Cookie Policy
Last updated: 23 August 2026
1. What cookies are
A cookie is a small text file stored on your device when you visit a website. Cookies let the site remember your preferences, keep you signed in, and measure page performance. This policy explains the cookies we use on bmdecor.es.
2. Legal basis
Under Article 22.2 of Law 34/2002 (LSSI-CE) and the GDPR, we may install essential cookies without consent; everything else requires your prior, informed, unambiguous consent. We obtain that consent via the cookie banner on your first visit and any time the consent record is cleared.
Our banner follows the AEPD's 2024 Cookie Guide: the “Reject all” and “Accept all” buttons are presented with equal visual prominence and each is a single click; a “Cookie settings” option lets you accept or reject the Analytics and Advertising categories independently; no box is pre-ticked; the choice is shown on arrival and stays until you answer it, so consent is never inferred from browsing, scrolling or closing a notice; access to the site is never conditional on accepting — rejecting leaves everything working exactly as before; and withdrawing consent is as easy as granting it, via the floating “Cookie preferences” control (bottom-left corner, available on every page) or the “Manage cookies” link in the footer.
3. Essential cookies
These cookies are strictly necessary for the site to work and are installed regardless of your consent choice.
- Session cookie — keeps you signed in once you authenticate. Issued by AWS Cognito. HTTP-only, Secure, SameSite=Lax. Expires with the browser session or on sign-out.
- Cart cookie —
bmdecor_cart_idremembers items added to the Bag between page loads. It is issued only when you first put something in the Bag — browsing the boutique installs no cart cookie at all. HTTP-only, Secure, SameSite=Lax. Expires after 30 days. - Consent record —
bmdecor_consentinlocalStoragestores which cookie categories you chose (Analytics, Advertising), and a companion first-party cookiebmdecor_consent_level(12 months) carries the same choice so our servers honour it on every request. Neither is a tracking cookie; they exist solely to remember and enforce your decision. PostHog keeps its own refusal record inlocalStorage(__ph_opt_in_out_…) for the same purpose: it is what stops analytics ever starting, and it is the only thing PostHog stores if you decline. They are replaced whenever you save a new choice via “Cookie preferences” (floating control) or “Manage cookies” (footer). - Pre-launch bypass cookie —
bm_prelaunch_bypass, installed only during the preview phase, lets invited testers skip the “coming soon” page. Removed at public launch. - Language cookie —
bmdecor_localeremembers the language you choose with the ES | EN switcher. Each page's language is determined by its own address (/en/…URLs serve the English version); this cookie keeps your preference for the customer area and for showing the Stripe payment page in your language. It is set only when you use the switcher. First-party, SameSite=Lax. Expires after 12 months.
4. Analytics cookies (optional)
If you accept Analytics cookies, we activate two analytics providers: PostHog (product analytics) and Google Analytics 4 (web analytics), to measure how visitors move through the boutique. PostHog installs a unique-identifier cookie and first-party session cookies to group events from the same browser; Google Analytics installs the first-party cookies _ga (13 months) and _gid (24 hours) to distinguish visitors, with IP anonymisation on. If you sign in or complete an order, we link this activity to your account identifier and email so we can measure the full shopping journey; the PostHog profile is deleted with your account under our erasure process. PostHog data is stored in the European Union (Frankfurt, Germany) under a GDPR-compliant data-processing agreement; Google Analytics is provided by Google under EU Standard Contractual Clauses (see our Privacy Policy).
PostHog covers the following on this site:
- Page views and navigation — which pages you visit and in what order, to understand the most relevant content and drop-off points.
- Autocapture of clicks and form submissions — aggregated interactions (clicks, form submits, rage-clicks) on generic UI elements.
- Heat maps — derived from the click data; shows where interaction concentrates.
- Session recording (sampled) — approximately 20% of consented sessions are recorded as video-style playback to debug UX issues. Text input values, passwords and payment fields are masked before leaving your browser — the recording shows that a field exists, never what you typed. Elements with class
ph-maskorph-no-captureare additionally blocked. - Feature flags — used to roll new features out gradually. In-product surveys are switched off and their code is not loaded, so no survey is ever shown to you.
- Search terms — the words typed into the shop's search, whether they matched anything, and which result was opened. Used to find the words customers use that our catalogue does not, so we can add them. The search term is recorded as a product signal; it is not kept as a per-person search history. With the same consent we also keep our own running count of each word and how often it found nothing — a total per word, never linked to you or to a session — for 90 days, and it is what tells our shop which words are missing.
If you accept only “Essential” cookies, both PostHog and Google Analytics are completely disabled and none of the above runs.
5. Advertising and other third-party cookies
If you accept Advertising cookies, we activate Google Ads to measure how our ads perform and to build remarketing audiences. Google Tag Manager orchestrates these tags and sets no cookies of its own; it loads on every page under Google Consent Mode v2 in its “Advanced” configuration. Before you consent, and if you decline, no advertising cookies or identifiers are stored: at most, the Google tags send anonymised, cookieless “pings” — with ad-click identifiers redacted — that Google uses only for aggregate, statistical conversion modelling. The advertising cookies below are set, and the tags run fully, only after you accept “Advertising”. The cookies and third-party services that may appear during your visit are:
- Google Ads —
_gcl_au(Conversion Linker, 90 days, first-party) plus Google advertising / DoubleClick cookies, used to attribute conversions and build remarketing audiences. Installed only after you accept “Advertising” cookies. We do not send Google any hashed customer identifiers (Enhanced Conversions are not used). - Google Tag Manager — our tag container, loaded on every page; GTM sets no cookies of its own. Before you accept “Advertising”, the Google tags it manages run only in Consent Mode v2's cookieless mode (anonymised pings, no cookies or identifiers, ad-click ids redacted); they set the cookies listed here and run fully only after you accept “Advertising”.
- Stripe —
__stripe_mid(1 year, fraud) and__stripe_sid(30 minutes, session). Installed only when you reach the checkout page; classified as essential to take payment. - PostHog — first-party
ph_*cookies and matchinglocalStorageentries for unique identifier and session attribution; installed only after accepting “Analytics” cookies. Nothing at all is stored before you answer the banner, and if you decline — or withdraw later — they are deleted, leaving only the refusal record described in section 3. - PostHog Error Tracking — error capture built into the same PostHog project; in our configuration it installs no additional cookies beyond those already described for analytics. Session recording is disabled.
6. Managing your consent
The cookie banner appears on your first visit and waits for your answer: there is no “close without choosing” option, because browsing on without answering would record no consent in any case — the optional categories simply stay off until you decide. “Reject all” is a single click and never limits your use of the site. You can change your mind at any time by clicking the floating “Cookie preferences” control (bottom-left corner) or “Manage cookies” in the footer: the banner reopens showing your current choice, which you can change or close again without altering; saving replaces the previous choice. Choosing “Reject all” after previously accepting switches analytics off immediately.
You can also block or delete cookies through your browser's privacy settings. Blocking essential cookies will prevent sign-in and cart persistence.
7. Changes to this policy
We may update this policy to reflect changes to the cookies we use. The “Last updated” date in the header reflects the latest change. Material changes are re-consented via the banner.
8. Contact and complaints
Enquiries: privacy@bmdecor.es. For the full data-protection framework see our Privacy Policy. Complaints may be filed with the Spanish Data Protection Agency (AEPD) at www.aepd.es.