Skip to main content
Free 24-hour delivery over £75 · Same-day dispatch

Cookie policy.

Last updated: 6 August 2026

This policy explains how Kovalabs (operated by Floww Group Limited, the data controller) uses cookies and similar technologies such as browser local storage on this website. It sits alongside our Privacy Policy, which describes how we handle your personal data more broadly. We follow the UK Privacy and Electronic Communications Regulations (PECR) and the UK GDPR.

What cookies are

A cookie is a small text file a website stores on your device so it can recognise your browser. We also use related technologies, such as local storage, that work in a similar way. Throughout this policy we use the word “cookies” to cover both.

Cookies do a range of jobs: some are essential to make the site work (keeping your basket, keeping you signed in), while others are optional and help us understand how the site is used or support our marketing.

How we ask for your consent

When you first visit, we set only the strictly necessary cookies the site needs to function. Under PECR these do not require your consent, so they are always on. Separately, unless you object, our own server counts the document request under PECR's statistical-purposes exception so we can improve the shop. It maps the path to a fixed page type, reduces acquisition and referrer information to broad classes, and immediately adds one to a daily count. It does not receive a visitor or device identifier, a cookie value, an IP address, a user agent, a query value, or a key that can join the count to another system. The only thing derived from the browser's user agent is a yes/no note that the request came from an automated browser rather than a person, so automated traffic does not distort the counts; the user agent itself is never stored in or sent to the counter, and the note cannot identify you. A random retry key is deleted after 15 minutes.

Consent-based optional purposes stay off unless you choose Accept all or enable them under Customise. The controls group the optional purposes by capability. Analytics covers aggregate service analytics, and person-level analytics and replay. Advertising covers advertising storage, advertising measurement and advertising personalisation. Preferences covers functional preferences. Each group can be switched on or off as one, and every individual purpose stays separately controllable under the group's individual choices, so nothing is bundled beyond what each purpose describes. Essential (necessary and security) storage is always on. Selecting Deny all, or switching Analytics off (or just its Aggregate service analytics individual choice), is also a simple and free objection to our anonymous first-party statistics. Future page requests stop contributing while that choice remains off.

Each purpose describes a capability, not a particular tool. The specific providers and cookies serving a purpose can change over time; when they do, we update the tables below rather than asking you again, and the purpose you consented to stays the same. If we ever want to use your data for a genuinely new purpose, we will ask you first.

We remember your choice - whether you accept or refuse - for 365 days, so we do not ask again on every visit. Refusing is as easy as accepting, and you can change any purpose at any time using the Cookie settings link in the footer.

If you accepted analytics under our previous single-choice banner, that choice is kept exactly as you made it: analytics stays on and all advertising purposes stay off. We migrate that choice silently and do not regard it as permission for any new advertising purpose. You can choose those purposes yourself at any time using Cookie settings in the footer.

Your choice is set per device. The law treats cookie consent as specific to the device and browser you are using, so if you visit us on another device - for example you join our newsletter on your phone and later open an email on your laptop - you will be asked again on that device. A choice you make on one device does not carry over to another, and each device's choice is respected on that device.

We keep an immutable receipt for each purpose choice on our own servers. It records the device identifier, purpose, decision, time, policy version, source, a shortened IP address and reduced browser description. It also records which consent screen was used, why any recheck was shown, the site origin and release, bounded screen and viewport dimensions, and whether each necessary consent storage key could be read, written and read back. It records outcomes only, never the values held in those storage keys. If you later give us your email, the receipt can be linked using a one-way hash rather than storing the email in the receipt. Withdrawal creates a new receipt linked to the earlier one; it never rewrites the history. You can ask for a copy or request erasure where the law permits using the contact details in our Privacy Policy.

Strictly necessary cookies

These are required for the site to work and cannot be switched off. They do not track you for advertising. All are set by Kovalabs (first-party).

NameProviderPurposeDuration
_medusa_cart_idKovalabsRemembers the items in your basket between pages and visits. If a referral partner's link carries an active discount, the basket may hold that linked promotion so the discount you requested can be applied. Using that promotion can credit a qualifying order to the partner, but no referral cookie, click time, visitor identifier or advertising destination is added for this purpose. Persistent partner-link attribution is separate and starts only when you allow advertising storage. The same basket mechanism holds a personal welcome promotion when you use the apply link in our welcome email. These details live on our server, not in the cookie.30 days
_medusa_cart_summaryKovalabsLets the basket count appear instantly when a page loads, before the full basket is fetched. Holds only an item count and total, never personal details.30 days
_medusa_jwtKovalabsKeeps you signed in to your account as you move between pages and between visits, so you do not have to sign in again each time. Refreshed while you are active.365 days
_medusa_cache_idKovalabsMakes sure cached pages show your own basket and account state rather than another visitor's.30 days
kova_analytics_consentKovalabsKeeps the person-level analytics and replay choice compatible with our analytics provider. The detailed purpose choices are stored in kova_consent_v2. Re-issued by our server alongside kova_consent_v2 so the choice survives browsers that delete script-written cookies early.365 days, refreshed while you visit
kova_consent_v2KovalabsRecords each optional purpose choice on this device so we can apply it independently and avoid showing the banner on every visit. It also carries the random decision-batch and device identifiers needed to match a permitted server-side landing record to the exact consent receipts that authorised it. Our server re-issues this cookie with the same value during your visits, because some browsers (in particular Safari) delete script-written cookies after about a week; without the re-issue you would be asked to choose again even though nothing changed.365 days, refreshed while you visit
kova_consent_reaskKovalabsA one-time marker used when our systems find that the cookie choice saved on this device has been superseded (for example, an email link updated your choice elsewhere). It records whether that one-off re-confirmation is still pending or has been completed, so you are asked at most once. Once completed, our server re-issues it so browsers that delete script-written cookies early cannot repeat a prompt you have already answered.365 days, refreshed while you visit
kova_device_idKovalabsA random identifier for this device. We use it to keep each device's cookie choices straight. If you allow person-level analytics, it is also sent to Kovalabs' own event ledger as the anonymous device identifier for permitted events, so those events can be connected on this device. We also use it on our own servers as part of the fraud and security records described in our privacy notice (the "Security and fraud prevention" section). In every case it stays first-party: it is never sent to advertising platforms. Stored until you clear your browser's local storage; permitted ledger records follow the retention periods described below, and the security records are kept for 90 days.Until you clear your browser storage
kova_pending_consent_receipt_v2:* (and legacy kova_pending_consent_receipts_v1)KovalabsTemporarily keeps each failed consent-receipt request under its own browser local-storage key so choices made in different tabs cannot overwrite one another and can be recorded after a connection error. Legacy queued receipts are migrated automatically. A receipt keeps the decision batch and device identifiers. If you ask us to associate the choice with an email you supplied, it can temporarily include that email. A governed landing address and permitted campaign parameters are included only when the purpose you allowed requires them. Sensitive path identifiers, personal data inside campaign values and unrelated query parameters are removed.Up to 24 hours, or until the receipt is recorded
kovalabs_age_gate_accepted_v1KovalabsRemembers that you confirmed you are 18 or over, so the age check is not shown on every visit. Stored in your browser's local storage.Until you clear your browser storage
kova_age_v1KovalabsThe cookie copy of the age confirmation above. Some browsers, in particular Safari, can delete browser storage written by page scripts after about a week or when the app is closed. Our server re-issues this cookie so your confirmation is not forgotten and the age check does not reappear on every visit. Holds only the value 1 and does no tracking.365 days, refreshed while you visit
kova_state_fortified_at_v1KovalabsRemembers when your saved choices (such as the age confirmation and cookie preferences) were last re-saved by our server, so that housekeeping runs at most about once a day. Stored in your browser's local storage. Holds only a timestamp and does no tracking.Until you clear your browser storage
_kovalabs_last_address_v1KovalabsRemembers the shipping address and email you used at your last checkout so your next checkout on this device can pre-fill the form. Stored in your browser's local storage. You can clear it any time from the address form at checkout.Up to 180 days, or until you clear it from the checkout form
kovalabs_email_popup_seen_v2KovalabsRemembers how many times you have declined the email signup offer and when, so it stays away for a quiet period after each decline (about a day after the first, longer after each further decline, and around 30 days once you have declined its final offer) instead of appearing on every visit. Stored in your browser's local storage. Holds only a count and a date, no personal details, and does no tracking.Quiet period as described after declining; until you clear your browser storage after subscribing
kova_popup_v2KovalabsThe cookie copy of the signup-offer record above. Some browsers, in particular Safari, can delete browser storage written by page scripts after about a week. Our server re-issues this cookie so your declines are not forgotten and the offer does not restart from the beginning on your next visit. Holds only a count and a date and does no tracking.365 days, refreshed while you visit
kova_newsletter_opted_in_v1KovalabsRemembers that this browser has already joined our mailing list (through the signup offer, the footer form, or the checkout tick box), so the signup offer and the checkout marketing tick box are not shown to you again. Stored in your browser's local storage. Holds only a yes marker, never your email address, and does no tracking.Until you clear your browser storage
kova_nl_optin_v1KovalabsThe cookie copy of the mailing-list marker above, re-issued by our server so browsers that delete script-written storage early do not show you the signup offer again after you have already joined. Holds only the value 1 and does no tracking.365 days, refreshed while you visit
kovalabs_email_popup_shown_sessionKovalabsRemembers that the email signup offer has already appeared in this browsing session, so it is shown at most once per session. Stored in your browser's session storage and cleared when you close the tab. Holds no personal details and does no tracking.Until you close the browser tab
kovalabs_session_pageviews_v1KovalabsCounts how many pages you have viewed in this browsing session, so the email signup offer is never shown on the first page you land on (a search-engine requirement for mobile). Stored in your browser's session storage and cleared when you close the tab. Holds only a number and does no tracking.Until you close the browser tab
kova_asKovalabsA functional cookie for signed-in accounts that keeps your session's settings applied as you move between pages. It holds only a short signed reference, no personal details, and cannot be read by page scripts. It is refreshed about every ten minutes while you browse.10 minutes, refreshed while you browse
kova_gxKovalabsA functional cookie that maintains your browsing session as you move between pages. It holds only a short signed reference, no personal details, and cannot be read by page scripts. It is refreshed about every ten minutes while you browse.10 minutes, refreshed while you browse
kova_svKovalabsA short, opaque marker your browser uses to cache pages correctly for your current session. It is not a login, holds no personal details, and does no tracking.10 minutes, refreshed while you browse
kova_gxaKovalabsRemembers your browsing session on this device so it continues smoothly when you return, even after a break. It holds only a short signed reference, no personal details, and cannot be read by page scripts.365 days, refreshed while you browse

Analytics cookies (optional)

These help us understand how visitors use the site so we can improve it. Aggregate measurement and person-level analytics remain separate individual choices within the Analytics group. Our analytics provider is PostHog, whose servers are hosted in the EU. See PostHog's own privacy notice for how they process data on our behalf.

Our first-party service-statistics count is different from PostHog, session replay and advertising measurement. It creates no visitor history, cannot follow a journey, is not shared with advertising platforms, and is never used to profile or decide anything about a person or group. We rely on the narrow PECR statistical-purposes exception for this count and on our legitimate interest in improving the service for any momentary processing to which UK GDPR applies. You can object by switching Analytics off (or just its Aggregate service analytics individual choice) under Cookie settings.

If you allow person-level analytics and replay, we measure how you interact with pages, such as where you click, how far you scroll, and which elements get the most attention (sometimes shown as a heatmap), so we can improve the layout. This interaction measurement runs only after you allow that purpose. Without it, no person-level analytics or replay is sent.

If you allow person-level analytics and replay, we may also record a replay of your visit: the pages you view, clicks, scrolling, and mouse movement. We use replays to find and fix problems with the site. Replays are only captured after you accept. Text you type into forms is masked before it leaves your browser, so passwords, addresses, and payment details are not visible in a replay.

NameProviderPurposeDuration
kova_ledger_sessionKovalabsA random short-lived session identifier used by our own event ledger to order permitted landing touches and connect the latest permitted touch to your basket. Set only when you allow person-level analytics, or when both advertising storage and advertising measurement are allowed.30 minutes after the latest eligible landing
kova_ledger_touchKovalabsCarries the random identifier of the latest permitted acquisition touch so the basket and any later order can retain that attribution without relying on a third-party analytics service. It follows the same purpose controls as kova_ledger_session.30 minutes after the latest eligible landing
kova_landing_stateKovalabsRecords whether our own event ledger accepted the current permitted landing. It lets the page retry an interrupted edge request without duplicating an accepted landing. The HttpOnly value contains an opaque landing checksum, status, timestamps, random event, touch and session identifiers, plus bounded copies of the permitted Meta and TikTok browser identifiers used in the original request so an exact retry cannot be changed by browser tags. It does not contain the page URL. It is set only after an eligible optional purpose has been allowed.30 minutes after the latest eligible landing
kova_occurrence_authorityKovalabsCarries opaque event identifiers for the current permitted page so queued analytics events keep the session and page context that applied when they happened, even if delivery is retried later. It contains no contact details or page URL.30 minutes after the latest eligible landing
kova_phPostHogRecognises your browser between visits so we can measure how the site is used over time and improve it. Also links session replays to your visit if you accept analytics cookies. Set only after you accept; before that, analytics run with no cookie at all. While your acceptance stands, our own server re-issues this cookie during your visits so browsers that delete script-written cookies early do not wrongly count you as a brand-new visitor.Up to 365 days, refreshed while you visit

We also use Vercel Web Analytics for aggregate page-performance measurement, such as load speed and Core Web Vitals. It sets no cookies, but its script runs only when you allow aggregate service analytics.

Marketing cookies (optional)

The Advertising group has three individual choices. Advertising storage supports campaign and partner attribution. The separate advertising measurement and personalisation choices control whether eligible conversion data or audience activity may be sent to advertising platforms. Our email marketing runs server-side and sets no advertising cookies in your browser.

Google, Meta and TikTok conversion delivery remains blocked unless the required advertising purposes are granted. Any browser cookies added by those platforms will be listed here before they are enabled.

When advertising measurement is allowed, your order and browsing activity on this site can be sent to those platforms so they can tell whether an advert led to a visit or a purchase. When advertising personalisation is allowed, that activity can also be used to reach people with advertising. Either way it is sent together with contact details you have given us, which we convert into a one-way hash before they leave us wherever the platform accepts one. A one-way hash cannot be turned back into the original value: the platform can only compare it with a hash of data it already holds. Some address details are shared with Google in plain form because Google accepts them only that way. No platform receives your street address or your payment details. What each platform can accept differs, so the exact fields vary between them and may change as their services change. This is set out in our Privacy Policy.

NameProviderPurposeDuration
_gcl_au, _gcl_awGoogle AdsStores eligible ad click and campaign information so Google can measure whether an ad visit leads to a purchase, and so we can show advertising to people who have visited this site.Up to 90 days
_fbp, _fbcMetaIdentifies an eligible browser and ad click so Meta can measure visits, basket activity and purchases and deduplicate browser and server purchase events.90 days
_ttp, ttcsid_*, ttclidTikTokIdentifies an eligible browser, session and ad click so TikTok can measure visits, basket activity and purchases, deduplicate browser and server purchase events, and so we can show advertising to people who have visited this site.13 months from last use
kova_attrKovalabsRemembers how you first arrived at the site, such as a search engine or campaign link, for advertising attribution. Set only when you allow advertising storage; otherwise the information is kept only for the current visit.365 days
affiliate_refKovalabsStores the referral code from a partner link so eligible orders can be credited to that partner. Orders qualify for partner commission only when placed within 90 days of the click. Set only when you allow advertising storage.365 days
affiliate_ref_atKovalabsRecords when the partner link was clicked, alongside affiliate_ref, so the 90-day commission window can be applied correctly. Set only when you allow advertising storage.365 days
affiliate_ref_srcKovalabsRecords the sub-source tag from a partner link, such as a social platform or post, so partner traffic can be measured by channel. Set only when you allow advertising storage.365 days

Changing or withdrawing your choice

You can review or change your choice at any time using the button below, or the Cookie settings link in the site footer. Withdrawing consent is as straightforward as giving it.

You can also block or delete cookies through your browser settings. Most browsers let you refuse or remove cookies, but if you block the strictly necessary ones, parts of the site (such as your basket and sign-in) may stop working.

Changes to this policy

We may update this policy as our site and the tools we use change. The “last updated” date at the top shows when it was last revised. Any new cookie categories will be reflected here and, where required, gated behind your consent.

Contact

Questions about cookies or your data? Email team@kovalabs.co.uk and we will respond within one calendar month.