This Cookie Policy explains how Bonideco uses cookies, pixels, local storage and similar technologies, why they are used, how long they operate and how you can manage your choices.
Website: bonideco.ee
1. Controller
- Seller / data controller
- MB “Bonideco”
- Company code
- 306048688
- Registered address
- Servečės g. 2, LT-02121 Vilnius, Lithuania
- [email protected]
- Telephone
- +370 632 51053
2. What these technologies are
Cookies are small text files stored by a browser. Similar technologies include local or session storage, pixels, tags, SDKs and server-side events. They may be first-party, set by this domain, or third-party, controlled by an external provider.
A technology’s actual name and duration may vary with the Website, browser and provider configuration. The consent-management list shown on the Website is the most specific current inventory for your device.
3. Legal basis and categories
Strictly necessary technologies are used without consent only where objectively required to provide a service you requested, secure the Website, maintain a basket, authenticate a session or remember privacy choices. Where applicable, this is also supported by contract-related necessity or legitimate interests.
Functional, analytics and marketing technologies are activated only after the required consent. Rejecting them does not prevent core browsing and purchasing. New non-essential technologies are not activated merely because they are mentioned in this Policy; they must first be assessed, categorised and added to consent controls.
4. Managing consent
You can accept, reject or customise non-essential categories using the cookie settings available on the Website and change your choice later. Withdrawal does not affect processing already lawfully carried out. We stop setting or using the relevant technologies as far as technically possible; providers may retain earlier data under their own retention rules and data-subject procedures.
5. Essential Magento technologies
| Examples | Purpose |
|---|---|
| PHPSESSID, form_key | Session continuity and protection against forged requests |
| X-Magento-Vary, private_content_version, section_data_ids | Correct customer-specific content and cache updates |
| mage-cache-storage, mage-cache-storage-section-invalidation, mage-cache-sessid | Local storage and refresh of basket and customer sections |
| recently_viewed_product, product_data_storage | Requested product-navigation functions where enabled |
| user_allowed_save_cookie, store | Remembering consent capability and selected store/language |
Some entries are session technologies; others remain only as long as technically necessary or according to the current Magento configuration.
6. Analytics and advertising partners
| Provider / examples | Purpose | Typical maximum |
|---|---|---|
| Google Analytics: _ga, _ga_<ID> | Audience and session statistics | Up to 2 years |
| _gid, _gat, _dc_gtm_<ID> | Visitor distinction, request throttling and tag operation | 24 hours / 1 minute |
| Google Ads: _gcl_au, _gcl_aw, _gac_* | Click and conversion attribution | Usually up to 90 days |
| Google / DoubleClick: IDE | Advertising, frequency and campaign measurement | Usually up to 13 months in the EEA/UK |
| Meta Pixel: _fbp, _fbc | Conversion measurement, audiences and remarketing | Usually up to 90 days |
| TikTok / Pangle: _ttp, ttcsid_*, ttclid, _pangle | Campaign measurement, optimisation and audiences | Up to 13 months from last use |
These providers may receive IP address, page URL, browser or device data, identifiers and consented event data. Depending on configuration and consent, pseudonymised or hashed contact and conversion identifiers may be sent for matching. We do not send card security data, account passwords or customer-support correspondence to advertising partners.
7. Omnisend, forms and newsletters
Omnisend may be used for subscription forms, newsletters and consented behavioural automation. The email address itself is not a cookie. Browser technologies may remember that a form was closed or completed, or—with the required consent—recognise a contact and record events.
omnisend-form-{id}-closed-at,-filled-atand-teaser-closed-at: form display choices, up to 365 days where configured.omnisendSessionID: session recognition, typically about 30 minutes.omnisendContactIDand page-view/event storage: identification and behavioural automation only with the required consent; duration follows the active configuration and consent inventory.
8. Embedded content and transfers
Payments, finance, maps, video, social posts, reviews, chat, recommendations or CAPTCHA may involve third-party technology. Non-essential embedded content is blocked until consent where required. A tool strictly necessary for a function you request receives only data needed for that function.
Providers may process data outside the EEA. Relevant transfers are handled as explained in the Privacy Policy, using an adequacy decision or appropriate safeguards such as standard contractual clauses where required.
9. Browser controls and consequences
You may also delete or block cookies in browser settings. Blocking essential technologies can prevent login, basket, language selection, checkout or other core functions. Rejecting analytics or marketing technologies should not prevent ordinary browsing or purchasing. Browser privacy signals are honoured where legally required and technically supported.
10. Rights, contact and updates
Your data-protection rights and complaint channels are described in the Privacy Policy. Questions may be sent to [email protected].
We update this Policy and the consent inventory when providers, names, purposes, recipients, retention or configuration change. The current consent interface is reviewed alongside this document.