Cookie Policy
Cookie Policy
Cookie and Similar Technologies Policy
Effective 21 August 2026 | Version 2026.08.21 | Consent version 2.0
This policy supplements the Privacy Policy. “Cookies” also covers localStorage, sessionStorage, IndexedDB, Cache Storage, pixels and similar identifiers. A request for an external asset does not necessarily create a cookie, but its provider receives the IP address, user-agent, time and asset URL; these requests are therefore disclosed too.
1. Core rule
Necessary technologies support the basket, security, sign-in, consent choice, reliable loading and functions expressly requested by the visitor. Optional technologies write no cookies and no other data to your device before the relevant consent. The Google tag script loads for every visitor, but it runs in the denied consent state: it stores no cookies, creates no advertising identifier and allows no personalisation. It sends Google only a cookieless signal containing the IP address, browser type, time and page address, on the basis of our legitimate interest in measuring the effectiveness of our own advertising. Once you grant consent the state changes and these technologies begin using cookies as described below. Refusing is as easy as accepting, and you can change your choice at any time through the Cookie settings link in the footer.
Rejecting is as easy as accepting. Purchasing works without optional categories. Consent can be changed at any time through Cookie settings in the footer. Withdrawal stops future optional processing and the site removes identifiers it can technically access. Data already sent to a provider is erased under that provider's retention period or a valid rights request.
2. Categories
Necessary, always active
- aftershock_cookie_consent, cookie_consent_status: preserve the exact choice, version and decision time for 12 months,
- Evolved sign-in, CSRF, trusted-device and security cookies: for the session or the displayed security choice; a 2FA trusted device is normally kept for 7 days,
- aftershock_influencer_user and influencer_profile in sessionStorage: partner-profile data only while the tab is open or until sign-out; the current release removes legacy localStorage copies,
- aftershock-cart, evolved_checkout_info, checkout_autosave and checkout_recovery_email: basket and checkout progress; autosave for no more than 24 hours and the remainder until completion, expiry or deletion,
- checkout_discount_code, referral_code and influencer_referral_code: apply a code entered by the customer or already verified by the server; merely opening a URL containing a referral parameter does not store it,
- pending_purchase, tracked_purchases and local legal-document version records: secure payment return, idempotency and evidence of a legally relevant choice,
- PWA Cache Storage, EvlovedOfflineData, chunk-reload and chunk-reload-once: application assets, user-requested offline data and recovery after an update,
- Cloudflare CDN and security layer: processes every request to evolved.sk and may set necessary cookies such as __cf_bm or cf_clearance when protecting against bots or attacks; it receives the IP address, HTTP headers, requested URL and security signals,
- Stripe.js: __stripe_mid, __stripe_sid and fraud-prevention storage, if created after payment checkout is opened; typically around 30 minutes to 12 months according to Stripe,
- Google Identity Services, including g_state, g_csrf_token or Google account cookies where used by the selected sign-in mode; only for user-requested sign-in or account linking,
- Packeta and Slovak Post checkout widgets: load pickup points and store the selected point only during delivery selection,
- jsDelivr Twemoji and fal.media editorial images: technical delivery without an Evolved account, order or customer identifier; the browser requests no-referrer, but the CDN necessarily receives the IP address, user-agent, time and asset URL.
Their legal basis is not cookie consent, but the requested service, contract performance, legal duties or proportionate security.
Preferences, optional
- preferred-language,
- userCountry, userCountryManual, userCountryTimestamp,
- animationSettings, floating_cart_collapsed,
- aftershock_search_history (up to 10 searches),
- aftershock-share-count, aftershock-link-history,
- session value evolved-strip-dismissed-sale-2607 and the local developer switch perfDebug.
These values remember a user-selected language, country, presentation and local convenience features. They remain until changed, preference consent is withdrawn or the browser deletes them.
Analytics, optional
- Google Analytics: _ga, ga*, _gid, _gat, approximately 1 minute to 24 months depending on the identifier,
- Microsoft Clarity: _clck, _clsk, CLID, ANONCHK, MR, MUID, SM, from a session to approximately 13 months depending on the identifier; Clarity retains playback for 30 days and click/heatmap data and labeled or favorited sessions for no more than 9 months,
- Evolved first-party traffic measurement runs for every visitor and needs no consent because it writes nothing to your device: the session identifier lives only in the memory of the open page and disappears when you close or reload it. On our own server we store, with each event, its name and type, the page visited with sensitive parts of the address removed, the time, that session identifier, the browser string (user-agent), the referring page, campaign parameters from the address and the IP address. If you are signed in, your account identifier is attached as well. The legal basis is our legitimate interest in understanding how our site is used. Legacy analytics_session_id is no longer created and consent cleanup removes it; non-identifying server operational metrics create neither a cookie nor a visitor session,
- Bugsnag error reporting runs for every visitor and needs no consent because it writes nothing to your device: automatic session tracking, the persistent anonymous ID and IP collection are all disabled in the client configuration. Filtered technical errors are held for the account's limited retention period. The legal basis is our legitimate interest in keeping the site working; you can object under Article 21 GDPR,
- module_load_diagnostics, diagnostic_data only after a critical loading failure.
They measure use, diagnose errors and support technical improvement. Clarity loads only after analytics consent. Bugsnag runs for every visitor on legitimate interest and writes nothing to your device. Google Analytics uses cookies only after analytics consent; before that it runs in the denied consent state.
Marketing, optional
- Google Ads: _gcl_au, _gcl_aw, _gcl_dc, generally up to 90 days,
- evolved_attribution only after marketing consent, for no more than 90 days; without marketing consent this key is never created and the parameters from an advertising link stay in browser memory for the visit only; legacy referral_session, referral_visitor, referral_tracking, referral_utm and influencer_click_counted_* are not created by the current release and marketing-consent cleanup removes them,
- aftershock-banner-variant, aftershock-banner-views and exitIntent_* for the variation, frequency and state of a displayed offer; from a session to 7 days or the offer's expiry,
- Heureka OCM: hg_ocm_id, for 30 days,
- Google Customer Reviews opt-in is disabled in the current release and its script is not loaded.
They attribute campaigns and measure advertising. Partner/referral tracking is disabled in the current release: a URL parameter creates neither an identifier nor a server-side profile, the server only deletes the legacy HttpOnly aftershock_ref cookie and never creates a new one. Re-enabling it requires separate server-verifiable consent evidence. Heureka “Verified by Customers” is separate from the OCM cookie: it uses no cookie and no browser identifier. For that programme we pass your email address and the identifiers of the products you ordered to Heureka Group a.s. only on the basis of a separate, unticked-by-default checkbox at checkout under Article 6(1)(a) GDPR. Marketing cookie consent is not a substitute for it, and without the checkout consent nothing is sent. If you arrive through our advertising, we store the click identifier and the campaign labels from the address (gclid, gbraid, wbraid, fbclid and the utm parameters) with your order. We process these parameters during your visit; without marketing consent nothing is stored on your device and they are lost when you close the tab. With marketing consent your browser keeps them for no more than 90 days in the evolved_attribution key. We do not use them for profiling or ad targeting. Where an order follows a click on our advertising, we send the click identifier, the order value, the currency, the purchase time and the order number from our server to Google as a conversion measurement in Google Ads; we send no name, address, email or basket contents. This exists so we can tell which orders came from advertising and evaluate it. The legal basis for processing them during your visit is our legitimate interest in measuring the effectiveness of our own advertising under Article 6(1)(f) GDPR, and for the 90 day storage in your browser it is your marketing consent.
3. Providers and transfers
Cloudflare, Stripe, Google Identity Services, Packeta, Slovak Post, jsDelivr and fal.media provide the necessary technical layer only within the service described above. Google, Microsoft Clarity and Heureka provide optional services. SmartBear/Bugsnag reports technical errors for every visitor on legitimate interest, writing nothing to the device. Fastmail is the server-side SMTP email processor and is not itself a browser-cookie technology.
Data may be transferred outside the EEA under an adequacy decision, the EU-US Data Privacy Framework or standard contractual clauses. The Privacy Policy and provider documentation explain recipients, data and legal bases in more detail.
4. Browser controls
The browser can also block or erase cookies. Blocking all storage may disrupt the basket, sign-in or security. Browser settings do not replace the choice available in our consent centre.
After withdrawal, we erase accessible optional cookies and storage, stop further optional requests and send available “denied” signals to Google and Clarity. A browser may not allow Evolved to erase a third-party cookie on a provider's domain directly; that cookie can be removed in browser or provider settings.
The controller is evolved s. r. o.; its contact details appear in the Privacy Policy. The current name-level technical register, purpose and lifetime are displayed directly in Cookie settings and take precedence over this general summary within the same consent version.