Cookie Policy
Every cookie we set, what it does, and how long it sticks around.
Last updated · April 25, 2026
This policy explains which cookies (and similar local storage) Avafem sets, who set them, and what each one does. It pairs with our Privacy Policy — that has the bigger picture; this one has the table.
1. Cookie categories
- Essential. Required for the site to work — authentication, cart state, admin gating. Cannot be turned off; without these you can't sign in or check out.
- Functional. Remember your preferences (locale, currency, dismissed banners). Improve the experience but aren't strictly required.
- Analytics. Help us understand how the site is used. Off by default. Loads only when an admin enables analytics AND the visitor hasn't sent a Do-Not-Track header.
2. Cookies we set
| Cookie | Category | Party | Duration | Purpose |
|---|---|---|---|---|
_clerkdb_jwt | Essential | Third-party | Session + 7d | Member sign-in session (Clerk). |
avafemadminsession | Essential | First-party | 8 hours | Admin operator session, HMAC-signed. |
avafem_locale | Functional | First-party | 1 year | Language preference. |
avafem_currency | Functional | First-party | 1 year | Display currency override. |
avafem_cart | Essential | First-party | 30 days | Local cart contents. |
ga / ga_* | Analytics | Third-party | Up to 24 months | GA4 visitor + session counter, only when admin-enabled and DNT not sent. |
3. Plausible (cookieless)
When admins enable Plausible alongside or instead of GA4, no cookies are set. Plausible is cookieless by design and anchors on a daily-rotating salt of (URL hash + IP + User-Agent) so no cross-day visitor tracking is possible.
4. How to control cookies
- Browser-level. All major browsers let you block or auto-clear cookies. Be aware that disabling essential cookies will prevent sign-in and checkout from working.
- Do-Not-Track. Sending DNT=1 disables our analytics scripts entirely (server-side check before the script ever loads). Most browsers expose this in their privacy settings.
- Anonymise mode. Flip Privacy Shield on to make analytics + curator jobs operate on derived traits with direct identifiers stripped.
- Wipe local cart / locale. Clear site data for avafem.com from your browser; Avafem will re-bootstrap with defaults on next visit.
5. Changes
If we add a new third-party cookie we'll update the table and bump the "Last updated" date.