Art Persona · Cookie Policy · v1.0 · Effective 30 July 2026
| Field | Value |
| Operator | GromeFeet OÜ |
| Company number | 17348635 |
| Registered office | Pärnu mnt 12, Kesklinna linnaosa, 10148 Tallinn, Harju maakond |
| Trading name / brand | Art Persona |
| Website | https://art-persona.com |
| Contact email | info@art-persona.com |
| Support / complaints | info@art-persona.com (Monday-Friday, 09:00-17:00 Estonia time, excluding public holidays) |
| Governing law | Estonia, subject to mandatory consumer protections |
| Document version | v1.0 |
| Effective date | 30 July 2026 |
| Important: Strictly necessary technologies support security, checkout and consent records. Analytics, preference and marketing technologies are used only under the consent model required by applicable law, and users can change their choices at any time. |
1. Introduction and scope
This Cookie Policy applies to art-persona.com and related checkout or account pages controlled by GromeFeet OÜ. It should be read with the Privacy Policy. Technologies placed directly by a payment provider or other independent service may also be governed by that provider’s notice.
2. What cookies and similar technologies are
Cookies are small text records stored by a browser. Similar technologies include local storage, session storage, software development kit identifiers, tags and pixels. They can remember a session, secure a form, record consent, measure performance or associate a visit with an advertising campaign.
3. Why we use cookies
Art Persona uses technology to keep the website secure, preserve checkout state, remember language and consent choices, diagnose errors, understand aggregate use and evaluate marketing where permission has been given. Data is not used to create a biometric identity profile from avatar images.
4. Cookie categories
Technologies are grouped as strictly necessary, functional or preference, analytics or performance, and marketing. Classification follows the purpose actually served. A technology used for more than one purpose is treated according to the purpose requiring the highest level of user choice.
| Category | Purpose | Consent required | Effect if disabled |
| Strictly necessary | Security, session continuity, checkout, load balancing and consent storage | No, where strictly necessary | Login, upload, checkout or preference storage may fail |
| Functional / preferences | Remember language, interface and non-essential user choices | Yes, where required | Settings may reset and convenience features may be reduced |
| Analytics / performance | Measure aggregate traffic, errors and feature performance | Yes, where required | Core service remains available; improvement data is reduced |
| Marketing | Measure campaigns and limit or attribute promotional messages | Yes | No behavioural marketing technology is activated |
5. Lawful basis and consent
Strictly necessary technologies operate because they are required to provide a requested service or secure the website. Non-essential cookies rely on consent where European privacy rules require it. Consent is specific by category, recorded, and not bundled with acceptance of the Terms.
Non-essential technologies remain off until a valid choice is recorded where consent is required.
6. Cookie inventory and example technology
The inventory below identifies the main technologies used by the current service architecture. A payment provider may generate additional short-lived security identifiers during checkout. Their exact technical names can vary by provider, device and risk-control path, while the stated purpose and category remain controlling.
| Cookie / technology | Type | Purpose | Duration | Provider |
| ap_session | Strictly necessary | Maintains secure website and account session | Session | Art Persona |
| ap_csrf | Strictly necessary | Prevents unauthorised form and checkout requests | Session | Art Persona |
| ap_cookie_consent | Strictly necessary | Stores category choices and notice version | 12 months | Art Persona |
| ap_locale | Functional / preferences | Remembers language and regional display choice | 6 months | Art Persona |
| payment_session | Strictly necessary | Connects the checkout to authentication and transaction status | Session to 24 hours | Payment provider displayed at checkout |
| ap_analytics_id | Analytics / performance | Counts visits and measures aggregate feature use | 13 months | Art Persona analytics service |
| ap_campaign | Marketing | Attributes a consented campaign visit to an Order | 90 days | Art Persona marketing service |
7. Third-party cookies and embedded services
Third-party providers may set technology when their content or payment frame loads. Art Persona limits such integrations, contractually restricts processors where applicable and blocks non-essential tags before consent. Independent third parties can determine additional purposes and should provide their own notices.
8. Managing preferences
The cookie settings interface allows category choices to be changed at any time. Users may also block or delete cookies in browser settings. Blocking essential cookies can prevent login, secure upload, checkout, fraud checks or preservation of a partially completed order.
9. Retention and expiry
Session cookies expire when the browsing session ends or shortly afterwards. Persistent identifiers use the duration shown in the inventory and are refreshed only where justified. Consent records are retained long enough to demonstrate the choice and then renewed at reasonable intervals or after a material change.
10. Do-Not-Track and browser signals
Because browser Do-Not-Track signals are not implemented consistently, the Service does not rely on them as a universal consent mechanism. Where a legally recognised opt-out signal applies, GromeFeet OÜ will honour it for the relevant processing. The cookie settings interface remains the primary control for European users.
Withdrawal must be as accessible as the original consent choice.
11. Children and age
The Service is directed to adults. Art Persona does not knowingly use behavioural advertising cookies to profile children. An adult arranging an avatar involving a minor must control the session and ensure that no child independently submits information or changes consent preferences.
12. International data flows
Cookie and analytics providers may process identifiers outside the European Economic Area. Transfers are handled under the safeguards described in the Privacy Policy. Users may refuse non-essential categories to prevent the related technology from being activated where consent is the legal basis.
13. Changes to this policy
The inventory is updated when providers, durations, names or purposes materially change. A new non-essential purpose will not be treated as covered by an unrelated prior consent. The effective date shows the current version, and the settings interface may request renewed choice where appropriate.
14. Contact and complaints
Questions about cookies, consent records or providers may be sent to info@art-persona.com. A privacy complaint can also be made to the Estonian Data Protection Inspectorate or another competent supervisory authority. Technical problems with the settings interface should be reported with browser and device details but without unnecessary personal information.
Operational Maintenance Checklist
1. Inventory owners review active cookies, local storage and embedded tags at least quarterly and before each material release.
2. A new non-essential technology is blocked until its purpose, provider, retention, lawful basis and consent category are documented.
3. The production website is scanned after deployment to compare actual names and durations with the published inventory.
4. Consent logs are tested for category accuracy, withdrawal, expiry and version linkage.
5. Expired providers and unused tags are removed from code, consent configuration and this policy.
6. Material discrepancies are corrected promptly and renewed consent is requested where a new purpose is introduced.
15. Governing law and mandatory rights
This Cookie Policy is governed by Estonian law and applicable European privacy law. It does not limit a user’s right to withdraw consent, object to unlawful processing, complain to a competent supervisory authority or use any other mandatory remedy. Mandatory local rules apply where they provide stronger protection.
Deployment and consent controls
Before release, engineering maintains a tag register linking every cookie, local-storage key, pixel or embedded component to an owner, provider, trigger, purpose, category, retention period and consent state. The release is blocked when a non-essential tag can load before the relevant consent choice or when a necessary identifier is used for an unrelated purpose.
Quality assurance tests a first visit with no choice, rejection of all optional categories, selective category acceptance, withdrawal, expiry, refreshed consent after a material change and checkout through the payment-provider interface. Tests also confirm that rejection does not disable ordinary browsing or a requested purchase except where a strictly necessary security function cannot operate.
After deployment, the production website is scanned and compared with the published inventory. Unknown technologies are disabled or investigated, obsolete tags are removed from code and the consent platform, and provider documentation is checked for changed names or durations. A purpose change is not treated as a routine update: it requires a lawful-basis assessment and renewed consent where required.
Consent evidence records the policy version, categories presented, user action, timestamp and relevant technical context without creating an unnecessary behavioural profile. Access to these records is limited, retention is proportionate to demonstrating compliance, and a withdrawal takes effect for future non-essential processing without making the previous lawful use invalid.
• Ownership and approval: The named operational owner confirms that the customer-facing rule, production workflow and support script describe the same outcome before publication.
• Change control: A material product, provider or checkout change is assessed for legal impact and deployed only after the affected wording, controls and training have been updated.
• Customer evidence: Staff rely on the minimum relevant Order, communication, delivery and payment evidence and do not request unrelated identity, image or card information.
• Exception handling: An unusual case is escalated to a competent reviewer rather than resolved through an undocumented promise that conflicts with the published terms or mandatory law.
• Quality assurance: Sample cases are tested from customer request through final outcome, including the status visible to support and the records needed to explain the decision.
• Access control: Systems and provider dashboards use role-based access, strong authentication and prompt removal of credentials when responsibilities change.
• Customer communication: Notices state what happened, what the customer must do, the expected next step and the available escalation route without overstating technical or legal certainty.
• Provider alignment: The configuration and contractual scope of each processor or platform are checked against the functions attributed to it in this policy.
• Incident response: A security, delivery, payment or rights incident is contained, documented and routed to privacy, consumer, payment or legal response procedures as applicable.
• Training: Personnel who operate the relevant workflow receive concise instructions, prohibited practices and escalation examples before handling live Orders.
• Monitoring: Material failure patterns, complaints and reversals are reviewed for root cause and corrective action rather than treated only as isolated customer-service cases.
• Retention discipline: Operational evidence is retained for the applicable legal or dispute period and then deleted or anonymised when no continuing purpose justifies it.
• Version integrity: The effective version accepted or presented for an Order can be identified, while the website clearly presents the current version for future transactions.
• Remediation: A confirmed control gap is corrected promptly, affected processing or fulfilment is paused where necessary, and impacted customers receive the remedy required by law.
• Management review: Senior management periodically reviews whether the policy remains accurate for the live commercial model, risk appetite and acquiring arrangements.
• Auditability: A reviewer can reconstruct the material decision and execution status without relying on private memory, informal chat or inaccessible personal files.
• User journey review: The desktop and mobile journeys are checked from entry page through consent, checkout, fulfilment and post-purchase support for accuracy and accessibility.
• Data minimisation: Forms, logs and case templates collect only fields needed for the stated purpose and avoid free-text requests for sensitive information where structured evidence is sufficient.
• Supplier exit: Replacement or termination of a provider includes export or deletion of relevant records, revocation of access and removal of obsolete code, links and policy references.
• Complaint learning: Substantiated complaints are mapped to the control that failed, assigned a corrective-action owner and retested after remediation.
• Business continuity: Contingency steps preserve customer communications, secure evidence and lawful remedies when a critical provider or internal system is unavailable.
• Legal watch: Material changes in consumer, privacy, payment or digital-content requirements are assessed against the live policy and implementation without waiting for a complaint.
• Accessibility: Customer notices, controls and support routes remain understandable and operable across common devices and assistive technologies.
• Localisation: Translated or localised customer text is checked against the controlling English version so that material rights, deadlines and restrictions are not altered.
• Test environment hygiene: Test accounts and sample files are segregated from live Customer Materials and do not use real payment credentials or unnecessary personal data.
• Escalation timing: Urgent safety, fraud or security cases are prioritised immediately, while ordinary questions follow published response standards and are not left without ownership.
• Metrics integrity: Service metrics distinguish acknowledged, resolved, refunded, corrected and appealed cases so performance reporting does not conceal unresolved customer harm.
Art Persona · Cookie Policy · v1.0 · Effective 30 July 2026. Published on the website; subject to update; the current published version governs.

