OrderFlow
Back to website

Website docs

Store guides and reference pages

Practical guides for your WooCommerce and Allegro store.

Cookie and Tracking Notice

Last updated: 2026-09-14

This notice explains the cookies and similar technologies that may be used on the Lolisoft OrderFlow website.

Technologies that may be used

Depending on the page and flow, the website may use cookies, local storage, pixels, scripts, tags, and server-side identifiers.

First-party technology register

Identifier Owner Storage and purpose Duration
orderflow-consent Lolisoft Local storage recording the optional-cookie choice, notice version, and decision time Up to 180 days; renewed consent is requested sooner when the notice version changes
orderflow-landing-language Lolisoft Local storage remembering the selected website language Until removed in the browser
orderflow_session Lolisoft Strictly necessary, HTTP-only account/security session cookie Browser session
orderflow_remember Lolisoft Optional account cookie used only when Keep me signed in is selected 30 days or until sign-out
Google identifiers such as _ga, _gid, _gat, _gac, _gcl, __gads, and __gpi Google Optional analytics/advertising identifiers; only eligible marketing pages may allow them after opt-in Set by the active Google configuration and documented by Google; withdrawal attempts to remove every readable matching identifier

Stripe may set its own necessary anti-fraud and checkout technologies on Stripe-hosted pages. Their names and lifetimes are controlled by Stripe and described in Stripe's privacy and cookie information.

Why they may be used

These technologies may be used to:

  • keep the website and documentation pages functioning
  • support checkout continuity, payment return pages, and secure download recovery
  • remember selected preferences such as language or interface context
  • protect forms, downloads, and checkout against abuse, spam, or fraud
  • measure traffic, page performance, campaign effectiveness, and purchase attribution

Categories

Strictly necessary

Used for core functionality, security, navigation, payment return handling, secure download validation, and abuse prevention. Without these technologies, some parts of the website may not work.

Preferences

Used to remember choices such as language or other website display preferences.

Analytics and attribution

Used to understand website usage and campaign performance, including whether a purchase or a trial request followed an advertisement. Google tag (gtag.js) is requested only after the visitor explicitly accepts optional cookies. Once accepted, it runs on the marketing landing page, the documentation, the purchase-return page, and the account pages. On the purchase-return and account pages the address reported to Google has checkout session identifiers, download tokens, and email addresses removed from it first. Administrator, background worker, and API endpoints are never instrumented.

A purchase is reported only after the payment has been verified with Stripe, using the amount actually charged and the Stripe checkout session as its transaction identifier. A trial request is reported only when the form submission has been accepted. Where the website is configured to use enhanced conversions, the billing email address from the payment or the address entered in the trial form is supplied to Google tag, which hashes it in the browser before it leaves the device; this only happens after advertising consent has been granted.

Marketing-related tags

Depending on website configuration and the visitor's consent choice, measurement or advertising-related tags may be deployed through Google tag (gtag.js) or similar tooling.

Third-party tools

The website may rely on third-party technologies including:

  • Google tag (gtag.js) and any analytics or advertising tags configured through it, loaded only after opt-in
  • Stripe checkout and payment-related services
  • hosting, CDN, infrastructure, or security providers involved in page delivery

Those providers may read or set their own identifiers under their own policies.

Legal basis and consent context

Strictly necessary storage or access is used to provide the website and secure the purchase flow. Optional analytics or advertising technologies should be assessed under the consent and privacy rules that apply in the visitor's jurisdiction, including GDPR and ePrivacy-style rules where relevant.

How to manage cookies

Analytics and advertising technologies stay disabled until you accept them in the cookie banner. Administrator, background worker, and API endpoints are never instrumented, and no page ever reports a checkout session identifier, download token, or email address to Google as part of its address. Refusing optional cookies does not block access to the website or checkout, although strictly necessary technologies may still run. You can change or withdraw that choice at any time using the Cookie settings control — withdrawing consent clears readable Google identifiers and reloads the page without Google code.

The saved choice includes the current notice version and decision time. It expires after 180 days, and an updated notice version asks for a fresh choice earlier.

You can also manage cookies and similar technologies through your browser settings, privacy tools, or device controls. Blocking some technologies may affect checkout continuity, language preferences, security checks, or download recovery.

Microsoft Clarity

After you accept optional cookies, the marketing landing page loads Microsoft Clarity for heatmaps and session recordings to understand clicks, scrolling, and website usage. The trial form is explicitly masked. Clarity runs on the marketing landing page only: it does not load on the documentation, purchase-return, download, account, or token-bearing pages.

Clarity uses first-party _clck and _clsk identifiers and may use Microsoft third-party identifiers. Microsoft documents their purpose and current configuration in its cookie information and Privacy Statement. Withdrawing consent also sends a denial to Clarity, removes readable _clck and _clsk cookies, and reloads the page without Clarity. This notice update requires a fresh choice before analytics can load.

Contact

Questions about cookie or tracking use on the website can be sent to info@lolisoft.eu.