Legal
Cookie Policy
§ 01
What cookies are
Cookies are small text files placed on your device when you visit a website. They allow the site to recognise your device, remember your preferences, keep you signed in, and (for some sites) track your activity across the web. This Cookie Policy explains exactly which cookies and similar technologies (local storage, session storage, fingerprinting) Women In Art uses, why we use them, and how you can control them. It supplements our Privacy Policy and forms part of our Terms of Service.
§ 02
Our cookie philosophy — strictly necessary by default
We run the leanest possible cookie footprint. We do NOT use Google Analytics, Meta Pixel, TikTok Pixel, LinkedIn Insight, advertising trackers, behavioural retargeting, fingerprinting libraries, or any cross-site profiling. We do not sell, rent or share device data with data brokers. We have no tracking pixels in our newsletter. The cookies we do set fall almost entirely into the "strictly-necessary" category under the UK PECR / EU ePrivacy Directive — meaning no consent is required for them, because the service would not function without them.
§ 03
Strictly-necessary cookies (always on)
wia_token — your signed JWT login session. Set on login, cleared on logout. HttpOnly equivalent: stored in localStorage so it survives tab close. Expires after 30 days of inactivity. wia_cookie_choice — records that you have seen and dismissed our cookie banner so we don't re-show it. Stores either "all" or "essential". Expires after 12 months. wia_lang — your preferred language (one of 37). Used by the i18n layer to render the site in your language. wia_currency — your preferred display currency (GBP, EUR, USD, etc.). wia_cart — the contents of your shopping cart while you browse. Stamped with the id of the user who built it (or `null` for a guest cart). On sign-out, the cart is hidden from the next visitor on the same browser; on sign-in, a guest cart is claimed by the user signing in. Cleared on checkout completion. wia_mvp_gate — confirms you accepted the pre-launch gate. Cleared at full public launch. stripe_mid / __stripe_sid — set by Stripe.com on our checkout page for fraud detection. We do not set these directly; they are set by Stripe Elements when payment forms are rendered. Required for PCI-compliant card processing under PSD2 SCA. See Stripe's cookie policy.
§ 04
Functional cookies (set only when you opt-in)
If we ever add functional cookies that are not strictly necessary (e.g. "remember my filter preferences across visits"), they will only be set after you click "Accept All" on the cookie banner. Clicking "Essential only" keeps the site fully usable without these. As of February 2026 we run no functional cookies — the banner choice is reserved for future use.
§ 05
Analytics, marketing and third-party cookies — none currently
We currently set zero analytics cookies, zero advertising cookies and zero social-embed cookies. If we ever add these in the future — for example, server-side analytics with anonymised IPs, or a Pinterest "Save this artwork" button — we will: (i) update this page with the precise list and purpose; (ii) require explicit opt-in via an updated cookie banner; (iii) not set any non-essential cookie before consent.
§ 06
Local and session storage
In addition to cookies, modern browsers offer localStorage and sessionStorage — similar key-value stores that don't transmit with every request. We use localStorage for the same strictly-necessary purposes as above (token, lang, currency, cart, cookie choice). We do not use sessionStorage for tracking.
§ 07
Third-party services that may set cookies on our pages
Stripe (stripe.com) — payment processing on /checkout and /account/subscription. Sets fraud-detection cookies (stripe_mid, __stripe_sid). Necessary for processing payments under PSD2 SCA. See https://stripe.com/cookie-settings. Cloudinary (res.cloudinary.com) — serves artwork images via its CDN. May set caching cookies on the image domain (not on womeninart.com). Didit (didit.me) — embedded in the artist identity verification flow. Sets a verification-session cookie during the live KYC check. Only runs after an artist clicks "Start verification". No other third party sets cookies on our domain.
§ 08
How to control cookies
You can clear and block cookies via your browser settings (Chrome, Safari, Firefox, Edge, Brave all support this). Blocking strictly-necessary cookies will break login, cart and checkout — the site will not function. You can also use the "Essential only" button on our cookie banner (footer of every page) to reject all non-essential cookies. To withdraw consent later, click the cookie banner trigger in the footer at any time.
§ 09
Do Not Track and Global Privacy Control
We honour the Global Privacy Control (GPC) signal. If your browser sends GPC, we treat that as a withdrawal of consent for any non-essential cookies — exactly as if you had clicked "Essential only" on the banner. We do not currently rely on the older Do Not Track header (which lacks an enforcement standard), but we respect its spirit by not running advertising trackers regardless.
§ 10
Changes to this policy
We will update this policy if our cookie footprint changes — for example, if we add a new sub-processor that sets cookies, or introduce opt-in analytics. Material changes will trigger a fresh cookie banner so you can re-consent. The "Last updated" date at the bottom of this page always reflects the current effective version.
§ 11
Contact
Questions or complaints: hello@womeninart.com (subject: COOKIES). You also have the right to complain to the UK Information Commissioner's Office at ico.org.uk.
Last updated: 21 February 2026.