Cookie Policy
Last updated: 10 August 2026
1. What this policy covers
This policy explains cookies and similar browser technologies used on studiomood.de, why they are used and how you control them. It supplements our Privacy Policy.
The website is operated by Studiomood Ltd, Tagm. Gonia Demetriou Pouliou & Kost. Pantelidi, Melna Court, 8011 Paphos, Cyprus, registration HE 495191; info@studiomood.de.
Server-to-server connectors in our private dashboard are not website cookies or browser technologies. Their existence alone does not load a website script, set a browser identifier or access a visitor's device; they are described separately in the Privacy Policy.
2. Cookies and similar technologies
A cookie is a small text file stored on a device. Browser local storage, session storage and IndexedDB can also store/read information. A script or beacon may process browser data without using any of those storage mechanisms. We therefore use “service” when a disclosure covers processing that is not literally a cookie.
A first-party technology is provided through studiomood.de; a third-party service connects to another provider. A session cookie is ordinarily removed when the browser session ends; a persistent item remains until it expires or is deleted.
3. Legal basis
Cyprus Section 99(5) of Law 112(I) of 2004 requires consent for storage of or access to information on a device unless it is solely for a communication transmission or strictly necessary to provide an information-society service explicitly requested by the user. Because this .de website and our products are directed to Germany, Studiomood applies the corresponding consent and strict-necessity requirements of Section 25 TDDDG as an additional operational standard for studiomood.de. We do not rely on a narrower territorial interpretation to start non-essential device storage or access without consent.
Where related processing concerns personal data, non-essential services rely on Article 6(1)(a) GDPR. Strictly necessary processing relies on the activity-specific Article 6(1)(b), (c) or (f) basis explained below and in the Privacy Policy. We do not use legitimate interests to bypass a required statistics or marketing consent.
Cloudflare Web Analytics is a special case: Cloudflare documents that its RUM beacon does not store or access browser storage. We nevertheless require express statistics consent because an external provider processes browser/performance data. This GDPR opt-in must not be misdescribed as a Cloudflare cookie.
4. Strictly necessary technologies
These technologies provide the consent controls you request and cannot be disabled through the banner.
| Name | Provider | Purpose | Period |
|---|---|---|---|
real_cookie_banner-* |
studiomood.de (first party) |
Remembers and applies the consent decision. | 365 days |
real_cookie_banner-test |
studiomood.de (first party) |
Tests whether the browser accepts cookies so consent management can operate. | Session; may be removed earlier |
real_cookie_banner-consent-queue |
studiomood.de local storage |
Temporarily queues a choice when immediate server recording fails. | Until sent, then removed |
WordPress can also set necessary authentication/administration cookies for users who log in to the private administration area. They are not set for ordinary public visitors.
5. Currently offered consent services
5.1 Google Analytics 4
Purpose: consent-based aggregate usage/content/design analysis. Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acting as processor for this activity.
Before statistics consent, no GA4 script or request is loaded. After consent GA4 processes pseudonymous pages/events, approximate location and browser/device/interaction data. Google states that collection-time IP addresses are used for routing and approximate location and discarded before logging. Google Signals is disabled.
| Name | Provider | Purpose | Period |
|---|---|---|---|
_ga |
studiomood.de |
Distinguishes browsers/visits with a random identifier. | 2 years |
_ga_G2X7RQVETH |
studiomood.de |
Holds session state for this GA4 property. | 2 years |
Category: statistics. Legal basis: Article 6(1)(a) GDPR and consent under the applicable device-access law described in section 3. The banner is configured to delete the listed first-party definitions after opt-out. Current GA account retention: two months for event data and 14 months for user data. Google Privacy Policy.
5.2 YouTube
Purpose: optional embedded video. Provider in the EEA/Switzerland: Google Ireland Limited; platform operator: Google LLC, USA.
Before marketing consent the iframe has no source, no YouTube/Google connection is made and a locally hosted placeholder appears. After consent youtube-nocookie.com loads. Source IP and connection data are sent to Google and Google may use cookies/comparable technologies for the player, measurement, recommendations, profiling or advertising. A signed-in Google account can add account cookies. Provider technologies vary by account, region and experiments; neither this table nor our banner is an infallible real-time scan.
Current configured definitions include:
| Name | Provider | Purpose | Period |
|---|---|---|---|
YSC |
.youtube.com |
Measures video views within a session. | Session |
VISITOR_INFO1_LIVE |
.youtube.com |
Bandwidth/recommendation functions. | 6 months according to Google documentation checked 1 August 2026 |
__Secure-YNID |
.youtube.com |
Preferences and service-problem handling. | 6 months |
__Secure-YENID |
.youtube.com |
Preferences and service-problem handling. | 13 months |
__Secure-ROLLOUT_TOKEN |
.youtube.com |
Feature rollout and impact measurement. | 6 months |
PREF |
.youtube.com |
Playback preferences such as autoplay/player size. | 8 months from last use |
Signed-in account cookies can include SID, APISID, SAPISID, SIDCC and __Secure-*APISID families, plus varying local-storage/IndexedDB entries. Category: marketing. Legal basis: Article 6(1)(a) GDPR and consent under section 3. Google Privacy Policy.
6. Additional statistics services
The following services are independently selectable in Real Cookie Banner. Each remains off unless you expressly select that service or accept the statistics group. Rejecting other services does not activate either one.
6.1 Studiomood Intelligence First-Party Analytics
Provider: Studiomood Ltd. Purpose: consent-based pseudonymous usage, funnel and performance analysis. Category: statistics.
After separate opt-in, a locally served script sends events first only to the same-origin endpoint /wp-json/studiomood-intelligence/v1/event. WordPress then uses an HMAC-signed server request to the Access-protected private collector. No collector secret or Access service-token value is published to the browser.
The local-storage key studiomood_si_analytics_session_v1 holds a random 128-bit pseudonymous session ID for no more than 180 days. It is not a cookie. Withdrawing consent deletes it and reloads the page.
Data is limited to path without query/fragment; time and random event ID; page language; coarse viewport/device/OS/browser families; referrer domain; UTM source/medium/campaign/content/term; TTFB/LCP/CLS/INP; and page view, ten-visible-second engagement, 25/50/75/90 percent scroll, trial click, checkout start, navigation clicks (internal destination path or external destination domain only), language change, video start, a developer-marked limited demo-interaction category and the bare fact that the website contact form reported successful delivery. Trial, checkout and video events also record the page area in which the click occurred, such as header, footer or a developer-defined section name. No form field, message or other form content is sent. The normal user-agent header is forwarded through the protected server path only to derive the coarse device/OS/browser families.
The service does not use fingerprinting or collect customer identity, name, email, order/payment data, form text or search content. The source IP reaches WordPress; it is HMAC-pseudonymised with a rotating five-minute bucket for rate limiting. Only a shortened transient key lasts at most ten minutes. Raw IP is not sent to or stored in SI.
Recipient infrastructure: ALL-INKL and Cloudflare, Inc. with its authorised group entities and subprocessors. A third-country connection is possible. Cloudflare's Self-Serve Subscription Agreement incorporates DPA version 6.4, which provides for the EU Standard Contractual Clauses where a transfer is restricted and records Cloudflare's EU–US Data Privacy Framework participation. Website events are kept for no more than 400 days. The recurring process removes session records whose first observation falls outside that window, removes events older than the cutoff, and then removes old session records that no longer have any event; ingestion fails closed when required retention cannot complete.
Legal basis: Article 6(1)(a) GDPR and consent under section 3. No profiling or advertising personalisation.
6.2 Cloudflare Web Analytics
Provider/recipient: Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA, with its authorised group entities and subprocessors. Purpose: consent-based real-user page/performance analysis. Category: statistics.
After its own opt-in, the browser loads https://static.cloudflareinsights.com/beacon.min.js. Because the snippet is installed manually (this site is not Cloudflare-proxied), Cloudflare documents that the beacon reports to https://cloudflareinsights.com/cdn-cgi/rum.
Cloudflare documents a page-load ID; referrer/landing-page information; time origin; memory where supported; navigation/resource/paint timing; FCP, LCP, CLS, TTFB and INP; and dimensions such as host/path, referrer host/path, country, browser, OS, device and navigation type. It currently states that query strings are not logged.
Cloudflare states that this RUM beacon does not set/read cookies and neither stores nor reads localStorage, sessionStorage or IndexedDB. We do not configure it for fingerprinting or advertising personalisation. Cloudflare states it does not track individuals across customers' Internet properties. Source IP is necessarily received during HTTP transmission; Cloudflare states it discards the IP at the nearest data centre and does not store it in core databases/logs.
Cloudflare currently states: unsampled data seven days; longer-term aggregation to about ten percent of original volume; previous six months accessible in Web Analytics. It says processing can occur in another country/region. We do not infer a hard aggregate-deletion date. Cloudflare's Self-Serve Subscription Agreement incorporates DPA version 6.4; its transfer provisions use the EU–US Data Privacy Framework or, for restricted transfers, the EU Standard Contractual Clauses.
This service uses no cookie/storage definition in Real Cookie Banner. Its disclosure instead identifies the external script and beacon request. Legal basis: Article 6(1)(a) GDPR. It remains opt-in despite the documented absence of browser storage.
7. Lemon Squeezy checkout and optional acceleration
Opening a product page loads no Lemon checkout script, iframe or checkout document unless you have consented to the optional Lemon Squeezy checkout acceleration Functional service. With that consent, we preload lemon.js and the product checkout in a hidden, non-interactive iframe before any purchase click so that a later Buy Now click can display the already-loaded checkout overlay. The preload establishes connections to assets.lemonsqueezy.com and studiomood.lemonsqueezy.com and may transmit your IP address, browser/device information, referring page and access time. Lemon's checkout may use the browser technologies required for its operation and can read an existing ls_aff_ref affiliate-attribution cookie; Studiomood does not create that cookie as part of the preload. The hidden checkout is not displayed or interactive before the click, Studiomood supplies no billing or payment details during the preload, and the preload does not make a purchase or payment. Its legal basis is your Functional consent under Article 6(1)(a) GDPR and the device-access rules described above.
If you do not consent to checkout acceleration, no Lemon script, iframe or checkout document is loaded in the background. These are loaded only after a genuine Buy Now click and Lemon Squeezy's embedded checkout opens as an overlay on the product page. That user-requested connection sends ordinary HTTP/browser metadata to Lemon Squeezy and is necessary to provide the pre-contract checkout step under Article 6(1)(b) GDPR. If the script or overlay cannot load, a direct hosted-checkout link is offered as a fallback. You can withdraw acceleration consent through the controls above; this prevents future background preloading but cannot undo a transmission already made.
8. What we do not use
We do not use advertising pixels, advertising networks or unblocked social plugins. We do not load Google Fonts, Adobe Fonts or MyFonts. We do not add a cookie-banner service merely because the private dashboard queries GA4, Search Console, Bing Webmaster, Lemon Squeezy, Google/Meta Ads or social APIs server-to-server.
Except for the explicitly described services, ordinary fonts, stylesheets, scripts and images are served locally. This qualification matters: GA4, YouTube and Cloudflare Web Analytics make the disclosed external connections after the relevant consent, while Lemon Squeezy is contacted either after optional Functional consent for checkout acceleration or when a user intentionally selects Buy Now.
App-store buttons are ordinary links with local images. Viewing a product page alone loads no Apple/Google store script or store cookie. The selected store controls technologies after a click.
9. Withdrawal and service deletion
Use the controls at the top of this page. Rejecting must remain as accessible as accepting, and withdrawal at least as easy as consent.
On withdrawal, Real Cookie Banner blocks future requests for the relevant service and reloads the page where configured. It deletes the configured first-party definitions where technically supported. For SI this includes removal of studiomood_si_analytics_session_v1; subsequent page views send no new SI request. For Cloudflare Web Analytics, subsequent page views load neither its external script nor its beacon unless consent is given again.
Withdrawal cannot undo data already transmitted lawfully. A separate GDPR erasure request can be sent to info@studiomood.de and will be assessed under the Privacy Policy.
10. Browser controls
You can also refuse or delete cookies in browser settings. Blocking all cookies can affect this and other websites. Deleting consent storage removes the remembered choice, so the banner will normally appear again.
11. Inventory limitations and changes
Third parties can add, rename or change technologies. Our tables and banner reflect the services and definitions we configure and test; they are not represented as complete or continuously updated scans of every provider/account technology.
We update this policy and the corresponding service record when a service, purpose, data field, recipient, transfer or period materially changes, and request renewed consent where required. The date of this version appears above; material prior versions are archived internally.