Legal
Cookies and storage
Pavia sets no cookies. The storefront keeps your cart and a few other things in your own browser, and each one is listed here.
Last updated 7 September 2026
In short
Pavia sets no cookies. There is no advertising cookie, no analytics cookie, and no cookie of ours of any kind.
The storefront does keep things in your browser's own storage, because a cart that empties on every page is not a cart. Every item is listed below.
None of it is shared, sold, or sent anywhere. Clearing your browsing data clears all of it.
Why there is no consent banner
A banner is what a site needs when it stores something on your device for its own purposes, above all for advertising or for following you across other websites. Pavia does neither.
What is stored here is the cart, the wishlist, the recently viewed row, your own order history and the anonymous sign in that lets your browser place an order. Every one of them exists to do the thing you came here to do, and storage that is strictly necessary for a service you asked for does not need consent.
If that ever changes, a banner will appear before the thing it is asking about loads, and refusing will be one click and will work.
Everything kept in your browser
- Cart. What you added and in what size and quantity.
- Wishlist. Pieces you saved.
- Recently viewed. The last few pieces you opened.
- Your orders. A copy of the orders placed from this browser, so you can look one up without an account.
- Pending order. A short lived marker written while an order is being placed. It is what makes a retry after a dropped connection the same order rather than a second one.
- Catalogue cache. A copy of the products so a repeat visit paints immediately.
- Anonymous sign in. A Firebase identifier with no name or email attached, held so the same browser is not issued a new one on every visit.
- Preview unlock. A flag set when the launch password is entered, so the gate does not ask again.
The offline copy
Pavia is installable, which means a service worker keeps a copy of the pages, the stylesheet and the scripts so the shop opens without a connection.
That cache holds the site's own files, not your details. Uninstalling the app or clearing site data removes it.
What loads from somewhere else
Three, and each one can see your network address when it is fetched:
- Google Fonts for the two typefaces. No cookie is set.
- imgbb for the product photographs.
- Firebase for the catalogue, the anonymous sign in and the orders.
These are described in more detail on the privacy page. There is no advertising script, no Google Analytics and no social media widget anywhere on the site.
Measurement
Cloudflare's Web Analytics beacon is permitted by the site's content security policy. It is cookieless: it counts a page view and sets nothing on your device.
Clearing it
Your browser's Clear browsing data control removes everything above, and a private window keeps none of it between sessions. The only cost is an empty cart and a forgotten wishlist.
A content blocker that stops the site's scripts will stop the cart working too, because the cart is the script. The catalogue will still show.