Cookie Policy

Cookie Policy

This Cookie Policy describes the types of cookies and tracking technologies used by the website www.caffeborbone.mom (the "Website"), their purposes, retention periods and the ways in which users may manage or withdraw their consent.

This document is prepared pursuant to Articles 6, 7 and 13 of Regulation (EU) 2016/679 ("GDPR"), Article 122 of Legislative Decree 196/2003 ("Privacy Code"), as amended by Legislative Decree 101/2018, Directive 2002/58/EC ("ePrivacy") and the Guidelines on the use of cookies and other tracking tools issued by the Italian Data Protection Authority on 10 June 2021.

1. Data Controller

The Data Controller for the data collected through cookies is: Caffè Borbone S.r.l.

      Registered office: Zona ASI, Loc. Pascarola snc – 80023 Caivano (NA), Italy

      Naples Companies Register: no. 567049

      VAT No. / Tax Code: 07097160639

      Email: privacy@caffeborbone.it

      Certified email: privacy.caffeborbone@pec.it

      Website: www.caffeborbone.mom

      Data Protection Officer (DPO): dpo@caffeborbone.it

For any request concerning the processing of personal data or the exercise of the rights set out in Articles 15-22 of the GDPR, users may contact the Controller or the DPO at the addresses indicated above.

For information on the processing of personal data for purposes other than cookies, please refer to the general Privacy Policy available at: https://sites.google.com/caffeborbone.it/gdpr/documenti/informative/privacy-policy.

2. What are cookies and tracking technologies?

Cookies are small text files that the websites visited send to the user's device (computer, tablet, smartphone), where they are stored so that they can be sent back to the same websites on the next visit. In addition to cookies, the Website may use other identifiers or tracking technologies (e.g. pixels, tags, SDKs, local storage technologies) that allow information to be collected from, or stored on, the user's device.

2.1 Classification by the party installing them

      First-party cookies: installed directly by the Website operator.

      Third-party cookies: installed by parties other than the Website operator (e.g. Google, TikTok, Criteo), acting as independent controllers or processors.

2.2 Classification by purpose

      Technical / necessary cookies: essential for the operation of the Website and the provision of the services requested. They do not require the user's consent (Article 122 of the Privacy Code).

      Functional cookies: improve the experience by enabling additional functions (support chat, wishlist, loyalty programme). If they are not strictly necessary, they are subject to consent.

      Analytics / statistical cookies: collect aggregated information on how users use the Website. They require consent, except in cases of first-party analytics with anonymised IP addresses that can be treated as technical cookies.

      Marketing / profiling cookies: track browsing to create user profiles and display personalised advertising messages, including on other websites. They always require prior consent.

3. Legal basis for processing

      For technical and necessary cookies, the legal basis is the Controller's legitimate interest (Article 6(1)(f) GDPR) in providing the service requested by the user, as well as compliance with a legal obligation (Article 6(1)(c) GDPR).

      For functional, analytics and marketing cookies, the legal basis is the user's consent (Article 6(1)(a) GDPR), which is freely given, specific and informed, and may be withdrawn at any time.

4. Consent management

When the user first accesses the Website, a cookie banner, managed through the iubenda Cookie Solution platform, is displayed and allows the user to:

  • accept all cookies;
  • reject all non-necessary cookies (keeping only technical cookies active);
  • customise choices by individual purpose category.

Until the user makes a choice, only technical cookies are installed on the Website. Analytics and marketing cookies are activated only after consent has been obtained.

The user may change or withdraw any consent already given at any time, with the same ease with which it was granted, by clicking at any time on the link "Review your cookie choices" in the footer of each page of the Website, which reopens the iubenda preference management panel. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

5. List of cookies used

The following list shows the cookies and tracking technologies detected on the Website as of the update date of this policy. The retention periods indicated correspond to the standard values declared by the respective providers and may vary.

5.1 Technical and necessary cookies (do not require consent)

Name Provider Purpose Duration
cart_currency Caffè Borbone / Shopify Stores the currency selected for the cart Session / 2 weeks
localization Caffè Borbone / Shopify Stores the country/language preference 1 year
shopify_client_id Shopify Technical client identifier for store operation Persistent
secure_customer_sig, _secure_session_id Shopify User session, account area and checkout management Session / 1 year
_iub_cs-77863493 iubenda Stores cookie consent preferences 1 year
_iub_previous_preference_id iubenda Stores proof of the consent given 1 year
marketing_accepted Caffè Borbone / Shopify Stores the user's marketing acceptance choice Persistent
cart Shopify Cart identification token 2 weeks
cart_sig, cart_ts Shopify Cart signature and timestamp for integrity and security 2 weeks
_tracking_consent Shopify Stores tracking consent preferences 1 year

 

5.2 Cart and checkout cookies (Shopify)

When accessing the cart and, especially, the checkout, the Shopify platform sets additional technical and necessary cookies, largely HttpOnly (not readable via scripts but documented by the provider), which are essential to securely complete the order:

Name Provider Purpose Duration
_shopify_essential Shopify Essential website and checkout operation, session management and security Session / 1 year
_secure_session_id Shopify Secure session during the checkout process 24 hours
secure_customer_sig Shopify Maintains secure access for registered users 1 year
keep_alive Shopify Keeps the session active during browsing/checkout Session / 30 min
checkout_session_token__* Shopify Stores the status of the ongoing checkout Session
_landing_page Shopify Tracks the landing page for attribution purposes (analytics) 2 weeks
_orig_referrer Shopify Tracks the original referrer for attribution purposes (analytics) 2 weeks

 

In addition to cookies, the Website uses identifiers in the browser's local storage, including: cartToken, trackedSourceId, __ui (cart management and traffic source attribution, checkout); GW_TOKEN, GW_RECENTLY_VIEWED_PRODUCTS (Growave - loyalty and recently viewed products); __kla_id, __kla_viewed, __kla_viewed_reviewed_items, klaviyoOnsite (Klaviyo); theme:recently-viewed-products, cp_deals_product (theme). Although these identifiers are not cookies, they are tracking technologies subject to the same consent rules when they are not strictly necessary.

5.3 Functional cookies (require consent)

Name Provider Purpose Duration
GW_TOKEN and related identifiers Growave Loyalty programme, reviews and wishlist Session / 1 year
Chat cookies Gorgias Customer support / live chat widget Session / persistent
Subscription cookies Recharge Management of purchases and recurring subscriptions Session

5.4 Analytics / statistical cookies (require consent)

Name Provider Purpose Duration
_ga Google Analytics 4 Distinguishes unique users 2 years
_ga_KR9CPCFKJS Google Analytics 4 Maintains GA4 session state 2 years
_shopify_s Shopify Internal analytics: session duration 30 minutes
_shopify_y Shopify Internal analytics: identifies unique visitor 1 year
FPGSID Google (tagging server-side) GA4 session ID set server-side Session
FPLC Google (tagging server-side) Cross-domain linker cookie in server-side mode ~20 hours

 

5.5 Marketing / profiling cookies (require consent)

Name Provider Purpose Duration
_gcl_au Google Ads / AdSense Conversion Linker: measures ad conversions 3 months
FPAU Google (server-side) Ad conversion attribution (server-side) 3 months
_ttp TikTok TikTok Pixel: identifier for measurement and retargeting 13 months
_tt_enable_cookie TikTok Enables TikTok Pixel functionality 13 months
ttcsid TikTok Pixel session state for advertising purposes 1 year
ttcsid_CNJFACRC77U9NURULG60 TikTok Session state for the specific pixel ID 1 year
_uetsid Microsoft Advertising (UET) Session ID for conversion tracking 1 day
_uetvid Microsoft Advertising (UET) Unique visitor ID for retargeting 13 months
cto_bundle Criteo Retargeting: collects an identifier for personalized ads 13 months
__kla_id Klaviyo Identifies the user for email/SMS marketing and personalization 2 years
Pixel/cookie 9gtb.com 9gtb.com (Gorgias) Third-party tracking/marketing script Session/Persistent

 

6. Third-party cookies and data transfers

Some of the tools listed above are provided by third parties who may process the data as independent data controllers and, in some cases, transfer them to non-EU countries (in particular, the United States). Where applicable, such transfers take place on the basis of the Standard Contractual Clauses (SCCs) approved by the European Commission or the provider's adherence to the EU-U.S. Data Privacy Framework.

To learn about the processing methods and the safeguards adopted by each third party, please refer to their respective privacy policies:

 

7. Managing cookies through the browser

In addition to the Website's preference panel, users can manage or disable cookies directly through their browser settings. Disabling technical cookies may affect the proper functioning of the Website.

 

8. Data subject rights

As a data subject, the user has the right to: access their personal data (Art. 15), obtain rectification (Art. 16) or erasure (Art. 17), restrict processing (Art. 18), object to processing (Art. 21), exercise data portability (Art. 20), and withdraw consent at any time. The user also has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali - www.garanteprivacy.it).

To exercise their rights, the user can write to: privacy@caffeborbone.it or contact the DPO at: dpo@caffeborbone.it.

 

Last updated: 31/07/2026

 

The Data Controller reserves the right to modify or update this Cookie Policy, including as a result of changes in legislation or in the tools used on the Website. Any changes will be published on this page indicating the update date. Users are invited to consult this page periodically.