Cookies are small text files stored on your device (computer, phone, tablet) when you visit a website. In addition to cookies, websites also use local storage (localStorage) and session storage (sessionStorage) — browser mechanisms for temporarily or persistently storing data on your device.
Cookies and similar technologies cannot identify you personally on their own, unless you voluntarily provide personal data (e.g., during login).
The pigmalion.si website uses only strictly necessary cookies and browser storage for basic functionality: login cookies, local and session storage, a static-file cache (Cache Storage), and bot protection on the sign-in and order forms (Cloudflare Turnstile). We do not use analytical, marketing, or third-party tracking cookies (Google Analytics, Facebook Pixel, etc.).
| Name | Provider | Purpose | Duration | Type |
|---|---|---|---|---|
sb-[ref]-auth-token | Supabase (authentication provider) | Authenticated user session — stores encrypted authentication token | Session / until logout | First-party cookie (session) |
sb-[ref]-auth-token-code-verifier | Supabase (authentication provider) | PKCE security key during OTP login process | Session (temporary) | First-party cookie (session) |
[ref] is the Supabase project identifier. These cookies are first-party (set directly by pigmalion.si) and are not used for tracking; they are required to keep you logged in.
Legal basis: Article 225(3) of the Slovenian Electronic Communications Act (ZEKom-2) — exemption from consent for cookies that are strictly necessary for providing an information-society service explicitly requested by the user (login to a user account).
You cannot reject them, as they are required for basic authentication functionality.
| Key | Purpose | Duration | Category |
|---|---|---|---|
pigmalion_cart | Stores your shopping cart contents (products, quantities, gift box options) | 48 hours from when each item is added (automatic cleanup) | Strictly necessary |
pigmalion_voucher_code | Stores an entered voucher code for use during checkout | Until order submission or manual deletion | Strictly necessary |
pigmalion_cookie_consent | Stores your cookie consent decision (acceptance date) | Permanent (until manual deletion) | Strictly necessary |
Data in local storage does not leave your device and is not sent to our servers. Legal basis: Article 225(3) ZEKom-2 — strictly necessary technologies for providing a service explicitly requested by the user (shopping cart, voucher input, recording of the cookie-notice acknowledgement).
| Key | Purpose | Duration | Category |
|---|---|---|---|
pigmalion_checkout_session | Prevents duplicate order submission during checkout | Session (until tab is closed) | Strictly necessary |
pigmalion_order_[order-number] | Temporarily passes the details of the just-placed order to the order confirmation page | Session (until tab is closed) | Strictly necessary |
Data in session storage is automatically deleted when you close the browser tab. Legal basis: Article 225(3) ZEKom-2 — strictly necessary technologies for completing the checkout process explicitly requested by the user.
| Name | Purpose | Duration | Category |
|---|---|---|---|
pigmalion-static-v1 | Caches the site's static files (JavaScript, CSS, fonts) so pages open faster | Until you clear browsing data or the site updates | Strictly necessary |
The cache is managed by a service worker — a script belonging to this site that runs in your browser. It stores only the site's own static files, no personal data, and none of it leaves your device. Legal basis: Article 225(3) ZEKom-2 — strictly necessary technology for providing the service explicitly requested by the user.
On the sign-in, registration and order forms we verify that the request is not being sent by an automated program. The check is performed by Cloudflare Turnstile: a script is loaded from challenges.cloudflare.com and may temporarily store technical data in your browser in order to complete the check.
For this, Cloudflare processes the IP address, User-Agent header, the browser's TLS fingerprint, and the site key and domain. Cloudflare states that these signals cannot directly identify an individual and are not used for advertising or cross-site tracking. We do not use the pre-clearance feature, so Turnstile does not set a cf_clearance cookie on this site.
Legal basis: legitimate interest (Article 6(1)(f) GDPR) — protecting the forms against abuse, unsolicited email and automated ordering. Signing in and placing an order are not possible without this check.
The pigmalion.si website does not use third-party tracking or advertising cookies. We do not use:
Login cookies (sb-[ref]-auth-token) are first-party — they are set on the pigmalion.si domain by the website's own authentication library and are not third-party cookies. Supabase and Cloudflare act as our sub-processors in operating the site and may set strictly necessary infrastructure cookies:
All such cookies are essential to the safe operation of the website and cannot be rejected without breaking functionality.
On your first visit, a cookie notice is displayed where you can accept the use of strictly necessary cookies. Since we only use strictly necessary cookies, additional settings are not needed.
You can manage cookies directly in your browser:
You can delete cookies and local storage in your browser settings under "Clear browsing data".
Warning: Deleting cookies will cause you to be logged out of your account and empty your shopping cart.
Since we only use strictly necessary cookies, they cannot be rejected without affecting functionality:
The website will still be accessible for browsing products, but purchasing and login will not be possible.
| Service | Provider | Purpose | Location |
|---|---|---|---|
| Web application hosting | Cloudflare, Inc. | Serving the website | Cloudflare EU network (HQ USA, EU-US DPF) |
| Authentication and database | Supabase Inc. | User login, data storage | Frankfurt, Germany (EU) |
| Image storage (R2) | Cloudflare, Inc. | Product photos and uploaded logos | Cloudflare EU network (HQ USA, EU-US DPF) |
| Form bot protection (Turnstile) | Cloudflare, Inc. | Verifying that sign-ins and orders are not submitted by an automated program | Cloudflare EU network (HQ USA, EU-US DPF) |
| Email delivery | Sendinblue SAS (Brevo) | Login security codes and order emails | France (EU) |
Cloudflare may use its own infrastructure cookies for traffic routing and abuse protection (e.g., DDoS mitigation); these are likewise strictly necessary and do not contain personal data.
We reserve the right to update this cookie policy. Changes will be published on this page with a new effective date.
For questions regarding cookies, contact us:
LINK Ljubljana, d.o.o.
Dunajska cesta 21, 1000 Ljubljana, Slovenia
Email: info@pigmalion.si
Phone: +38631578393
Registration number: 5297214000
VAT ID: SI95763520
| Category | Used | Requires consent |
|---|---|---|
| Strictly necessary cookies (authentication) | Yes | No |
| Local storage (cart, voucher, consent) | Yes | No |
| Session storage (checkout process) | Yes | No |
| Static-file cache (Cache Storage) | Yes | No |
| Bot protection (Turnstile) | Yes | No (strictly necessary) |
| Analytical cookies | No | / |
| Marketing cookies | No | / |
| Third-party tracking cookies | No | / |
Our website uses a minimal amount of cookies and storage — only those strictly necessary for functionality. We do not track your behavior, display personalized ads, or share data with advertising platforms.
Useful links:
Effective date: July 31, 2026