Cookie Policy

vaticandesign.com

This Cookie Policy explains what cookies and similar technologies are used on vaticandesign.com, why, who provides them, and how you control them. It supplements our Privacy Policy, which explains who we are and how we process personal data generally.


1. Who is responsible

The website vaticandesign.com is operated by BIBLE SPA Dorota Mayer-Gawron, Mattew Pulis Street, Sliema SLM 3051, Malta, VAT MT31576318.

Orders delivered within Italy are fulfilled by DAYENU S.R.L.S., Borgo Santo Spirito 14, 00193 Roma (RM), P. IVA IT 17983511001, REA RM–1753957. The two companies are joint controllers to the extent described in the Privacy Policy.

Contact for both: dayenudesign@gmail.com


2. What cookies and similar technologies are

A cookie is a small text file stored on your device when you visit a website. It lets the site remember information between page loads — what is in your basket, whether you are logged in, what privacy choice you made.

We also use technologies that work in a similar way, and everything in this policy applies to them too:

  • local storage and session storage in your browser;
  • pixels and web beacons;
  • embedded content loaded from another website inside ours;
  • device and session identifiers, including those used for fraud detection.

First-party technologies are set by vaticandesign.com. Third-party technologies are provided by another organisation whose service is embedded in or called from our pages — Google, YouTube, Stripe or PayPal.


3. Your choices

When you first visit, a banner lets you:

  • Accept all optional technologies;
  • Deny all optional technologies; or
  • View preferences and choose category by category.

The categories are Necessary (always on), Preferences and Marketing. “Manage services” in the banner takes you to the technical listing in section 9, where individual services are shown.

Optional technologies are switched off by default and are not activated unless you consent. Closing the banner without choosing does not count as consent and does not activate anything optional.

Rejecting optional cookies does not affect essential website, account, basket or checkout functions. Optional third-party content — the Google map and embedded YouTube videos — will remain unavailable until you consent, and a placeholder is shown in its place.

Strictly necessary technologies do not require consent because they are needed to deliver a function you asked for: keeping a basket, securing a login session, processing a payment you selected, or recording your privacy choice.

You can change or withdraw consent at any time via “Cookie settings” in the footer of any page, or from the panel in section 3 of this policy. Withdrawing consent:

  • does not affect the lawfulness of processing carried out beforehand;
  • stops the relevant services from loading in future;
  • does not automatically delete cookies a third party already stored — remove those through your browser (section 9).

4. Strictly necessary — always active

Cookie or technologyProviderPurposeDuration
woocommerce_cart_hashvaticandesign.com / WooCommerceDetects when the basket contents changeSession
woocommerce_items_in_cartvaticandesign.com / WooCommerceRecords that the basket is not emptySession
wp_woocommerce_session_*vaticandesign.com / WooCommerceLinks you to the basket and order data held on our server2 days
wordpress_test_cookievaticandesign.com / WordPressChecks whether your browser accepts cookiesSession
wordpress_logged_in_*vaticandesign.com / WordPressKeeps a registered customer logged inSession, or 14 days with “Remember me”
wordpress_sec_*vaticandesign.com / WordPressAuthenticates and secures the logged-in sessionSession
wp-settings-*, wp-settings-time-*vaticandesign.com / WordPressRemembers interface settings for logged-in users1 year
cmplz_banner-statusvaticandesign.com / ComplianzRecords that the cookie banner has been dealt with365 days
cmplz_consented_servicesvaticandesign.com / ComplianzRecords which services you consented to365 days
cmplz_policy_idvaticandesign.com / ComplianzRecords which version of this policy your choice relates to365 days
cmplz_functional, cmplz_preferences, cmplz_statistics, cmplz_marketingvaticandesign.com / ComplianzRecord your choice per category365 days
wpEmojiSettingsSupportsvaticandesign.com / WordPressRecords whether your browser can display emoji, so the page does not test it repeatedlySession storage — cleared when you close the tab

Payment technologies — necessary only during payment

These are loaded only on the basket and checkout pages, and only for the payment method you select. They are not loaded while you browse the shop, and we never use them for advertising or general visitor measurement.

Cookie or technologyProviderPurposeDuration
__stripe_midStripe Payments Europe, Ltd.Fraud prevention and risk assessment for a card transaction1 year
__stripe_sidStripe Payments Europe, Ltd.Fraud prevention within a single payment session30 minutes
ts, ts_c, tsrce, l7_az, x-pp-s, enforce_policy, LANG, nsid, cookie_checkPayPal (Europe) S.à r.l. et Cie, S.C.A.Processing the payment, session management, security and fraud preventionFrom session-only up to 3 years, depending on the individual cookie — see PayPal’s list linked below
PayPal FraudNet — the c.paypal.com script and the __paypal_storage__ entry in local storagePayPal (Europe) S.à r.l. et Cie, S.C.A.Device recognition used to detect fraudulent transactionsPersistent until you clear your browser storage

Stripe and PayPal set the names and lifetimes of their own cookies and may change them. Their current, authoritative lists:

  • Stripe — stripe.com/cookie-settings · stripe.com/privacy
  • PayPal — paypal.com/mt/legalhub/paypal/cookie-full · paypal.com/mt/legalhub/paypal/privacy-full

5. Preferences — set only after consent or your own action

Cookie or technologyProviderPurposeDuration
boxzilla_box_*vaticandesign.com / BoxzillaRemembers that you dismissed a particular pop-up so it is not shown to you again365 days
boxzilla_pageviewsvaticandesign.com / BoxzillaCounts pages viewed in the current visit, to decide when a pop-up may appearSession storage — cleared when you close the tab

If you reject this category, some non-essential interface choices are not remembered and a pop-up you closed may reappear on your next visit.


6. Statistics

We do not currently use Google Analytics or any other visitor analytics service. No statistics cookies are set, and the cookie banner therefore does not offer a statistics category at all.

If we introduce an analytics tool, we will add the category to the banner, ask for your consent, and update this policy — all before the tool goes live.


7. Marketing and traffic attribution — only with your consent

Order attribution

WooCommerce records how you reached our shop, so that we can tell which channel an order came from. This is done with the following first-party cookies. They are not necessary to operate the shop and are set only if you consent to this category.

CookieProviderPurposeDuration
sbjs_first, sbjs_first_addvaticandesign.com / WooCommerce Order AttributionRecords the source, medium, campaign and landing page of your first visit6 months
sbjs_current, sbjs_current_addvaticandesign.com / WooCommerce Order AttributionRecords the same details for your most recent visit6 months
sbjs_udatavaticandesign.com / WooCommerce Order AttributionRecords your user agent and, where available, IP address6 months
sbjs_sessionvaticandesign.com / WooCommerce Order AttributionCounts pages viewed in the current session and records the current page30 minutes from the last page view
sbjs_migrationsvaticandesign.com / WooCommerce Order AttributionTechnical marker of the data format version6 months

If you reject this category, we simply do not learn where your order came from. Nothing about the shop stops working.

Advertising

We do not use advertising pixels, behavioural advertising cookies or remarketing on vaticandesign.com. If we introduce them, they will remain disabled until you consent, and this policy will be updated first.


8. External media — only with your consent

External media is content loaded from another company’s servers inside our pages. Until you consent, it is blocked and replaced with a placeholder, and no connection to the provider is made.

Google Maps

We use Google Maps on our home page to show where the Vatican Design shop is.

Once you activate it, your browser connects directly to Google, which receives your IP address, browser and device information, the referring page and the time of the request. If you are signed in to a Google account, Google may link the interaction to that account.

CookieProviderPurposeDuration
NIDGoogle Ireland LimitedStores preferences and supports personalisation across Google services6 months from last use
__Secure-ENIDGoogle Ireland LimitedStores preferences and helps secure Google services13 months
AECGoogle Ireland LimitedDetects fraud, spam and abuse6 months
SOCSGoogle Ireland LimitedRecords your Google cookie choices13 months

If you do not consent, the map stays blocked. Our address is always written out in text on the page, so you lose nothing you need: Borgo Santo Spirito 14, 00193 Roma, Italy.

YouTube

Some of our pages embed YouTube videos. Once you activate them, your browser connects directly to Google and YouTube.

Cookie or technologyProviderPurposeDuration
VISITOR_INFO1_LIVEGoogle Ireland Limited / YouTubeEstimates your bandwidth and selects the video interface6 months
VISITOR_PRIVACY_METADATAGoogle Ireland Limited / YouTubeStores your cookie choice for YouTube6 months
YSCGoogle Ireland Limited / YouTubeCounts video views within a browsing sessionSession
__Secure-ROLLOUT_TOKENGoogle Ireland Limited / YouTubeManages the rollout of YouTube features6 months
yt-remote-*, yt.innertube::requests, yt.innertube::nextIdGoogle Ireland Limited / YouTubeStore player settings and identifiers for the embedded playerLocal storage — persistent until you clear it

You can always watch the same videos by opening them on YouTube directly.

Social media links

Our pages link to profiles on Instagram, Facebook, YouTube, LinkedIn and Behance. These are ordinary links, not embedded content — they load nothing and set no cookies on vaticandesign.com. If you click one, you leave our site and the platform processes your data under its own policies.

If we embed a social media feed or post in future, it will be blocked until you consent, and this policy will be updated before it goes live.


9. Full technical list of cookies

The tables in sections 4 to 8 are the authoritative description of what this website uses. They are maintained by hand and reviewed whenever we change a plugin or a provider.

Below is an additional technical listing generated by our consent tool from its own scan of the site. It is provided for transparency and it updates itself, but an automated scan cannot reach every page, so it may show fewer services than the tables above. Where the two differ, the tables above are the complete picture. If you spot a discrepancy, write to us and we will correct it.

Stripe

Functional

Usage

We use Stripe for payment processing.

Sharing data

For more information, please read the Stripe Privacy Statement.

Functional

Name
__stripe_mid
Expiration
1 year
Function
Provides fraud prevention and secure payment processing.
Name
__stripe_sid
Expiration
30 minutes
Function
Fraud prevention during a payment session

Miscellaneous

Purpose pending investigation

Usage

Sharing data

Sharing of data is pending investigation

Purpose pending investigation

Name
cmplz_functional
Expiration
365 days
Function
Name
cmplz_preferences
Expiration
365 days
Function
Name
cmplz_marketing
Expiration
365 days
Function
Name
cmplz_consented_services
Expiration
365 days
Function

10. Third-party providers and transfers outside the EEA

Where you activate external content or choose a payment method, data is sent to the relevant provider. Providers may process it outside the European Economic Area, in particular in the United States. Where that happens, the transfer relies on an adequacy decision of the European Commission, on Standard Contractual Clauses, or on another safeguard recognised under Chapter V GDPR.

The providers involved in the technologies described here:

  • Google Ireland Limited — Google Maps, YouTube;
  • Stripe Payments Europe, Ltd. — payment processing and fraud prevention;
  • PayPal (Europe) S.à r.l. et Cie, S.C.A. — payment processing and fraud prevention.

Depending on the service, they act as processors, independent controllers or joint controllers; their own privacy notices set out the details and the transfer safeguards they rely on.

The Complianz consent-management plugin runs on our own server. Its cookies are first-party and no data about you is sent to its supplier.

InPost and FedEx receive data in order to deliver your order. That is not cookie processing — no delivery-provider widget or script runs on this website — and it is described in our Privacy Policy.


11. Browser controls

You can also view, delete and block cookies in your browser. These settings apply per browser and per device:

  • Google Chrome — support.google.com/chrome/answer/95647
  • Mozilla Firefox — support.mozilla.org/kb/cookies-information-websites-store-on-your-computer
  • Safari on macOS — support.apple.com/guide/safari/sfri11471/mac
  • Safari on iPhone and iPad — support.apple.com/HT201265
  • Microsoft Edge — support.microsoft.com/microsoft-edge
  • Opera — help.opera.com/latest/web-preferences/#cookies
  • Chrome on Android — support.google.com/chrome/answer/114662

Blocking strictly necessary cookies will stop the account, basket and checkout from working. Deleting cookies also deletes the record of your consent choice, so the banner will appear again on your next visit.

The browser controls above are a fallback. The simplest way to change your mind about this website is “Cookie settings” in the footer, or the panel in section 3.


12. Server logs

Independently of cookies, our hosting infrastructure automatically records standard server logs: the URL requested, the date and time of the request and response, the HTTP status and any errors, the referring page, browser and operating system information, and the IP address.

Server logs are used only to operate, maintain and secure the website, to prevent abuse and to diagnose faults. They are kept no longer than necessary for those purposes, and longer only where needed to investigate a security incident, to establish or defend legal claims, or to comply with a legal obligation. They are not used to build profiles of individual visitors.


13. Changes to this policy

We update this policy when a service, plugin or provider is added or removed, when the purpose of a technology changes, when cookie names or durations change, or when the law changes.

Where a change introduces a new purpose or a new provider requiring consent, we ask for your choice again before activating it.

The current version and its date are always at vaticandesign.com/cookie-policy/.


14. Contact

Questions about this policy or about our use of cookies:

dayenudesign@gmail.com
Vatican Design, Borgo Santo Spirito 14, 00193 Roma, Italy
BIBLE SPA Dorota Mayer-Gawron, Mattew Pulis Street, Sliema SLM 3051, Malta — VAT MT31576318
DAYENU S.R.L.S., Borgo Santo Spirito 14, 00193 Roma (RM), Italy — P. IVA IT 17983511001, REA RM–1753957