Last updated: 28 August 2026. Version 2.3.

This cookie policy explains how Second Life Vault uses cookies and similar technologies on secondlifevault.co.uk, what each one does, how long it lasts, and how you can control them. It sits alongside my privacy policy, which explains more broadly what I do with personal data, and my terms and conditions.

1. Who is responsible for this site

Second Life Vault is the trading name of Stephanie Gola, a sole trader based in the United Kingdom. I am the data controller for personal data collected through this website.

  • Trading name: Second Life Vault
  • Trader: Stephanie Gola, sole trader
  • Address: 121 Waltersgreen Crescent, Golborne, WA3 3WA, United Kingdom
  • Email: legal@secondlifevault.co.uk

2. What cookies and similar technologies are

A cookie is a small text file that a website asks your browser to store on your device. When you return, your browser sends that file back, which is how a site can remember things such as what is in your basket or that you are signed in.

Several other technologies do a similar job, and where this policy says “cookies” it covers all of them:

  • Local storage and session storage. Larger stores of data held in your browser that are not sent back to the server automatically. This site uses local storage for two things: remembering your cookie choices, and holding your basket on the basket and checkout pages. Both are listed in the table in section 5. Nothing is written to local storage anywhere else on the site.
  • Pixels and tracking images. Tiny invisible images that record that a page or an email was opened. I do not use these.
  • Software development kits and scripts. Third party code embedded in a page that can set its own cookies. The only third party code on this site is described in section 6.

Cookies are also described as first party (set by secondlifevault.co.uk itself) or third party (set by another organisation whose code runs on the page). They are further described as session cookies, which are deleted when you close your browser, or persistent cookies, which survive until they expire or you delete them.

3. The law that applies

Two pieces of UK law govern this area. The Privacy and Electronic Communications Regulations 2003, usually shortened to PECR, govern the act of storing information on or reading information from your device. The UK General Data Protection Regulation and the Data Protection Act 2018 govern what happens to any personal data that results.

Under PECR I must obtain your consent before setting any cookie, with one narrow exception: cookies that are strictly necessary to provide a service you have expressly requested. A basket that remembers what you put in it is strictly necessary. An analytics cookie is not, however useful I might find it.

Where consent is required, it must be freely given, specific, informed and unambiguous, and it must be as easy to refuse as it is to accept. That is why the banner on this site offers Accept all and Reject all as equally prominent buttons, with no pre-ticked boxes, and why nothing beyond the strictly necessary cookies loads until you have made a choice.

4. The categories I use

Strictly necessary

These make the shop function. Without them the basket empties between pages, checkout cannot complete, and signing in does not persist. They do not require your consent and cannot be switched off through the banner, though you can still block them in your browser if you accept that the shop will stop working.

Functional and preference

These remember choices you have made so you are not asked again. On this site the only one is the record of your cookie choices itself, which is treated as strictly necessary because storing your refusal is the only way to honour it.

Analytics

These would tell me which pages are visited, how people arrive, and where they give up. I do not currently use any analytics cookies. The category appears in the banner so that the control already exists if I ever add one.

Marketing

These record how you found the site, so that when an order is placed I can tell which channel brought it in. I use one set of these, listed in the table below. They come with WooCommerce’s order attribution feature and note whether you arrived from a search engine, a link on another site, or by typing the address straight in.

Nothing here tracks you across other websites, builds an advertising profile about you, or is shared or sold to advertising networks. If you reject marketing cookies, or have simply not answered the banner yet, the script that would set them is not loaded onto the page at all.

5. Every cookie this site sets

The list below is complete as at the date at the top of this page. Not all of them are set on every visit. Several appear only once you add something to your basket, begin checkout, or sign in.

NameSet byPurposeExpires
woocommerce_cart_hashFirst partyRecords that your basket has changed so the page and the stored basket stay in step.When you close your browser
woocommerce_items_in_cartFirst partyTells the site whether your basket has anything in it, so the basket count in the header is correct.When you close your browser
wp_woocommerce_session_First partyA unique identifier that links your browser to your basket and order data held on the server. Without it the basket cannot follow you between pages.2 days
woocommerce_recently_viewedFirst partyRecords the products you have looked at, if a recently viewed list is shown.When you close your browser
wordpress_logged_in_First partyKeeps you signed in, if you have created an account. Only set after you log in.Session, or up to 14 days if you tick remember me
wordpress_sec_First partyAuthenticates you securely on encrypted pages once signed in.Session, or up to 14 days
wp-settings- and wp-settings-time-First partyRemembers display preferences for account holders.1 year
slv_consent_v1First partyRecords the cookie choices you made in the banner so you are not asked on every page. Held both as a cookie and in your browser local storage.6 months
sbjs_first, sbjs_current, sbjs_first_add, sbjs_current_add, sbjs_session, sbjs_udata, sbjs_migrationsFirst partyMarketing. Set only if you accept marketing cookies. Placed by Sourcebuster, the script behind WooCommerce’s order attribution feature. Between them they record how and when you first reached the site, how you reached it this time, and how many pages you have viewed, so that an order can be traced back to the channel it came from.6 months
storeApiCartData, storeApiCartHashFirst party, browser storageHold a copy of your basket and a checksum of it, so the basket page can show what is in it without asking the server again on every click. Written only once you open your basket.Until you clear your browser storage
storeApiNonceFirst party, browser storageA short-lived security token that proves a basket or checkout request genuinely came from you and not from another site acting in your name.Until you clear your browser storage
WOOCOMMERCE_CHECKOUT_IS_CUSTOMER_DATA_DIRTY, wc-blocks_dismissed_incompatible_extensions_noticesFirst party, browser storageHousekeeping flags belonging to the basket and checkout pages: whether your details have been edited since they were last saved, and which shop notices have been dismissed. Neither contains an identifier and neither records anything about you.Until you clear your browser storage
Payment provider cookiesThird partySet only at the point of payment, to process the transaction and to detect fraudulent card use. These are strictly necessary to take payment safely.Varies by provider, typically session to 1 year

Cookie names ending in an underscore are followed by a unique hash, which is why they are shown as a prefix.

Browsing this site sets nothing at all. On the homepage, the shop and every other page, no cookie and no browser storage entry is created unless and until you either accept cookies in the banner or put something in your basket. The basket entries above are written only when you open your basket, because they are what makes a basket possible.

6. Third parties whose code runs on this site

I keep third party code to the minimum needed to run a shop. The following are the only ones present.

  • My payment provider. Card details are entered into the provider’s own secure fields and are never seen or stored by me. The provider sets cookies necessary for processing the payment and for fraud prevention. This is a legal and contractual necessity, so it is treated as strictly necessary.
  • My web host. The server records standard log data such as IP address, browser type and the pages requested, for security, fraud prevention and keeping the site running. This is server logging rather than cookies, but it is disclosed here for completeness.
  • Fonts. The typefaces are served from this domain, not from Google’s font servers. Loading a page therefore sends no request to Google and discloses your IP address to nobody. This was previously not the case, and the change was made in August 2026.

There are no social media buttons, embedded videos, advertising tags, chat widgets or heat mapping tools on this site.

7. How consent works here, and how to change your mind

On your first visit a banner appears at the foot of the screen. Nothing outside the strictly necessary category loads until you choose. Accept all and Reject all sit side by side with equal weight, and Manage choices lets you switch analytics and marketing on or off individually. There are no pre-ticked boxes and refusing does not restrict your access to any part of the site.

Your choice is stored for six months, after which you will be asked again. You can change it at any time before then by selecting Cookie settings in the footer of any page, which reopens the banner with your current choices shown. Withdrawing consent is as easy as giving it, and takes effect immediately for anything set afterwards. Cookies already placed with your earlier consent can be cleared through your browser as described below.

Clearing your browser storage will also delete the record of your choice, so the banner will appear again on your next visit. That is expected behaviour rather than a fault.

Refusal here is enforced rather than merely promised. Until you agree to something, the site actively blocks any attempt to write a cookie or a browser storage entry that is not on the strictly necessary list, whatever it came from. If a future feature or plugin tried to set a tracker without being asked, it would be refused rather than quietly allowed through.

8. Controlling cookies in your browser

Every major browser lets you see the cookies stored, delete them individually or all at once, and block them in future. The setting is usually found under Settings, then Privacy and security.

  • Chrome: Settings, Privacy and security, Third-party cookies and Site settings.
  • Safari: Settings or Preferences, Privacy, Manage Website Data.
  • Firefox: Settings, Privacy and Security, Cookies and Site Data.
  • Edge: Settings, Cookies and site permissions.
  • Mobile: the same options appear in the browser app settings, or under the device settings for the default browser.

Most browsers also offer a private or incognito window, which discards all cookies when the window is closed. Please note that blocking the strictly necessary cookies listed in section 5 will stop the basket and checkout from working. That is a limitation of how shopping baskets function, not a restriction I have chosen to impose.

This site honours Global Privacy Control and Do Not Track. If your browser sends either signal, it is treated as a refusal of everything beyond the strictly necessary, recorded as your choice, and the banner does not interrupt you to ask a question your browser has already answered. You can still change it from Cookie settings in the footer if you want to. This is declared publicly, in the standard machine-readable form, at /.well-known/gpc.json.

The site also publishes its consent state in Google Consent Mode v2 format, which is the common language most privacy scanners and tag tools read. Every storage category is declared denied before anything runs, and updated only when you choose otherwise.

9. Cookies and your personal data

Some cookie identifiers count as personal data under the UK GDPR because they can single out a device. Where they do, my lawful basis is as follows: strictly necessary cookies are processed on the basis of my legitimate interests in operating a secure and functioning shop, and in the case of payment cookies for the performance of our contract; any analytics or marketing cookies would be processed on the basis of your consent, which you may withdraw at any time. Your wider rights over that data, including access and erasure, are set out in the privacy policy.

10. Changes to this policy

I will update this page whenever the cookies in use change. The version number and date at the top will tell you when it last happened. If a change means new non-essential cookies, I will ask for fresh consent through the banner before any of them are set, rather than relying on a consent you gave to something different.

11. Questions and complaints

Email me at legal@secondlifevault.co.uk and I will explain anything on this page in plain terms. I answer everything myself and aim to reply within a few days.

If you are not satisfied, you can complain to the Information Commissioner’s Office, the UK regulator for data protection and electronic marketing. You can reach them at ico.org.uk, on 0303 123 1113, or by writing to the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. I would appreciate the chance to put things right first, but you are entitled to go to them directly.