Cookie policy.
Every cookie this site sets, why it exists, and how long it lasts.
This is a working draft. The list below was compiled by walking a browser through this site on 6 August 2026 and recording every cookie it actually received — it is a measurement, not a template. It has not been reviewed by a lawyer, and it describes a shop that is not open yet, so some of it will change when payments go live.
The short version
This site sets six cookies, all of them first-party — set by us, readable only by us. Five are needed for the basket or for signing in; the sixth just remembers that you closed the notice bar. Nothing here tracks you. No advertising network, no social network and no analytics company sets a cookie on you here, and we do not set one either.
Open this site in a clean browser and count: until you add something to your basket, sign in, or press “Got it” on the notice bar, you are given no cookies at all.
Until recently that was not quite true, and we would rather say so than quietly tidy it away: the shop software also set a group of cookies recording how you found us, from your very first page view, before anyone asked you. Those have been switched off. They will only come back once there is a working way for you to say yes or no first.
Strictly necessary — the shop does not work without these
wp_woocommerce_session_…- Links your browser to your basket, which lives on our server. Set when you add your first item. Lasts 2 days, or 7 days once you are signed in.
woocommerce_items_in_cart- Tells the page your basket is not empty, so the header shows the right thing. Set at the same moment; gone when you close your browser.
woocommerce_cart_hash- A fingerprint of your basket’s contents, so the basket display refreshes when it changes. Gone when you close your browser.
wordpress_logged_in_…- Keeps you signed in as you move between pages. Gone when you close your browser — unless you tick “Remember me”, which extends it to 14 days.
wordpress_sec_…- The same check on the site’s secure areas. Same lifetime as above.
cookieconsent_status- Remembers that you dismissed the notice bar at the bottom of the page, so it does not reappear on every page you open. Its only value is the word “dismiss”. Set when you press “Got it” — never before — and lasts one year.
Blocking these will break the basket and sign-in. There is no way around that — they carry no information about you beyond “this browser, this basket, this account”.
Kept in your browser rather than in a cookie
These never travel to our server on their own. Your browser holds them so pages redraw instantly instead of asking us again.
storeApiCartData, storeApiCartHash- A local copy of your basket so the page renders without waiting for us.
storeApiNonce- A short-lived security token for basket updates.
wc-blocks_dismissed_incompatible_extensions_notices- Which shop notices you have dismissed.
gc_wishlist_u…- A local copy of your wishlist. The real one is on your account.
wpEmojiSettingsSupports- Whether your browser can draw emoji, so we do not load a fallback.
Clearing your browser storage removes these, and nothing is lost — your basket and wishlist live on our server.
Analytics and advertising — there are none
This category is empty, and we would rather say that than pad it out. There is no Google Analytics, no Tag Manager, no Meta or TikTok pixel, no advertising network, no affiliate tracker, no session recording, no heatmap tool and no A/B testing tool on this site. We looked for every one of them.
Third-party content — no cookies, but they do see you
Screenshots load straight from Steam’s image servers — cdn.akamai.steamstatic.com and shared.akamai.steamstatic.com. Your browser fetches those images itself, so those servers see your IP address, your browser, and which of our pages asked for the image.
Cover art used to work the same way, from static.kinguin.net. We are copying every cover onto our own server, and a cover that has been copied is served by us — Kinguin never learns you looked at it. That is a fallback rather than a clean break: a product whose cover has not been copied yet, or whose copy failed, still points at the original Kinguin URL, and for those images Kinguin’s server sees your IP address and browser exactly as before. The copying is a background job working through the catalog, so the number of products still loading from Kinguin goes down by itself — we would rather describe that than print a figure that is out of date by tomorrow.
We checked, and none of these servers sets a cookie on you.
Everything else the site loads — fonts, styles, scripts — is served from this domain. There is no font CDN, no script CDN, and no embedded video or social widget anywhere on the site.
Controlling cookies
Every browser lets you view, block and delete cookies and site storage, usually under Settings → Privacy. Blocking the strictly-necessary group above will stop the basket and sign-in from working.
The bar at the bottom of the page is a notice, not a consent request. It has one button, “Got it”, and no “reject” — not because the choice was taken away from you, but because there is nothing on this site to reject: every cookie listed above is needed for the basket, for signing in, or for remembering that you closed that bar. Pressing “Got it” grants no permission; it only stops the bar reappearing, and it is the one thing that sets cookieconsent_status. If we ever add something that genuinely needs your permission, the bar will have to start asking properly, and this page will be rewritten to match what is set at that moment.