The Mining Shop UK Cookie Policy
What Are Cookies?
Cookies are small text files stored on your computer, phone or other device when you use a website. They can keep the shop secure, remember a basket or preference, distinguish visits and help measure whether our pages and campaigns are useful.
- First-party cookies are set from www.theminingshop.co.uk, even where a service provider helps us operate them.
- Third-party cookies are set or read by another provider, such as Google or Stripe, when its service is used.
- Session cookies normally expire when you close your browser.
- Persistent cookies remain until their stated expiry, you delete them, or they are replaced.
Similar technologies include pixels, web beacons, local storage, device identifiers and conversion tags. The same consent rules apply where these technologies store or access information on your device.
Under the UK Privacy and Electronic Communications Regulations (PECR), non-essential storage or access normally requires clear information and prior consent. Where a technology also processes personal data, the UK GDPR and Data Protection Act 2018 apply. Strictly necessary technologies do not require PECR consent, but we still explain them transparently in this policy.
Why We Use Cookies
- Strictly necessary cookies operate security, privacy choices, account sessions, the basket, checkout and payment fraud prevention. They are used because the service cannot be provided securely without them.
- Preference cookies remember choices that are not essential, such as optional display or service preferences.
- Statistics cookies measure visits, product views, searches, basket activity, checkout steps, purchases and technical performance so we can improve the customer experience. We use them only after consent.
- Marketing cookies measure advertising, attribute sales and, where enabled and consented to, support audience or personalised-advertising features. We use them only after consent.
Our current consent setup: optional Google Analytics and advertising tags are blocked until you make an affirmative choice. Stripe security and fraud-prevention technologies may operate when payment functionality is requested because they protect the checkout and payment process.
Services and Cookie Details
The table describes the principal services and cookie families used by the current website. Exact names can contain an account or container identifier. Providers may update their technology; we therefore review this table and our Complianz scan regularly.
| Service and examples | Purpose and category | Typical duration | Information and recipient |
|---|---|---|---|
WooCommerce and WordPresswoocommerce_cart_hash, woocommerce_items_in_cart, wp_woocommerce_session_*, login/security cookies | Basket, checkout, account and authenticated-session operation. Strictly necessary. | Session for basket indicators; normally up to 2 days for the WooCommerce customer session; login cookies last for the session or longer if “Remember me” is selected. | First-party information processed by The Mining Shop UK Limited and its contracted hosting/security providers. |
Complianzcmplz_*, including consented services, policy ID and category choices | Records and proves your privacy choices and keeps optional services in the selected state. Strictly necessary. | Normally 365 days, then consent may be requested again; a new request may also appear when services or purposes materially change. | Stored first party. Complianz processes configuration or scan information only where its optional Cookie Database or website-scan service is enabled. |
Google Analytics 4_ga, _ga_* | Measures visits, sessions, product interactions, checkout steps, purchases and site performance. Statistics; consent required. | Up to 2 years by default. A shorter period can result from browser controls, consent withdrawal or configuration changes. | Pseudonymous identifiers, event data, device/browser information, referrer and approximate location are sent to Google. We do not intentionally send payment-card details or free-text form contents. |
Google Ads and conversion measurement_gcl_au and Google advertising identifiers where available | Attributes advertising clicks and conversions, measures campaign effectiveness and supports advertising features where enabled. Marketing; consent required. | _gcl_au is normally up to 3 months. Other Google advertising identifiers follow Google’s published durations and user settings. | Conversion, campaign, device and consent information is shared with Google. For enhanced conversions, eligible first-party customer data may be normalised and hashed before transmission following a purchase; Google uses it under the connected Ads account settings. |
| Google for WooCommerce and Merchant Center | Synchronises product listings, availability and commerce configuration with Google; measures shopping performance through the connected Google tags. Server-side commerce service plus consent-controlled statistics/marketing measurement. | The product feed itself does not require a separate browser cookie. Where measurement applies, it uses the relevant Google Analytics or Ads durations above. Merchant records follow the connected Google account’s retention settings. | Product catalogue, price, availability, shipping/returns information and permitted conversion data are shared with Google Merchant Center and connected Google services. |
Stripe, Stripe Elements, Radar and Link where selected__stripe_mid, __stripe_sid, m, and Link/session identifiers | Secure payment entry, authentication, fraud and loss prevention, checkout continuity and optional Link functionality. Strictly necessary when card or supported Stripe payment functionality is requested. | Depending on the Stripe feature: session or short-lived identifiers, approximately 30 minutes for __stripe_sid, up to 1 year for __stripe_mid, and up to 2 years for some fraud-prevention identifiers. Stripe may revise these periods. | Stripe receives transaction, device, browser, IP-derived location and fraud-prevention signals. Full card details are entered into Stripe-controlled fields and are not stored by The Mining Shop. |
Cloudflare security technologies__cf_bm, cf_clearance where a security check is triggered | Bot management, abuse prevention, content delivery and proof that a security challenge was passed. Strictly necessary for security. | Often about 30 minutes for bot-management state; challenge clearance duration depends on the security configuration and may last longer. | Request, device, network and security-event information is processed by Cloudflare on our behalf. |
Data Sharing and International Processing
The Mining Shop UK Limited is the controller of personal data collected through www.theminingshop.co.uk, except where a named provider acts as an independent controller for its own purposes. We use service providers only for the purposes described above and under contractual, security and access controls appropriate to their role.
The principal recipients are Google for analytics, advertising and merchant services; Stripe for payment and fraud prevention; Complianz for consent management and any optional scan service; Cloudflare for security and delivery; and our WordPress, WooCommerce and hosting providers for operation of the shop. We do not sell personal data collected through cookies.
Google, Stripe, Cloudflare and some of their subprocessors may process information outside the United Kingdom. Where UK personal data is transferred internationally, we rely on an applicable adequacy regulation or approved contractual safeguards such as the UK International Data Transfer Agreement or UK Addendum, as appropriate. Further detail, including the lawful bases for processing and your UK data-protection rights, is provided in our Privacy Policy.
Managing Cookies and Your Preferences
You are in control of non-essential cookies and similar technologies:
- Consent banner: on your first visit you can accept analytics, continue with necessary cookies only, or choose individual categories. Optional categories are off until you make an affirmative choice.
- Change or withdraw consent: use the persistent Privacy settings control in the website footer. Withdrawing consent stops future optional storage and tag use; you can also delete cookies already stored through your browser.
- Browser settings: most browsers let you inspect, reject or delete cookies. Blocking strictly necessary cookies can stop login, basket, security or checkout features from working.
- Google controls: review Google My Ad Center (opens in a new tab) or install the Google Analytics opt-out browser add-on (opens in a new tab). These controls supplement rather than replace the choices on our site.
- Other advertising controls: you can also use Your Online Choices (opens in a new tab).
Refusing optional cookies does not prevent you from browsing or purchasing. Reports may contain aggregated or modelled information where a provider supports consent-aware measurement, but our current basic consent setup does not load Google measurement tags before consent.
Common Questions
How long do cookies remain on my device?
Session cookies normally expire when you close your browser. Persistent cookies remain until their stated expiry, you delete them, consent is withdrawn and the service removes them, or the provider replaces them. The service table gives the relevant typical periods.
Can I reject cookies?
Yes. Select necessary cookies only or customise the categories in the consent banner. Rejecting optional cookies is designed to be as easy as accepting them.
Will rejecting optional cookies affect checkout?
No. Optional analytics and marketing consent is not required to browse, add products to the basket or place an order. Strictly necessary security, session and payment technologies still operate where required to provide those functions.
Does Google receive my payment-card number?
No. Card details are entered into Stripe-controlled payment fields. Google receives consent-controlled measurement and conversion information, not full card numbers. Eligible enhanced-conversion fields may be normalised and hashed before transmission to Google Ads.
Does Google for WooCommerce set its own cookie?
The product-feed connection is primarily server to server. Browser measurement associated with shopping performance uses the Google Analytics and Google Ads technologies disclosed in the table.
Do you use cookies for personalised advertising?
Only where the relevant advertising feature is enabled and you have consented to the required marketing purposes. You may withdraw that consent at any time through Privacy settings.
How can I ask a privacy question?
Email [email protected]. Your data-protection rights and the route to the Information Commissioner’s Office are explained in our Privacy Policy.
Updates to This Policy
We review this Cookie Policy, the Complianz service inventory and the cookies observed on the website regularly, and whenever we add or materially change a provider. We may update the policy to reflect changes in our practices, technology, provider defaults or the law.
If a change introduces a new optional purpose or materially changes what you previously agreed to, we will request consent again where required. The review date at the top identifies this version.
Questions About This Policy?
The Mining Shop UK Limited · Company number 14666497 · VAT GB482035600
Registered office: Enterprise House, 202 to 206 Linthorpe Road, Middlesbrough, England, TS1 3QW
Shop and repair centre: 38 Church Street, Hartlepool, TS24 7DG, United Kingdom
Email: [email protected] · Admin: [email protected] · Phone: 01429 408034