Cookie and Storage Notice
Version 1.2 · In force from: 7 October 2026
ColourSense — https://colour-sense.com
In brief — the five things that matter most
- We use three cookies of our own in total. A third-party cookie is created on the
https://colour-sense.comdomain only with your consent (the advertising cookies of Meta and Google, section 4.1). Two of our three own cookies are created only when an administrator logs in: as a visitor, without consent, you will in practice receive at most one cookie, and that one contains nothing but a language code. - The most sensitive data is not held in a cookie. The order form stores your first name,
your e-mail address, all your questionnaire answers, your full billing address and
the facial photograph you upload in your browser's session storage (
sessionStorage). That is not a cookie, but the law applies to it as well — which is why Chapter 6 lists every item. These data disappear when you close the browser tab concerned, and this storage operation itself never sends them off your device. - We load advertising measurement code (the Meta pixel, the Google Ads tag) only with your consent — the consent bar shown at the foot of the page asks for it, and without consent the code is not even loaded (section 4.1, Chapter 8). There is no Google Analytics, no Tag Manager and no TikTok pixel. Audience measurement — where it is switched on — works without cookies.
- If you arrive by clicking an advertisement, we record the advertising click identifier
(
gclid,fbclid,msclkid,ttclid) in your browser's session storage, count it in our audience measurement, and also send it to our own server when the order is submitted — where it is written to the operational log next to your e-mail address (section 7.4). This is not storage strictly necessary for the provision of the service — the present arrangement needs to be regularised. - Card payment takes place on Stripe's own site. Stripe's cookies are created on the
checkout.stripe.comdomain, not on ours.
If the language versions of this notice differ from one another, the interpretation more favourable to you prevails.
1. What this notice covers and what it is based on
This notice describes what the https://colour-sense.com website places on your device (computer,
telephone, tablet) and what data stored there it accesses — irrespective of whether the
storage technique concerned technically qualifies as a "cookie".
Legal basis.
Section 155(4) of Act C of 2003 on Electronic Communications (the Hungarian Electronic Communications Act, the Eht.), which is the Hungarian transposition of Article 5(3) of Directive 2002/58/EC (the ePrivacy Directive). The Hungarian text provides, in a working translation:
"Data may be stored on, or access may be gained to data stored on, the electronic communications terminal equipment of a subscriber or user only with the consent of the user or subscriber concerned, given after clear and comprehensive information — extending also to the purpose of the data processing — has been provided to that person."
(This rendering is a working translation provided for information only; the authentic text is the Hungarian one.) The corresponding provision of Union law reads, in its official English version:
"Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information, in accordance with Directive 95/46/EC, inter alia, about the purposes of the processing. This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service."
— Article 5(3) of Directive 2002/58/EC, as amended by Directive 2009/136/EC
Article 6(1)(a) and Article 7 of Regulation (EU) 2016/679 (GDPR) (the conditions for valid consent) and Article 13 GDPR (information to be provided in advance), where the data stored is at the same time personal data.
Two things must be kept apart. Section 155(4) of the Eht. applies to the act of storage and of access itself — even where the information stored is not in itself personal data. Where the information stored is also personal data, the GDPR applies to its processing as well, and the Privacy Policy gives detailed information about that.
Related documents: Privacy Policy · Terms of Service · Legal Notice · Withdrawal Information Notice · Complaints Policy.
This notice is directly accessible from every page of the website, and may be read, printed and saved free of charge.
The language of this notice. This notice is available in Hungarian and in English. The website operates in more languages than that; if you use the site in a language in which this notice is not yet available, the language clause above — the interpretation more favourable to you prevails — applies nonetheless, and you may request information free of charge at support@colour-sense.com.
2. Definitions — what a cookie is and what web storage is
| Term | What it means |
|---|---|
| Cookie | A small data file which the website places in your browser and which the browser automatically sends back to the server with every further request. |
| Session cookie | A cookie with no expiry time; it is deleted when the browser is closed. |
| Persistent cookie | A cookie that survives until a stated expiry (for our own cookies, at most 7 days; for the advertising cookies under section 4.1, 3 months). |
| First-party cookie | A cookie set by the domain you are actually visiting. All the cookies in Chapter 3 are of this kind. |
| Third-party cookie | A cookie set on the site you are visiting by another domain — typically an advertising or measurement provider. With us, such a cookie is created only with your consent (section 4.1). |
sessionStorage (session storage) |
Storage built into the browser. The data lives only in the browser tab concerned and is deleted when that tab is closed. The browser does not send it to the server automatically. |
localStorage (local storage) |
The same, except that the data survives the closing of the tab and of the browser until it is deleted. It, too, is not transmitted automatically. |
| Terminal equipment | Your device (computer, telephone, tablet) — the concept used in Section 155(4) of the Eht. and in Article 5(3) of the ePrivacy Directive. |
Why does the difference matter? A cookie travels to the server with every request; the contents of
sessionStorage/localStoragedo so only if the code of the page expressly sends them. The law, however, applies to both, which is why this notice lists the entire contents of web storage in addition to the cookies.
3. The cookies we use — the complete list
The list is based on the source code of our own applications. We place no other cookie, and — apart from the advertising cookies under section 4.1, which are created only with your consent — we allow no other cookie to be placed on our domain.
| # | Name | Who sets it | Purpose | Category | Lifetime | Settings |
|---|---|---|---|---|---|---|
| 3.1 | NEXT_LOCALE |
ColourSense website (own, first-party) | Remembering the language of the display (the language detected from your browser settings or chosen by hand with the language switcher) | Necessary for operation / user preference | Session — no expiry time; deleted when the browser is closed | SameSite=Lax; no HttpOnly (the website's own script can also read it), no Secure |
| 3.2 | coloursense.sid |
ColourSense server (own, first-party) | The login session of the operator (administrator) interface | Strictly necessary for operation (authentication) | 7 days | HttpOnly, SameSite=Lax, Secure in production; the cookie contains an identifier only, the session data are held on the server |
| 3.3 | crm_admin |
Studio CRM — a separate back-office application of the Provider | Administrative login to the back-office system | Strictly necessary for operation (authentication) | 7 days | HttpOnly, SameSite=Lax, Path=/admin, and Secure depending on configuration |
What you should know about the table above:
- Cookies 3.2 and 3.3 are never created for a visitor to the website.
coloursense.sidcomes into existence only after a successful administrator login (the system creates no session for an anonymous visitor);crm_adminbelongs to a different application, which customers of the webshop do not use. We list them so that the list is complete. - Even
NEXT_LOCALEis not always created. The website writes it only where the language displayed differs from the one that would be expected on the basis of your browser settings or of an earlier choice. If you view the site in your browser's own language and do not switch language, you receive no cookie at all. - The content of
NEXT_LOCALEis a single language code (for examplehu,en,de). It is not a unique identifier, it contains no personal data, and it is not capable of recognising or tracking you. - There is no other cookie of our own — no separate anti-abuse (CSRF) cookie, no measurement cookie and no "consent reminder" cookie. An advertising cookie is created only with your consent (section 4.1).
Legal classification. Each of the cookies 3.1–3.3 is strictly necessary for the provision of the service you have expressly requested, or serves authentication, and we therefore do not ask for separate consent for them. The detailed reasoning is set out in Chapter 8.
4. Third-party cookies on our own domain: only with your consent
On the https://colour-sense.com domain a third party sets a cookie only with your prior, express
consent, and only for the purpose of advertising measurement (section 4.1). Without consent —
and until you have decided — no such cookie is created, and your browser sends no request to Meta
or to Google either. In every other respect the list is negative; this is supported by the
following findings, each verified against the source code:
| What many sites use | With us |
|---|---|
| Google Analytics, Google Tag Manager | none |
| Meta (Facebook) pixel | only with your consent — see section 4.1 |
Google Ads conversion tag (gtag.js) |
only with your consent — see section 4.1 |
| TikTok pixel, LinkedIn Insight, Microsoft/Bing UET, Pinterest, Snap | none |
| Hotjar, Microsoft Clarity, Smartlook and other session-recording/heat-map tools | none |
| Social media share buttons, embedded social content | none |
| Advertising retargeting | only with your consent, using the cookies in section 4.1 |
Embedded YouTube/Vimeo video, Google Maps, any other iframe on the public pages |
none |
| reCAPTCHA, hCaptcha, Cloudflare Turnstile | none |
| Run-time call to an external font service (Google Fonts) | none — the fonts are served from our own server, so your browser sends no request to Google for typefaces |
| Script loaded from an external CDN (unpkg, jsDelivr, cdnjs) | none |
| Service Worker, IndexedDB, Cache Storage | none |
| External consent management platform (CMP) | none — we use our own simple consent bar, see Chapter 8 |
| Tracking pixel or click tracking in our outgoing e-mails | none — our messages contain no embedded image and no redirect link, so opening a message sends no data to our server |
Without consent, the only external script loaded at run time is that of the audience measurement provider (Chapter 7), and it is cookieless. The advertising scripts under section 4.1 are loaded only after you have given your consent.
4.1 The advertising cookies — only after consent
To measure the effectiveness of our advertising we use cookies from Meta and Google. These are created only if you chose "Accept" on the consent bar. If you refuse, or until you have decided, the measurement code is not even loaded.
| # | Name | Set by | Purpose | Lifetime |
|---|---|---|---|---|
| 4.1.1 | _fbp |
Meta (Facebook) | Distinguishing the browser in advertising measurement and retargeting | 3 months |
| 4.1.2 | _fbc |
Meta | Retaining the advertising click identifier so that a purchase can be attributed to the advertisement. Created only if you arrived by clicking an advertisement | 3 months |
| 4.1.3 | _gcl_au |
Linking the advertising click and the conversion in Google Ads conversion measurement | 3 months | |
| 4.1.4 | _gcl_aw |
Retaining the identifier of a click on a Google advertisement so that a purchase can be attributed to the advertisement. Created only if you arrived by clicking a Google advertisement | 3 months |
Legal basis: consent under Article 6(1)(a) GDPR, in conjunction with Section 155(4) of the Eht. Consent is voluntary: refusing carries no disadvantage whatsoever — the site and the ordering process work exactly the same way.
How to withdraw: clicking Cookie settings in the footer clears your decision and the page reloads, so the advertising scripts stop immediately, and the bar reappears. Cookies already set belong to a third-party domain and cannot be deleted by us; Chapter 9 explains how to remove them. Withdrawal does not affect the lawfulness of processing carried out before it (Article 7(3) GDPR).
What these cookies do NOT contain: your name, e-mail address, billing address or the photograph you uploaded. Meta and Google receive the page view (with the address of the page visited), the start of payment and the fact of the purchase — with its amount, its currency and the identifier of the payment session, which filters out double counting — not content identifying you.
One reservation, for the sake of accuracy. The list above is based on the code of our own applications. If a content delivery network or a web application firewall (CDN/WAF) is ever placed in front of the website, it may set a cookie of its own (for example
__cf_bm) on our domain; in that event this chapter will have to be supplemented.
5. Stripe's cookies — on Stripe's own domain
Card payment does not take place on our site: when you press "Pay", your browser redirects you
to Stripe's own payment page (checkout.stripe.com).
It follows that:
- Our website loads no Stripe script, and Stripe sets no cookie on the
https://colour-sense.comdomain. - Stripe's cookies (typically
__stripe_mid,__stripe_sid— the precise list and the lifetimes are set out in Stripe's own notice) are created on thecheckout.stripe.comdomain, within Stripe's own processing, while you are there. - Those cookies are governed by Stripe's own cookie notice and privacy policy, not by this document. The contracting entity is: Stripe Payments Europe, Limited (Ireland).
- We never see and never store card data — neither in a cookie nor anywhere else.
6. Data stored on your terminal equipment that does not qualify as a cookie
This is the most important chapter of this notice. The items listed here are not cookies, but Section 155(4) of the Eht. applies to all data stored on your device. Among the items the ordering process stores are some that qualify as personal data — including your photograph.
6.1 Session storage (sessionStorage) — lives until you close the tab
| # | Key | What it stores | For how long | Why we store it |
|---|---|---|---|---|
| 6.1.1 | cs-premium-flow-v1 |
The entire state of the order form: the current step, your first name, your e-mail address, all your answers on skin, hair and eye colour, undertone, contrast, style and wardrobe preference, the package chosen, together with your full billing address (billing name, country, postcode, town, street, house number) and the name and size of the file uploaded | Until you close the browser tab; deleted immediately upon successful payment | So that an order you have begun survives a page refresh, the back button and an abandoned or cancelled payment, and you do not have to fill in 14 screens again |
| 6.1.2 | cs-premium-flow-photo-v1 |
The facial photograph you uploaded — scaled down in the browser to at most 1600 pixels, in JPEG format, encoded as text (base64 data URL) | Until you close the browser tab; deleted immediately upon successful payment and when you remove the image | The same as above: so that the uploaded image is not lost during the process |
| 6.1.3 | cs-attribution |
The advertising and campaign parameters present in the URL when you arrive: utm_source, utm_medium, utm_campaign, utm_content, utm_term, together with the advertising click identifiers — gclid (Google), fbclid (Meta), msclkid (Microsoft), ttclid (TikTok) — and the path of the landing page. Created only if at least one such parameter is present in the URL |
Until you close the browser tab | ⚠️ Measurement (attribution) purpose: so that it can be seen which campaign an order came from. This is not storage strictly necessary for the provision of the service — see section 6.4. ⚠️ Unlike the other items, this data does not stay on your device: when the order is submitted its contents are also sent to our own server, where they are written to the operational log — see section 7.4 |
| 6.1.4 | cs-purchase-<identifier> |
A single technical flag ("1") under a key formed from the Stripe payment identifier |
Until you close the browser tab | ⚠️ A technical guard so that the purchase event is not measured twice when the page is refreshed. As it serves audience measurement, it likewise belongs to storage for measurement purposes |
6.2 Local storage (localStorage) — survives the closing of the tab
| # | Key | What it stores | For how long | Why we store it |
|---|---|---|---|---|
| 6.2.1 | cs-quiz-result |
The result of the free colour test: the season type obtained and the time of completion | 48 hours, after which it deletes itself the next time the page is opened; it can be deleted immediately with the "take the test again" button | So that we can show you the test result you expressly requested when you come back, and so that you do not have to take the test again |
| 6.2.2 | cs-consent |
Your decision on advertising cookies (acceptance or refusal), the time of the decision and the version number of the question. It contains no data about you personally | Until you clear it, or until we extend the question with a new purpose — in which case the old decision lapses and we ask again | So that you do not have to decide on every page load, and so that your decision can be evidenced (Article 7(1) GDPR). This storage is strictly necessary for providing the service — without it the consent question would be unmanageable — and is therefore not itself subject to consent |
Your answers to the questions of the free test stay in your browser — the evaluation runs entirely in your browser, and we do not send the answers to our server. If you also ask for the result by e-mail, all we receive is your e-mail address, the season type obtained and the language; the Privacy Policy deals with that.
6.3 Why the storage under 6.1.1, 6.1.2 and 6.2.1 qualifies as "strictly necessary"
Article 5(3) of the ePrivacy Directive — and the practice of the authorities applying it — does not require consent where the storage is "strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service". In our view the three items above fall within that exception, for the following reasons:
- You initiated it. The data comes into existence only if you start the order wizard or take the free test. Neither arises from mere browsing.
- The data is yours, and it stays with you. The purpose of the storage is not for us to learn the data (we receive it in any event when the order is placed), but for your browser to remember it. The storage operation in itself sends nothing to our server, and still less to a third party.
- Without it the function would not work as intended. The ordering process runs to 14 screens and payment concludes on Stripe's external site. Without storage, after every page refresh, every use of the back button and every abandoned or failed payment you would have to start filling in the form from the beginning and upload your photograph again — which would make reasonable use of the service impossible.
- The data lives for the shortest possible time. The storage is tied to the browser tab: it ends when the tab is closed. The order data and the photograph are in addition destroyed at the moment of successful payment, by an express deletion instruction.
- It is not tracking. Data stored in this way is not capable of — and is not used for — recognising you across pages or visits, building a profile of you, or targeting advertising at you.
We say so nonetheless:
cs-premium-flow-v1andcs-premium-flow-photo-v1store personal data — a name, an e-mail address, a billing address — and a facial photograph on your device. That is precisely why we could not content ourselves with the customary sentence that "we use only strictly necessary cookies": the law requires information about the fact of storage, whatever the sensitivity of the data stored.
Keeping the two legal layers apart. What is said in this section answers the question whether consent is required for the act of storage (Section 155(4) of the Eht.). It is a separate question that you also give us the same data with your order: the legal basis for processing that data under the GDPR is performance of the contract (Article 6(1)(b) GDPR), and for the facial photograph your explicit consent (Article 6(1)(a) and Article 9(2)(a) GDPR). The details are set out in rows 1–5 of Chapter 3 and in Chapter 4 of the Privacy Policy.
6.4 What is not strictly necessary — and what must therefore be regularised
The storage under cs-attribution (6.1.3) and cs-purchase-<identifier> (6.1.4) serves a
measurement purpose, not the provision of the service: the order could be completed without
it. In our view the exception set out above therefore does not extend to these two items, and
the requirement of prior consent under Section 155(4) of the Eht. arises for them.
An aggravating circumstance which we do not conceal: the contents of cs-attribution —
contrary to what point 2 of section 6.3 says of the other items — do not stay on your device.
When the order is submitted, your browser also sends the click identifiers to our own server,
where they are written to the operational log, next to your e-mail address (section 7.4).
That log is rotated by size today; it has no time-based retention rule.
We state this openly, and until it is resolved we undertake the following: we will either discontinue these two storage items or make them subject to prior, freely given and revocable consent — in the latter case by extending the consent bar (Chapter 8).
6.5 What we do not store in your browser's storage
- We store no login data or password in the browser's storage — there is no user account for making a purchase in the first place.
- We store no card data, neither in a cookie nor in web storage.
- We use no
IndexedDB, Service Worker or browser-side cache (Cache Storage) to store data. - We apply no device fingerprinting — neither browser-based, nor canvas-based, nor font-based.
7. Audience measurement — cookieless, but not invisible
7.1 What we use, and where matters stand today
To measure the audience of the website we use the service Plausible Analytics (Plausible Insights OÜ (Estonia)), which according to the provider's documentation operates without cookies: it sets no cookie and creates no device identifier.
The measurement provider acts as a processor; the processing agreement required by Article 28
GDPR will be concluded with it before measurement is switched on. The legal basis for the measurement processing is
legitimate interest under Article 6(1)(f) GDPR — understanding and improving the use of the
website — to which you may object under Article 21 GDPR (section 9.4). If the provider's seat or
the place of processing were outside the European Economic Area, the safeguards for the transfer
are set out in Chapter 8 of the Privacy Policy; the provider's exact legal entity and
registered seat become public once Plausible Insights OÜ (Estonia) is completed.
Audience measurement is switched on. The measurement code is loaded into the website as served, so the transfers described in sections 7.2–7.4 do take place. The measurement works without cookies, and the description below sets out exactly what reaches the measurement provider.
What we can prove about our own code: we write no cookie at all for analytics purposes and — apart from the two items named in sections 6.1.3–6.1.4 — we create no storage key for them either. How the provider's script itself behaves is evidenced by the provider's documentation and by the processing agreement to be concluded with it.
7.2 What reaches the provider — even without cookies
The measurement script is loaded from the provider's server, so your browser makes contact with the provider. In the course of that — even without cookies — the following reach the provider:
- your IP address (as a technical incident of the connection),
- your browser identifier (User-Agent: browser, operating system, device type),
- the referring page (where you came from), the address of the page opened and its language.
These — the IP address in particular — may qualify as personal data, and we therefore do not claim that the measurement is "entirely anonymous". What we do claim is that it is cookieless, and that we ourselves see nothing but aggregated statistics derived from the data. How long the provider retains those data is determined by the provider's own data processing policy.
7.3 The events measured — the complete list
| # | Event | When it arises | What parameters it sends |
|---|---|---|---|
| 1 | quiz_start |
on starting the free colour test | — |
| 2 | quiz_complete |
after the last question of the test | the season type obtained |
| 3 | quiz_lead |
if you also ask for the result by e-mail | the season type obtained |
| 4 | premium_cta_click |
on pressing a button leading to the paid analysis | season type, position of the button |
| 5 | season_details_click |
on opening the season details link | season type |
| 6 | checkout_step |
at every forward step of the order wizard | the name and ordinal number of the step |
| 7 | checkout_start |
on pressing "Pay", before the redirection to Stripe | ⚠️ the entire content of cs-attribution: the utm_* parameters, gclid, fbclid, msclkid, ttclid, landing page |
| 8 | purchase |
on confirmation of a successful payment | ⚠️ the entire content of cs-attribution (the same as above) |
No event sends a name, an e-mail address, a billing address, a photograph, a questionnaire answer or payment data — neither as a parameter nor concealed in the page title.
7.4 About the advertising click identifiers — separately, because they are not trivial
Events 7 and 8 also transmit an advertising click identifier to the measurement provider.
What is it? If you arrive by clicking an advertisement, the advertising system appends a unique
identifier to the end of the link (gclid — Google, fbclid — Meta, msclkid — Microsoft,
ttclid — TikTok). That identifier can be linked to your particular advertisement click and is
therefore — although it contains no name — to be regarded as a pseudonymous identifier, and it
cannot be dismissed as an insignificant technical detail.
What we do with it — both routes stated:
- To the measurement provider: we read it from the URL, keep it in your browser's session storage (6.1.3), and then send it to the measurement provider when the order is started and when payment succeeds, so that we can see which campaign brought a purchaser.
- 🔴 To our own server: when the order is submitted, your browser also sends the click identifiers to our server, together with the order data. There they are not written to the database; they are written to the operational log — in the present implementation within a single log entry together with your e-mail address. Our legal basis for that logging is legitimate interest under Article 6(1)(f) GDPR (being able to relate campaigns to orders; troubleshooting); in detail: row 10 of Chapter 3 of the Privacy Policy. That log is rotated by size today and has no time-based retention rule.
What we do not do with it:
- We do not ourselves send it back to Google, Meta, Microsoft or TikTok, and there is no server-side event forwarding (Conversions API). An advertising pixel and a conversion tag are loaded only with your consent (section 4.1); in that case the Meta and Google measurement code may itself record the advertisement click.
- We do not attach your name, your e-mail address, your billing address or your photograph to the events sent to the measurement provider (last paragraph of section 7.3). ⚠️ That statement concerns the data transmitted to the measurement provider; in our own log entry described in point 2 the identifier stands today next to the e-mail address — we have stated that expressly above, and we undertake to rework the logging (removing the e-mail address from the entry and introducing a time-based retention rule).
- We do not link it to your questionnaire answers, your facial photograph or your Report, and we build no advertising profile from it.
- We do not use it to build advertising audiences or for retargeting.
That said, this storage — as stated in section 6.4 — cannot be regarded as strictly necessary for the provision of the service, and it needs to be regularised.
8. The consent bar — for advertising cookies only
8.1 What the consent bar asks, and what it does not
The bar shown at the foot of the page asks a single question: do you allow advertising cookies (section 4.1). It asks nothing else, because nothing else requires consent:
- Our cookies are strictly necessary for operation (Chapter 3): one language preference and two authentication cookies belonging exclusively to operator login. For cookies of that kind, Article 5(3) of the ePrivacy Directive and the practice of the authorities applying it require no consent — they do require information, and this document provides it.
- Audience measurement is cookieless (Chapter 7) and rests on legitimate interest. The bar
does not ask about it, and the measurement continues to run after a refusal. (The
assessment of the
cs-attributionandcs-purchase-<identifier>storage that serves the measurement is different — see the exception at the end of this section.) - Advertising cookies, however, do require consent (section 4.1) — that is the sole subject of the bar.
- The storage used by the order form serves a function initiated by you (section 6.3).
One exception we do not conceal: the two measurement-purpose storage items referred to in section 6.4 cannot be brought within the reasoning above. Until that is resolved, this chapter does not assert that every element of the website's cookie and storage practice could be carried on without consent.
8.2 How the bar meets the requirements
An advertising pixel makes the processing subject to consent. The table below sets out, item by item, what the law requires and what implements it here:
| Requirement | Why | How it is met here |
|---|---|---|
| Obtaining consent in advance, before the pixel is loaded | Section 155(4) of the Eht.; Article 5(3) of the ePrivacy Directive — consent can only be prior | The pixel code is not loaded at all until consent is given; the gate sits in the loader component itself |
| A genuine choice: refusal must be as easily available as acceptance | Article 4(11) and Article 7 GDPR | Two buttons of equal weight, on one level, one click each; nothing is pre-ticked; refusal carries no disadvantage |
| Revocability of consent — as easily as it was given | Article 7(3) GDPR | The Cookie settings link is part of the footer on every page; one click clears the decision and stops the scripts |
| A record of the fact of consent (when, for what) | Article 7(1) GDPR — accountability | The cs-consent storage records the decision, its time and the version number of the question (6.2.2). For a new purpose the version is raised, the old decision lapses, and we ask again |
| Suspension of the pixel until consent is given, including the script not being loaded at all | The mere act of loading involves storage and a transfer of data | See the first row: the loading itself is what is conditioned on consent |
| Supplementing this notice and the Privacy Policy with the new recipient, the data concerned, the retention period and the safeguard for the transfer | Article 13 GDPR | Section 4.1 (cookies), Privacy Policy Chapter 7 (recipients) and Chapter 8 (third country) |
Should further advertising or profiling code be placed on the site in the future — a TikTok pixel, Google Analytics, Tag Manager or anything similar — that, alongside the requirements above, also entails raising the version of the consent question: an earlier acceptance does not extend to a new purpose.
9. How to delete or block the stored data
9.1 The quickest solution: close the tab
All the data referred to in section 6.1 — your first name, your e-mail address, your billing address, your questionnaire answers, the facial photograph you uploaded and the advertising click identifiers — is tied to the browser tab. If you close the tab (or the browser window) in which you opened the site, those data cease to exist on your own device — no separate step is required. The order data and the photograph are in addition deleted upon successful payment.
⚠️ One exception, for the sake of accuracy: if you have already submitted your order, a copy of the advertising click identifier remains in the operational log on our server, and closing the tab does not affect it (6.4, 7.4). Its retention and erasure are dealt with in row 10 of Chapter 3 and in Chapter 9 of the Privacy Policy.
If you are using a shared or public machine, we recommend closing the tab after ordering, or using a private / incognito window — in such a window the browser discards cookies and local storage alike when the window is closed.
9.2 Deleting the stored data, browser by browser
The menu items below reflect the current English-language interface of the most common browsers;
the exact wording may differ from version to version and between interface languages. In each of
them you will find the option to delete "cookies and site data", which also deletes the contents of
sessionStorage and localStorage.
| Browser | Path |
|---|---|
| Google Chrome | Settings → Privacy and security → Delete browsing data → Cookies and other site data |
| Mozilla Firefox | Settings → Privacy & Security → Cookies and Site Data → Clear Data |
| Safari (macOS) | Safari → Settings → Privacy → Manage Website Data → Remove |
| Safari (iOS/iPadOS) | Settings → Safari → Clear History and Website Data |
| Microsoft Edge | Settings → Cookies and site permissions → Manage and delete cookies and site data |
| Narrowed to a single site | Clicking the padlock (or "tune") icon in the address bar, most browsers offer to delete the cookies and data of the site concerned |
Using the developer tools (in most browsers the F12 key, then the "Application" / "Storage"
tab) you can also inspect and delete the Cookies, Session Storage and Local Storage entries
item by item.
9.3 Blocking cookies in advance
Cookies can also be restricted or blocked in advance in the privacy settings of your browser. What does that mean on our website?
| If you block | Consequence |
|---|---|
| Cookies | Your language choice will not be retained for the next page load; otherwise the website works and the order can be completed |
Writing to sessionStorage/localStorage (or blocking "all site data") |
⚠️ The order form cannot retain an order you have begun. After a page refresh, the back button or an abandoned payment you will have to start filling it in again, and upload your photograph again. The result of the free test will not be retained either |
The audience measurement tool (through a browser add-on, Do Not Track or a content blocker) |
The operation of the website is unaffected |
9.4 Withdrawing consent and the right to object
You may withdraw your consent to advertising cookies at any time, as easily as you gave it: through the Cookie settings link in the footer (section 4.1); withdrawal does not affect the lawfulness of processing carried out earlier.
You may object, under Article 21 GDPR, to processing based on legitimate interests carried out in the context of audience measurement and logging — the details and the contact points are set out in the Privacy Policy.
10. Contact and remedies
| Question | Contact |
|---|---|
| Questions about this notice, about cookies and about the data stored | support@colour-sense.com |
| Customer service, complaints | support@colour-sense.com |
| The full identification details of the Provider | Legal Notice |
| The legal bases of processing, retention periods, data subject rights, the supervisory authority (Hungarian National Authority for Data Protection and Freedom of Information — Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH) and judicial remedies | Privacy Policy |
The controller is: Ágnes Gróf, sole trader.
11. Changes to this notice
We will amend this notice if the cookie or storage practice of the website changes (for example if we introduce a new measurement tool or a CDN/WAF service), or if a change in the law or guidance from an authority so requires. We publish the text in force on the website, indicating the version number and the date of entry into force. We will bring a new storage item requiring consent into operation only by amending this notice beforehand and extending the consent question accordingly (section 8.2).
Version: 1.2 · Effective: 7 October 2026