Cookie Policy
Arose Arisen Last updated: [20/08/2026]
This policy explains what cookies arosearisen.com (the "Site") uses, why, how long they last, and how you can manage your preferences. It should be read alongside our Privacy Policy.
If you're in the EU or UK, you'll see a cookie banner when you first visit the Site, letting you accept or decline non-essential cookies before they're set.
1. Who we are
Arose Arisen is the data controller responsible for this Site. You can contact us at hello@arosearisen.com with any questions about this policy or your cookie preferences.
2. What are cookies?
Cookies are small text files that a website stores on your device when you visit it, so the site can remember information about your visit — for example, that you've added an item to your basket, or how you found the Site.
3. The cookies we use
We use Squarespace as our website host and online store platform, and the cookies below are set automatically by Squarespace as part of running the Site. We don't set any cookies of our own outside of what Squarespace's platform provides, and we don't currently use any advertising or social media marketing cookies (for example, from Meta or Google Ads) — if that changes, this policy will be updated first.
Necessary cookies
These are always active and can't be switched off, as the Site can't function properly without them. They don't require consent under UK/EU law because they're strictly necessary to provide the service you've requested (for example, running your basket).
CART / hasCart — Remembers items in your shopping basket. Duration: 2 weeks. Legal basis: strictly necessary.
CHECKOUT_WEBSITE — Identifies the correct site during checkout. Duration: session. Legal basis: strictly necessary.
Commerce-checkout-state — Stores your progress through checkout, including PayPal checkout. Duration: session. Legal basis: strictly necessary.
_ssid — Recognises your device for fraud prevention. Duration: 4 years. Legal basis: strictly necessary.
Crumb / siteUserCrumb — Security cookies that protect against cross-site request forgery attacks. Duration: session / 3 years. Legal basis: strictly necessary.
RecentRedirect — Prevents redirect loops if a page has been moved. Duration: 30 minutes. Legal basis: strictly necessary.
Locked — Maintains access if a page is password-protected. Duration: session. Legal basis: strictly necessary.
ss_performancecookiesAllowed / ss_marketingcookiesAllowed — Remembers your cookie consent choices. Duration: 30 days. Legal basis: strictly necessary.
Analytics and performance cookies
These help us understand how visitors use the Site so we can improve it. They're only set if you accept them via our cookie banner.
ss_cid — Identifies unique visitors and tracks sessions, for Squarespace Analytics. Duration: 2 years. Legal basis: consent.
ss_cpvisit — Identifies unique visitors and sessions. Duration: 2 years. Legal basis: consent.
ss_cvisit — Tracks an individual visit/session. Duration: 30 minutes. Legal basis: consent.
ss_cvr / ss_cvt — Tracks conversions (e.g. completed purchases) for site analytics. Duration: 2 years / 30 minutes. Legal basis: consent.
Note on this list: this reflects Squarespace's standard cookie set as documented by Squarespace at the time of writing. Squarespace can add, remove or rename cookies as its platform changes, so this table should be checked against Squarespace's own cookie documentation periodically and kept up to date, rather than treated as permanently accurate.
4. How to manage your cookie preferences
You can accept or decline non-essential (analytics and performance) cookies via the cookie banner shown when you first visit the Site. You can change your mind at any time by clearing your cookies in your browser settings and revisiting the Site, which will show the banner again, or by adjusting your browser's own cookie settings to block cookies from this Site going forward.
Necessary cookies can't be individually declined, as the Site relies on them to function (for example, to keep items in your basket).
5. Cross-border data transfers
Some of the companies whose cookies or embedded services we use are based outside the UK and European Economic Area (EEA), including in the United States (Squarespace, Stripe, Sift, Google, Adobe). Where personal information collected via cookies is transferred outside the UK/EEA, these providers are required to have appropriate safeguards in place, such as Standard Contractual Clauses or an equivalent legal mechanism, to protect your information to UK/EU standards. You can find more detail in each provider's own privacy policy, linked below.
6. Third parties who receive cookie data
Squarespace (hosting, checkout, and site analytics) — squarespace.com/privacy
Stripe (payment processing, via Squarespace Payments) — stripe.com/privacy
Sift (fraud monitoring, via Squarespace Payments) — sift.com/service-privacy
PayPal (if you choose to pay by PayPal) — paypal.com/uk/webapps/mpp/ua/privacy-full
Google (Google Places API for checkout address auto-complete, and Google Fonts) — policies.google.com/privacy
Adobe (Adobe Fonts) — adobe.com/privacy
7. Your rights
Under UK data protection law, you have the right to access, correct, or delete personal information we (or our providers) hold about you, to object to or restrict certain processing, to request your data in a portable format, and to withdraw consent at any time (for example, by declining analytics cookies). See our Privacy Policy for full detail, or contact us at hello@arosearisen.com. You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
8. Changes to this policy
We may update this policy from time to time, for example if Squarespace changes the cookies it sets, or if we add a new tool or service to the Site. The version in place at the time reflects our current practices.