Cookies Policy
Effective Date : [TO BE FILLED ON LAUNCH DAY — YYYY-MM-DD] Last updated : [TO BE FILLED ON LAUNCH DAY — YYYY-MM-DD]
This Cookie Policy explains the very limited use of cookies and similar technologies on gigifrance.com (the "Site"), operated by UNISHOP LLC ("we", "us", or "GIGI FRANCE"). It complements our Privacy Policy.
1. What is a cookie?
A "cookie" is a small text file that a website places on your browser when you visit. Cookies are used to remember your preferences (e.g., your cart contents), to keep you logged in, or to provide aggregated statistics.
Similar technologies include localStorage, sessionStorage, and pixel tags. The principles below apply to all of these.
2. Our approach: minimal by design
We have deliberately chosen a minimal-cookie, no-tracking approach. The Site uses only the cookies strictly necessary to operate the cart, the secure checkout, and the admin interface. We do not use:
- Third-party advertising cookies
- Behavioral retargeting pixels (Meta Pixel, Google Ads, TikTok Pixel, etc.)
- Cross-site tracking
- Marketing analytics with personal identifiers
- Social media tracking cookies
Our analytics provider, Plausible, is cookieless by design and does not identify individual users.
3. Cookies we use
3.1 Strictly necessary cookies
These cookies are essential for core Site functionality and are exempt from consent requirements under U.S. state laws and applicable EU rules (ePrivacy Directive, CNIL guidance).
| Cookie | Purpose | Provider | Type | Duration |
|---|---|---|---|---|
cart-id | Identifies your guest cart so items persist across pages and between sessions | First-party (Site) | HTTP cookie | 7 days |
__Host-next-auth.csrf-token | Cross-site request forgery protection for the admin login | NextAuth (self-hosted) | HTTP cookie, secure, httpOnly | Session |
__Secure-next-auth.session-token | Maintains the admin session for authorized staff only — not set for regular Customers | NextAuth (self-hosted) | HTTP cookie, secure, httpOnly | 30 days max |
Stripe Checkout cookies (e.g. __stripe_mid, __stripe_sid) | Set by Stripe on the Stripe-hosted Checkout page to detect fraud and process the payment securely | Stripe, Inc. | Third-party (Stripe domain) | Session / 1 year (Stripe-defined) |
Important note on Stripe Checkout cookies : these are set by Stripe on *.stripe.com only when you proceed to checkout, not while browsing gigifrance.com. They are required for PCI-DSS-compliant secure payment processing and cannot be disabled while still allowing payment. See Stripe's Cookie Policy for details.
3.2 Analytics: cookieless
We use Plausible Analytics for aggregated traffic measurement. Plausible:
- Does not set any cookies
- Does not use a persistent identifier
- Does not collect personal data
- Does not track users across sessions or across other websites
- Stores only aggregate, anonymous counts (pages visited, country, referrer, device type)
See Plausible Data Policy for full details.
3.3 LocalStorage / sessionStorage
The Site may use browser localStorage for minor UX preferences (e.g., dismissed informational banners). No personal data is stored in localStorage. Clearing your browser's local storage at any time has no consequence on your Orders.
4. Cookies we do NOT use
For transparency, we explicitly confirm that we do not use:
- Google Analytics, GA4, Adobe Analytics, Mixpanel, or similar : we use Plausible (cookieless) instead.
- Meta Pixel / Facebook Pixel, TikTok Pixel, X (Twitter) Pixel, Pinterest Tag, LinkedIn Insight Tag : we do not currently run any paid social retargeting campaigns. If we adopt any of these in the future, this Cookie Policy and our Privacy Policy will be updated and an appropriate consent mechanism will be deployed.
- Google Ads tags, Microsoft Advertising UET, Criteo, AdRoll, or any retargeting service
- Hotjar, Mouseflow, FullStory, Crazy Egg, or any session-recording / heatmap tool
- Intercom, Drift, or any chat tool that uses persistent identifiers
- A/B testing platforms with personal identifiers
5. Why we don't show a consent banner
Most websites in the U.S. and EU now display a cookie consent banner. We have intentionally chosen not to display one, because:
- Our only cookies are strictly necessary under both California (CCPA/CPRA), other U.S. state laws, and the EU ePrivacy Directive. Strictly necessary cookies do not require consent in either jurisdiction.
- Our analytics provider (Plausible) is cookieless and anonymous.
- We believe an unnecessary consent banner adds friction without privacy benefit — and consent banners themselves often constitute "dark pattern" interfaces if not designed perfectly. We prefer to design our Site so that no banner is needed at all.
A small, non-intrusive notice in the Site footer informs visitors of this approach and links to this Cookie Policy and to the Privacy Policy.
If we ever introduce a cookie that requires consent (advertising, retargeting, etc.), we will deploy a fully compliant consent management platform with clear "Accept", "Reject", and granular controls — all presented at the same visual level — before any non-essential cookie is set.
6. Browser controls
You can control or block cookies through your browser settings. Note that blocking strictly necessary cookies may impair core Site functionality (e.g., your cart may not persist; the admin interface will not function).
Browser-specific instructions:
- Chrome : Settings → Privacy and security → Cookies and other site data
- Safari : Settings → Privacy → Manage Website Data
- Firefox : Settings → Privacy & Security → Cookies and Site Data
- Edge : Settings → Cookies and site permissions
You can also use the Global Privacy Control (GPC) signal in your browser. We honor GPC signals for opt-out purposes where applicable. Since we do not sell or share personal information for cross-context behavioral advertising, the GPC signal does not change our processing — but we register it as confirmation of your preference.
7. Updates to this Cookie Policy
We will update this Cookie Policy if our cookie usage changes. The "Last updated" date at the top of this page reflects the most recent revision. Material changes will also be announced in the Site footer for 14 days following the update.
8. Contact
For any cookie-related question:
Email : contact@gigifrance.com (subject line: "Cookie Policy") Postal mail : UNISHOP LLC, 102 Gold Ave SW #399, Albuquerque, NM 87102, United States
Internal note (juriste opinion on the consent banner question for GIGI) :