Cookie Policy
Cookie Policy
This Cookie Policy describes the types of cookies and tracking technologies used by the website www.caffeborbone.mom (the "Website"), their purposes, retention periods and the ways in which users may manage or withdraw their consent.
This document is prepared pursuant to Articles 6, 7 and 13 of Regulation (EU) 2016/679 ("GDPR"), Article 122 of Legislative Decree 196/2003 ("Privacy Code"), as amended by Legislative Decree 101/2018, Directive 2002/58/EC ("ePrivacy") and the Guidelines on the use of cookies and other tracking tools issued by the Italian Data Protection Authority on 10 June 2021.
1. Data Controller
The Data Controller for the data collected through cookies is: Caffè Borbone S.r.l.
● Registered office: Zona ASI, Loc. Pascarola snc – 80023 Caivano (NA), Italy
● Naples Companies Register: no. 567049
● VAT No. / Tax Code: 07097160639
● Email: privacy@caffeborbone.it
● Certified email: privacy.caffeborbone@pec.it
● Website: www.caffeborbone.mom
● Data Protection Officer (DPO): dpo@caffeborbone.it
For any request concerning the processing of personal data or the exercise of the rights set out in Articles 15-22 of the GDPR, users may contact the Controller or the DPO at the addresses indicated above.
For information on the processing of personal data for purposes other than cookies, please refer to the general Privacy Policy available at: https://sites.google.com/caffeborbone.it/gdpr/documenti/informative/privacy-policy.
2. What are cookies and tracking technologies?
Cookies are small text files that the websites visited send to the user's device (computer, tablet, smartphone), where they are stored so that they can be sent back to the same websites on the next visit. In addition to cookies, the Website may use other identifiers or tracking technologies (e.g. pixels, tags, SDKs, local storage technologies) that allow information to be collected from, or stored on, the user's device.
2.1 Classification by the party installing them
● First-party cookies: installed directly by the Website operator.
● Third-party cookies: installed by parties other than the Website operator (e.g. Google, TikTok, Criteo), acting as independent controllers or processors.
2.2 Classification by purpose
● Technical / necessary cookies: essential for the operation of the Website and the provision of the services requested. They do not require the user's consent (Article 122 of the Privacy Code).
● Functional cookies: improve the experience by enabling additional functions (support chat, wishlist, loyalty programme). If they are not strictly necessary, they are subject to consent.
● Analytics / statistical cookies: collect aggregated information on how users use the Website. They require consent, except in cases of first-party analytics with anonymised IP addresses that can be treated as technical cookies.
● Marketing / profiling cookies: track browsing to create user profiles and display personalised advertising messages, including on other websites. They always require prior consent.
3. Legal basis for processing
● For technical and necessary cookies, the legal basis is the Controller's legitimate interest (Article 6(1)(f) GDPR) in providing the service requested by the user, as well as compliance with a legal obligation (Article 6(1)(c) GDPR).
● For functional, analytics and marketing cookies, the legal basis is the user's consent (Article 6(1)(a) GDPR), which is freely given, specific and informed, and may be withdrawn at any time.
4. Consent management
When the user first accesses the Website, a cookie banner, managed through the iubenda Cookie Solution platform, is displayed and allows the user to:
- accept all cookies;
- reject all non-necessary cookies (keeping only technical cookies active);
- customise choices by individual purpose category.
Until the user makes a choice, only technical cookies are installed on the Website. Analytics and marketing cookies are activated only after consent has been obtained.
The user may change or withdraw any consent already given at any time, with the same ease with which it was granted, by clicking at any time on the link "Review your cookie choices" in the footer of each page of the Website, which reopens the iubenda preference management panel. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
5. List of cookies used
The following list shows the cookies and tracking technologies detected on the Website as of the update date of this policy. The retention periods indicated correspond to the standard values declared by the respective providers and may vary.
5.1 Technical and necessary cookies (do not require consent)
| Name | Provider | Purpose | Duration |
| cart_currency | Caffè Borbone / Shopify | Stores the currency selected for the cart | Session / 2 weeks |
| localization | Caffè Borbone / Shopify | Stores the country/language preference | 1 year |
| shopify_client_id | Shopify | Technical client identifier for store operation | Persistent |
| secure_customer_sig, _secure_session_id | Shopify | User session, account area and checkout management | Session / 1 year |
| _iub_cs-77863493 | iubenda | Stores cookie consent preferences | 1 year |
| _iub_previous_preference_id | iubenda | Stores proof of the consent given | 1 year |
| marketing_accepted | Caffè Borbone / Shopify | Stores the user's marketing acceptance choice | Persistent |
| cart | Shopify | Cart identification token | 2 weeks |
| cart_sig, cart_ts | Shopify | Cart signature and timestamp for integrity and security | 2 weeks |
| _tracking_consent | Shopify | Stores tracking consent preferences | 1 year |
5.2 Cart and checkout cookies (Shopify)
When accessing the cart and, especially, the checkout, the Shopify platform sets additional technical and necessary cookies, largely HttpOnly (not readable via scripts but documented by the provider), which are essential to securely complete the order:
| Name | Provider | Purpose | Duration |
| _shopify_essential | Shopify | Essential website and checkout operation, session management and security | Session / 1 year |
| _secure_session_id | Shopify | Secure session during the checkout process | 24 hours |
| secure_customer_sig | Shopify | Maintains secure access for registered users | 1 year |
| keep_alive | Shopify | Keeps the session active during browsing/checkout | Session / 30 min |
| checkout_session_token__* | Shopify | Stores the status of the ongoing checkout | Session |
| _landing_page | Shopify | Tracks the landing page for attribution purposes (analytics) | 2 weeks |
| _orig_referrer | Shopify | Tracks the original referrer for attribution purposes (analytics) | 2 weeks |
In addition to cookies, the Website uses identifiers in the browser's local storage, including: cartToken, trackedSourceId, __ui (cart management and traffic source attribution, checkout); GW_TOKEN, GW_RECENTLY_VIEWED_PRODUCTS (Growave - loyalty and recently viewed products); __kla_id, __kla_viewed, __kla_viewed_reviewed_items, klaviyoOnsite (Klaviyo); theme:recently-viewed-products, cp_deals_product (theme). Although these identifiers are not cookies, they are tracking technologies subject to the same consent rules when they are not strictly necessary.
5.3 Functional cookies (require consent)
| Name | Provider | Purpose | Duration |
| GW_TOKEN and related identifiers | Growave | Loyalty programme, reviews and wishlist | Session / 1 year |
| Chat cookies | Gorgias | Customer support / live chat widget | Session / persistent |
| Subscription cookies | Recharge | Management of purchases and recurring subscriptions | Session |
5.4 Analytics / statistical cookies (require consent)
| Name | Provider | Purpose | Duration |
| _ga | Google Analytics 4 | Distinguishes unique users | 2 years |
| _ga_KR9CPCFKJS | Google Analytics 4 | Maintains GA4 session state | 2 years |
| _shopify_s | Shopify | Internal analytics: session duration | 30 minutes |
| _shopify_y | Shopify | Internal analytics: identifies unique visitor | 1 year |
| FPGSID | Google (tagging server-side) | GA4 session ID set server-side | Session |
| FPLC | Google (tagging server-side) | Cross-domain linker cookie in server-side mode | ~20 hours |
5.5 Marketing / profiling cookies (require consent)
| Name | Provider | Purpose | Duration |
| _gcl_au | Google Ads / AdSense | Conversion Linker: measures ad conversions | 3 months |
| FPAU | Google (server-side) | Ad conversion attribution (server-side) | 3 months |
| _ttp | TikTok | TikTok Pixel: identifier for measurement and retargeting | 13 months |
| _tt_enable_cookie | TikTok | Enables TikTok Pixel functionality | 13 months |
| ttcsid | TikTok | Pixel session state for advertising purposes | 1 year |
| ttcsid_CNJFACRC77U9NURULG60 | TikTok | Session state for the specific pixel ID | 1 year |
| _uetsid | Microsoft Advertising (UET) | Session ID for conversion tracking | 1 day |
| _uetvid | Microsoft Advertising (UET) | Unique visitor ID for retargeting | 13 months |
| cto_bundle | Criteo | Retargeting: collects an identifier for personalized ads | 13 months |
| __kla_id | Klaviyo | Identifies the user for email/SMS marketing and personalization | 2 years |
| Pixel/cookie 9gtb.com | 9gtb.com (Gorgias) | Third-party tracking/marketing script | Session/Persistent |
6. Third-party cookies and data transfers
Some of the tools listed above are provided by third parties who may process the data as independent data controllers and, in some cases, transfer them to non-EU countries (in particular, the United States). Where applicable, such transfers take place on the basis of the Standard Contractual Clauses (SCCs) approved by the European Commission or the provider's adherence to the EU-U.S. Data Privacy Framework.
To learn about the processing methods and the safeguards adopted by each third party, please refer to their respective privacy policies:
- Google (Analytics, Ads): https://policies.google.com/privacy — opt-out: https://tools.google.com/dlpage/gaoptout
- TikTok: https://www.tiktok.com/legal/page/eea/privacy-policy/it
- Microsoft Advertising: https://privacy.microsoft.com/it-it/privacystatement
- Criteo: https://www.criteo.com/privacy/
- Klaviyo: https://www.klaviyo.com/legal/privacy-policy
- Shopify: https://www.shopify.com/legal/privacy
- iubenda: https://www.iubenda.com/privacy-policy
- Growave: https://www.growave.io/privacy-policy
- Gorgias: https://www.gorgias.com/privacy
- Recharge: https://rechargepayments.com/privacy-policy
7. Managing cookies through the browser
In addition to the Website's preference panel, users can manage or disable cookies directly through their browser settings. Disabling technical cookies may affect the proper functioning of the Website.
- Google Chrome: https://support.google.com/chrome/answer/95647
- Mozilla Firefox: https://support.mozilla.org/it/kb/Gestione%20dei%20cookie
- Microsoft Edge: https://support.microsoft.com/it-it/microsoft-edge
- Safari: https://support.apple.com/it-it/guide/safari/sfri11471/mac
8. Data subject rights
As a data subject, the user has the right to: access their personal data (Art. 15), obtain rectification (Art. 16) or erasure (Art. 17), restrict processing (Art. 18), object to processing (Art. 21), exercise data portability (Art. 20), and withdraw consent at any time. The user also has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali - www.garanteprivacy.it).
To exercise their rights, the user can write to: privacy@caffeborbone.it or contact the DPO at: dpo@caffeborbone.it.
Last updated: 31/07/2026
The Data Controller reserves the right to modify or update this Cookie Policy, including as a result of changes in legislation or in the tools used on the Website. Any changes will be published on this page indicating the update date. Users are invited to consult this page periodically.



