Privacy, clearly explained
Last reviewed: 21 August 2026
Essential technology remains available so the store, security and checkout work. Visitors in the EU, EEA and United Kingdom are asked before optional analytics, marketing and support integrations load. AU, NZ and other regions do not see the popup. If the visitor country cannot be confirmed, optional integrations stay blocked until a choice is made. Cloudflare's cookie-free Web Analytics beacon does not store a browser identifier and can continue measuring site performance without the optional cookie choice.
Security, consent preferences, checkout and services you explicitly request.
Support chat, address assistance and features that improve how the store works.
Helps us understand performance and how visitors use the storefront.
Measures advertising, affiliate referrals and relevant campaign activity.
Some entries are conditional: payment, security, affiliate and Support identifiers appear only when that feature is used. Names containing brackets or words such as “identifier” are provider-controlled patterns and can vary by account or browser.
| Name or pattern | Provider | Category | Storage | Duration | Purpose |
|---|---|---|---|---|---|
| fnb-marketing-consent-v1 | Frank and Beans | Essential | Local storage | Until cleared | Remembers whether optional tracking was accepted or rejected. |
| recentSalesNotificationDismissed | Frank and Beans | Essential | Session storage | Browser tab session | Remembers that the recent-sales notice was dismissed in the current tab. |
| gc-flags | Frank and Beans / GraphCommerce | Essential | Local storage | Until cleared | Stores storefront display and compatibility flags used by site features. |
| __cf_bm | Cloudflare | Essential | Cookie, when bot protection requires it | 30 minutes of inactivity | Supports bot detection and protects the storefront from malicious traffic. |
| cf_clearance | Cloudflare | Essential | Cookie, after a security challenge | Configured challenge period | Remembers that a visitor passed a Cloudflare security challenge. |
| Cloudflare Web Analytics beacon | Cloudflare | Analytics | No cookie or local storage | No browser identifier retained | Measures performance and Core Web Vitals without client-side identifiers. |
| _ga, _ga_<container-id> | Google Analytics | Analytics | First-party cookies | Up to 2 years | Distinguishes visitors and preserves analytics session state. |
| _clck, _clsk | Microsoft Clarity | Analytics | First-party cookies | Up to 1 year / 1 day | Associates page views with a pseudonymous visitor and session. |
| CLID, ANONCHK, MR, MUID, SM | Microsoft Clarity | Analytics | Third-party cookies | Session to 13 months, depending on cookie | Supports Clarity visitor recognition, session continuity and Microsoft ID syncing. |
| _fbp, _fbc | Meta | Marketing | First-party cookies | 90 days | Measures advertising conversions and identifies browsers and ad-click referrals. |
| _gcl_au and Google advertising identifiers | Google Ads / DoubleClick | Marketing | First- and third-party cookies | Usually 90 days; some provider cookies last up to 13 months | Measures ad clicks, conversions and campaign effectiveness. |
| _uetvid, _uetvid_exp, _uetsid, _uetsid_exp, _uetmsclkid, MUID, MSPTC | Microsoft Advertising | Marketing | First- and third-party cookies | Session to 13 months; click ID up to 90 days | Measures Bing advertising visits, conversions and remarketing audiences. |
| __kla_id | Klaviyo | Marketing | First-party cookie | Up to 2 years (browser limits may shorten this) | Identifies visitors after a form submission or tracked email/SMS click. |
| _kx | Klaviyo | Marketing | URL value and session storage | Browser tab session | Connects a tracked Klaviyo email or SMS click to onsite activity. |
| Commission Factory attribution identifier | Commission Factory | Marketing | Cookie or equivalent attribution identifier after an affiliate referral | Program setting; commonly 30 days | Attributes an eligible purchase to the referring affiliate. |
| ZD-suid, ZD-buid | Zendesk Web Widget | Functional | Browser storage | 20 minutes / until cleared | Maintains Zendesk session and device identifiers for the Support widget. |
| ZD-store, ZD-settings, ZD-sendApiBlips | Zendesk Web Widget Classic | Functional | Local storage | Until cleared | Keeps the Support widget presentation consistent and reduces duplicate requests. |
| __zlcmid, __zlcprivacy, __zlcstore | Zendesk Chat | Functional | Cookies and local storage when chat is used | Up to 1 year / until cleared | Authenticates the chat visitor and remembers chat privacy and account settings. |
| zte2095, AWSALB, AWSALBCORS, _answer_bot_service_session | Zendesk Chat / Answer Bot | Functional | Session cookies when chat is used | Session | Maintains a stable Support and Answer Bot session. |
| Provider security and session identifiers | Braintree, PayPal, Afterpay, Zip and Klarna | Essential | Cookies or browser storage only when the payment service is requested | Session or provider-defined fraud-prevention period | Provides checkout, payment authentication, fraud prevention and instalment information. |
| Google Maps session and security identifiers | Google Maps Platform | Functional | Provider cookies when address autocomplete is used | Session to provider-defined duration | Provides address suggestions during checkout. |
The catalogue is based on the storefront code, the services observed on AU and NZ, and current provider documentation. Providers may change identifiers as their services evolve, so we review this page when tracking or checkout services change.
Read our Privacy Policy for information about personal data, access and deletion requests. You can revisit your optional-cookie decision through the Cookie settings control shown at the lower right in consent regions.