is nothing from them on the page, so they do not even learn about your refusal and receive nothing about your visit from your browser. Our own cookieless hourly totals are separate from this and stay cookieless. The legal basis is your consent. If you withdraw it, the code loaded at that moment immediately receives a denial signal, the measurement stops and on the next page nothing from Google, Meta or Microsoft loads anymore. Cookies they already set can be deleted through your browser settings.
The Browser Storage
- Name
- mirondigital_cart
- Purpose
- Remembers what is in your cart
- Type
- Functional, strictly necessary
- Retention
- 14 days
- Contents
- A reference to your cart in our order system, nothing more
- Name
- mirondigital_has_cart
- Purpose
- Only remembers that a cart exists, so the site can show the cart icon without unnecessary lookups
- Type
- Functional, strictly necessary
- Retention
- 14 days
- Contents
- Only the digit 1, no personal data
mirondigital_cart is httpOnly. That means JavaScript in your browser cannot read it. It contains no name, email address or payment information. mirondigital_has_cart can be read by JavaScript, but only contains the digit 1.
- Name
- pw:wag-focus (sessionStorage, not a cookie)
- Purpose
- After a change to your cart, returns keyboard focus to the correct row. This prevents keyboard and screen reader users from having to start at the top after every change.
- Type
- Functional, strictly necessary for the cart action you requested
- Retention
- Until the next page load, and at the latest until you close the browser tab
- Contents
- The technical cart row and the button you used. No name or contact details
- Name
- miron_voortgangsbalk_dicht (sessionStorage, not a cookie)
- Purpose
- Remembers that you dismissed the mix and match bar at the bottom of the screen, so it does not reappear on every following page
- Type
- Functional, strictly necessary for the dismissal you requested
- Retention
- Until you close the browser tab
- Contents
- Only the digit 1. No visitor ID or contact details
- Name
- pw:consent (localStorage, not a cookie)
- Purpose
- Remembers whether you accepted or refused measurement by Google, Meta and Microsoft Clarity, so we do not have to ask on every page
- Type
- Functional, strictly necessary to record your choice
- Retention
- At most 180 days, or sooner if you change your choice or clear your browser storage
- Contents
- Your measurement choice as yes or no and the time of the choice. No visitor ID or contact details
- Name
- pw:consent-sync-gedempt (sessionStorage, not a cookie)
- Purpose
- Remembers within this tab that our server cannot confirm your choice right now, so the site does not try again on every page
- Type
- Functional, so your choice is not sent to our server again on every page view
- Retention
- Until you close the browser tab
- Contents
- Only the digit 1. No measurement choice, visitor ID or contact details
- Name
- mirondigital_google_attribution (cookie)
- Purpose
- After your consent, links a Google ad click to the cart and later to the order so the purchase can be measured server-side
- Type
- Measurement and advertising, only after your consent
- Retention
- Up to 90 days, or sooner if you withdraw your consent
- Contents
- A pseudonymous Google click ID, GA client ID, optional session ID and capture time. No name, email address, postal address, IP address or order contents
- Name
- sm-recent-bekeken (localStorage, not a cookie)
- Purpose
- Remembers which products you recently viewed, so the Recently viewed section at the bottom of a product page can show them to you again. This list stays in your own browser and does not go to us or anyone else.
- Type
- Functional, for your own viewing history
- Retention
- 30 days, or sooner as soon as you clear your browser storage
- Contents
- Per product the name, the photo, the price and the web address of the product page, at most twelve. No name, email address or order details
- Name
- mirondigital_auth_flows, mirondigital_auth_state_<state>, mirondigital_auth_nonce_<state> and mirondigital_auth_verifier_<state>
- Purpose
- Protect the round trip when you sign in to your customer account. If you do not sign in, they are not set.
- Type
- Functional, strictly necessary for the sign-in you requested
- Retention
- At most 10 minutes; after a completed or failed sign-in they are deleted
- Contents
- One-time, random verification values. They are httpOnly
- Name
- mirondigital_at
- Purpose
- After you sign in, gives temporary access to your own orders and account details
- Type
- Functional, strictly necessary for the customer account you opened
- Retention
- The validity of that access key, or sooner as soon as you sign out
- Contents
- A temporary access key for your account; the cookie is httpOnly
- Name
- mirondigital_rt, mirondigital_at_exp, mirondigital_idt, mirondigital_ingelogd and mirondigital_rf
- Purpose
- Keep your chosen sign-in for at most thirty days, safely refresh an expired access key and make signing out possible.
- Type
- Functional, strictly necessary for the customer account you opened
- Retention
- At most 30 days, or sooner as soon as you sign out
- Contents
- Temporary account keys and the technical expiry time. Only mirondigital_ingelogd can be read by JavaScript and contains only the digit 1; the other cookies are httpOnly.
- Name
- mirondigital_gegevens_flash
- Purpose
- After a failed profile or address change, restores your form and shows the message at the right field. The cookie is deleted immediately after the next read.
- Type
- Functional, strictly necessary for the form processing you requested
- Retention
- At most 60 seconds and for a single read
- Contents
- Only the profile or address fields you just filled in and validation messages, for example name, address, postcode, town, phone or company name. The cookie is httpOnly.
- Name
- mirondigital_meta_attribution (cookie)
- Purpose
- After your consent, links a Meta ad click to the cart and later to the order so the purchase can be measured server-side by Meta
- Type
- Measurement and advertising, only after your consent
- Retention
- At most 90 days, or sooner if you withdraw consent
- Contents
- A pseudonymous Meta browser ID (the Meta pixel's _fbp value once the pixel runs), optional click ID, parameter-free source URL and capture time. No name, email address, postal address, IP address or order contents
- Name
- sm:herkomst (sessionStorage, not a cookie)
- Purpose
- Remembers within this tab where your visit came from, such as a newsletter, a search engine or an ad. As soon as you add something to your cart, that origin is attached to your cart as an attribute, so that we can see which campaign led to an order
- Type
- Statistics without a visitor ID; even without consent
- Retention
- Until you close the browser tab. The attribute on your cart stays with the cart and any order placed from it
- Contents
- The source from the link (or otherwise the name of the referring website), the medium, campaign, content and term from the link, whether you arrived through an ad click from Google or Meta, the first page, the time, and whether the origin is already on your cart. No visitor ID, click ID, IP address or contact details
- Name
- mirondigital_consent_receipt (cookie)
- Purpose
- Lets our server verify that your measurement choice was genuinely recorded on this site before a consent proof is added to the basket
- Type
- Functional, strictly necessary to respect your choice safely
- Retention
- At most 180 days, or sooner if you clear browser cookies
- Contents
- Your choice, our store domain, start and end times and a cryptographic signature. No visitor ID, name, email address, IP address or order contents. The cookie is httpOnly.
- Name
- mirondigital_consent_revoked (cookie)
- Purpose
- Makes every subsequent checkout check on our site honour your withdrawal immediately, even if confirmation to our server temporarily fails
- Type
- Functional, strictly necessary to honour a withdrawal immediately
- Retention
- At most 180 days; removed as soon as you later choose yes and the server confirms it
- Contents
- A random revocation token used only to preserve the order of your choices. No visitor ID, contact details or tracking code
Apart from the viewing history described above, which stays in your own browser, we do not use browser storage to build a profile of your interests. Cookies from Google, Meta and Microsoft are only set if you switch on the measurement above yourself.
Cookies at Checkout
As soon as you go to checkout, you arrive at our secure checkout page. It runs on Shopify, the platform behind our store, where your orders and payments are handled too, and Shopify sets its own necessary cookies there to complete your order and payment. We do not add advertising cookies on the checkout page. Which parties are involved in your order and what they process is explained in our Privacy Policy.
Questions?Happy to explain it in plain language.
Contact us