Cookie & storage policy
Privacy rules cover storing or reading anything on your device — not cookies alone. This page lists every cookie, local storage item and session storage item this site uses.
How we treat storage
We apply the same rules to cookies, local storage and session storage. Only strictly necessary storage runs before you choose: your bag, your saved items, signing in, and the record of your own consent. Preferences, analytics and marketing storage stay switched off until you turn them on, and we currently run no analytics or marketing storage at all.
Withdrawing consent is as easy as giving it: use the Cookie preferences link in the footer of every page, or the button above. Turning a category off deletes the storage it covers.
Categories
- Strictly necessary: Required to deliver the site and the features you ask for: your bag, your saved items, signing in, and remembering this consent choice. These cannot be switched off.
- Preferences: Optional comfort touches, such as remembering that you have already seen a one-off gesture hint. Off until you allow them.
- Analytics: Measurement of how the site is used. We currently run no analytics storage at all; this switch stays off unless that ever changes.
- Marketing: Advertising or cross-site measurement. We currently run none; this switch stays off unless that ever changes.
Full inventory
Strictly necessary
| Name | Type | Set by | Purpose | Retention | Basis |
|---|---|---|---|---|---|
collectors-road-cartUsed by this site | Local storage | Collector's Road | Keeps the contents of your bag, plus the Shopify cart it is linked to, so items survive a page reload and reach checkout. | Until the bag is emptied or you clear site data. | Strictly necessary — storage explicitly required to provide the shopping basket you requested. |
collectors-road-customerUsed by this site | Local storage | Collector's Road / Shopify Customer Accounts | Holds your signed-in Shopify customer session so account and order pages work without asking you to sign in on every page. | Until you sign out or the session expires. | Strictly necessary — authentication state for a service you asked for. |
cr-customer-pkce-verifierUsed by this site | Session storage | Collector's Road | One-time PKCE code verifier that proves the sign-in request came from this browser. | Deleted as soon as sign-in completes; cleared when the tab closes. | Strictly necessary — security of the sign-in you initiated. |
cr-customer-oauth-stateUsed by this site | Session storage | Collector's Road | Anti-forgery value checked when Shopify returns you from sign-in. | Deleted as soon as sign-in completes; cleared when the tab closes. | Strictly necessary — security of the sign-in you initiated. |
cr-customer-oauth-nonceUsed by this site | Session storage | Collector's Road | Binds the identity token Shopify issues to this sign-in attempt. | Deleted as soon as sign-in completes; cleared when the tab closes. | Strictly necessary — security of the sign-in you initiated. |
cr-customer-oauth-nextUsed by this site | Session storage | Collector's Road | Remembers which page to return you to after sign-in. | Deleted as soon as sign-in completes; cleared when the tab closes. | Strictly necessary — part of the sign-in flow you initiated. |
collectors-road:savedUsed by this site | Local storage | Collector's Road | Stores the items you save with the Save button, so your wishlist is still there when you come back. | Until you remove the items or clear site data. | Strictly necessary for a user-requested feature — saving is only ever written when you press Save, and the list cannot exist without it. Remove saved items to erase it. |
cr-consentUsed by this site | Local storage | Collector's Road | Records the consent choice you made here, so we do not ask again on every visit and so optional storage stays off until allowed. | 12 months, then we ask again. | Strictly necessary — required to honour and evidence your own choice. |
cr-themeUsed by this site | Local storage | Collector's Road | Remembers whether you chose the light or dark appearance, so the site does not flash the wrong theme on load. | Until you turn off appearance memory or clear site data. | User-interface customisation exception — written only when you pick a theme yourself. You can switch this memory off in Cookie preferences, which deletes it and follows your device setting instead. |
sb-*-auth-tokenUsed by this site | Local storage | Lovable Cloud (backend) | Session token for the site's own backend, used for authenticated requests when you are signed in. | Until you sign out or the session expires. | Strictly necessary — authentication state. |
__cf_bmObserved on collectorsroad.com | Cloudflare (our hosting/CDN provider) | Bot-management cookie set by Cloudflare to tell human visitors from automated traffic and keep the site available. | About 30 minutes. | Security cookie set by our infrastructure provider. It carries no advertising profile and is not controlled by this consent tool. | |
__dplObserved on collectorsroad.com | Hosting platform (deployment routing) | Pins your session to the deployed version of the site that served your first request, so assets and pages stay consistent while we ship updates. | Session / short-lived. | Strictly necessary — infrastructure cookie required to serve the site consistently. Carries no profile and is not controlled by this consent tool. | |
cf_clearancePossible — documented by the provider | Cloudflare (our hosting/CDN provider) | Records that a challenge (for example a bot check) has been passed, so you are not challenged again on every request. | Up to 1 year, depending on Cloudflare configuration. | Security cookie set by our infrastructure provider. Not controlled by this consent tool. | |
_tracking_consent / _cmp_aPossible — documented by the provider | Shopify (checkout domain) | Shopify's own record of the consent choice you made here, so the same choice applies when you continue to Shopify's checkout. | Set by Shopify on their checkout domain, typically up to 1 year. | Written on Shopify's domain only after you make a choice, to carry that choice into checkout. |
Preferences
| Name | Type | Set by | Purpose | Retention | Basis |
|---|---|---|---|---|---|
cr-swipe-hint-seenUsed by this site | Session storage | Collector's Road | Notes that the one-off 'swipe the photographs' hint has already been shown on touch devices, so it is not repeated. | Cleared when you close the tab. | Optional — only written after you allow Preferences storage. |
Analytics
Nothing in this category. We store nothing for this purpose.
Marketing
Nothing in this category. We store nothing for this purpose.
Provider and security cookies
Our hosting and CDN provider, Cloudflare, may set security cookies such as __cf_bm and cf_clearance to separate people from bots and to remember that a challenge has been passed. These protect availability rather than track you, and they are outside the control of this consent tool. Our hosting platform also sets a short-lived __dpl cookie so you keep being served one consistent deployed version of the site. Entries above are labelled to show whether we have actually observed them on collectorsroad.com or whether the provider merely documents them as possible.
Checkout and Shopify
Payment and checkout are handled by Shopify. When you make a choice here we pass it to Shopify using their official customer privacy interface, so the same analytics, preferences and marketing decision applies to the checkout you are taken to. Any cookies you see on Shopify's checkout domain are set there, under Shopify's own policy.
Fonts and other requests
Typefaces are served from our own domain, so no font request is made to Google. Product photography is served from Shopify's image CDN, which sets no cookies on this site.
Clearing everything
You can remove all of the above at any time by clearing site data for this domain in your browser settings. Emptying your bag and removing saved items deletes those entries immediately.

