Cookie Policy
Last updated:
This policy explains which cookies and local-storage (localStorage) mechanisms craftbox.ge uses, who sets these cookies, for what purpose, and what control you have over them. This document forms part of the Privacy Policy.
1. What are cookies?
A cookie is a small text file that a website places in your browser during a visit. It contains anonymous or pseudo-anonymous identifiers that help the site “remember” you or your settings.
craftbox.ge also uses localStorage — a browser storage mechanism that is part of HTML5. It is similar to a cookie but is not automatically sent to the server. The ePrivacy Directive (EU) also applies to this type of storage.
2. Cookies used on craftbox.ge
craftbox-consentNecessaryStores the cookie-consent decision ("accepted" or "declined"). Written to localStorage (for client-side scripts) and to an HTTP cookie (for server-side CAPI integration). Required for ePrivacy Directive compliance. Analytics scripts load only when the value is "accepted".
__Secure-next-auth.session-tokenNecessaryNextAuth.js session cookie. Stores the JWT that authenticates the user’s session on the server. In an HTTPS environment it is named __Secure-next-auth.session-token; in local development — next-auth.session-token. Used to protect the customer’s personal account (My Account). The Secure; HttpOnly; SameSite=Lax attributes are set.
__Secure-next-auth.callback-urlNecessaryStores the redirect URL used after OAuth sign-in completes. Part of the OAuth 2.0 flow (Google OAuth). Secure; HttpOnly; SameSite=Lax.
__Host-next-auth.csrf-tokenNecessaryCSRF-protection token for NextAuth.js. Prevents cross-site request forgery (CSRF) during session-management operations. HttpOnly; SameSite=Lax.
craftbox-cartFunctionalStores the shopping-cart contents across browser sessions. Without it the cart is cleared on page reload. Consent for this function is implied — it is directly related to the purchase process.
_gaAnalyticsThe main Google Analytics 4 cookie. Stores a randomly generated client ID to distinguish repeat visits. Does not store directly identifiable information. Data: statistics.
Third party: Google LLC — privacy policy
_ga_*AnalyticsA GA4 collection-specific cookie. Stores the session state for a specific GA4 Property ID. Works together with _ga for session analysis.
Third party: Google LLC — privacy policy
_fbpMarketingThe Facebook Pixel cookie. Tracks visits across Facebook’s family of platforms (including Instagram) to measure conversions and optimise advertising campaigns. Sent to Meta Platforms Ireland Ltd.
Third party: Meta Platforms Ireland Ltd. — privacy policy
3. Consent and Management
3.1 Cookie Banner
On your first visit to craftbox.ge a cookie banner appears at the bottom of the screen. The “Accept” button loads analytics (GA4) and marketing (Facebook Pixel) cookies. The “Decline” button prevents these scripts from loading. In both cases the decision is stored in the craftbox-consent localStorage key.
3.2 Withdrawing Consent
You can withdraw consent for analytics cookies at any time using the following methods:
Method 1 — Browser DevTools
Open DevTools (F12), go to “Application” → “Local Storage” → craftbox.ge. Delete the craftbox-consent key. When the page reloads the banner appears again.
Method 2 — Browser Settings
From your browser settings you can clear all cookies and localStorage for craftbox.ge. Chrome: Settings → Privacy and security → Cookies and other site data → See all site data.
Method 3 — Google Analytics Opt-Out
Additionally, you can use Google’s official opt-out add-on: tools.google.com/dlpage/gaoptout
Method 4 — Facebook Pixel Opt-Out
To turn off Facebook’s interest-based advertising: facebook.com/help/164968693837950
3.3 Disabling Cookies Entirely
You can disable cookies entirely in your browser, however this will impair the shopping-cart function (craftbox-cart) and the proper working of other sites.
4. Legal Basis
| Cookie | Category | Basis |
|---|---|---|
craftbox-consent | Necessary | Legitimate interest (GDPR Art. 6(1)(f)) — ePrivacy compliance |
__Secure-next-auth.session-token | Necessary | Contract (GDPR Art. 6(1)(b)) — session authentication |
__Secure-next-auth.callback-url | Necessary | Legitimate interest (GDPR Art. 6(1)(f)) — OAuth flow |
__Host-next-auth.csrf-token | Necessary | Legitimate interest (GDPR Art. 6(1)(f)) — CSRF protection |
craftbox-cart | Functional | Contract (GDPR Art. 6(1)(b)) — purchase process |
_ga, _ga_* | Analytics | Consent (GDPR Art. 6(1)(a)) — ePrivacy Directive Art. 5(3) |
_fbp | Marketing | Consent (GDPR Art. 6(1)(a)) — ePrivacy Directive Art. 5(3) |
5. Changes to this Policy
When new cookies are added or a category changes, we will update this page and change the “last updated” date. When analytics or marketing cookies that require consent are added, the cookie banner will appear again (reset consent).
6. Contact
For questions about cookies or privacy, please contact us:
Email: info@craftbox.ge
Address: დავით ყიფიანის 2#, Tbilisi 0154, Georgia
Response time: 30 calendar days (GDPR Art. 12)










