Cookie policy
Last updated 15/08/2026
Necessary — session, basket, consent record, CSRF (always on, no consent needed)
These make the site work. Without them you could not keep a basket or stay signed in, so they are set without asking — which is what the regulations allow for strictly necessary cookies.
- sw_glass_basket — remembers which basket is yours. 7 days. Not readable by scripts.
- sw_glass_customer_session and sw_glass_customer_sid — keep you signed in, and let a sign-out revoke that one device. 30 days. Not readable by scripts.
- sw_glass_csrf — a security token that stops another site submitting forms as you. Up to 12 hours.
- sw_glass_session — the staff sign-in for our own team. 12 hours. It is never set for customers.
- cc_cookie — the record of your cookie choices, including a random identifier for the choice itself. 182 days. Without it we would have to ask you on every page.
At checkout our payment provider sets its own cookies inside its secure card form. Those are strictly necessary too — you asked to pay, and they are part of taking the payment safely — so they are not gated behind consent.
Functional — remembers preferences such as VAT display
This category is for remembering how you like the site set up rather than measuring what you do.
To be straight with you: at the moment nothing is set only because you allowed this category. Your inc/ex VAT choice travels in the page address and with your account type, not in a cookie of its own.
Your browser does keep a few small entries on your own device to make the site less annoying — recently viewed products, your recent searches, and whether you dismissed the prompt to install the app. These stay on your device, are not sent to us, and are not used to build a profile. You can remove them by clearing site data in your browser.
If we later add a preference that genuinely needs storing, it will go in this category and it will wait for your consent.
Analytics — helps us understand how the site is used
Analytics tells us which pages people struggle with. It is off until you allow it.
If you allow it, we load Google Tag Manager, which brings in Google Analytics, and a Microsoft session-insight tool. Nothing from either of them is requested by your browser before you choose — we test that automatically on every build, by loading the site and asserting that zero requests go to any analytics host pre-consent. We also send Google's consent signals set to denied by default, and only update them to granted once you have said yes.
Separately, we count a handful of first-party events on our own servers — that a configurator session was started, that a price was produced, that something was added to a basket. These carry no name, no account and no visitor identifier: they are counts, not a profile, and they never leave our systems. We mention it because you should know it happens, not because it identifies you.
Marketing — used to show relevant ads
Marketing cookies let advertising platforms recognise that a visit came from one of our ads, and show our products to people who have looked at them. This is off until you allow it.
If you allow it, our tag container may load advertising tags for the platforms we advertise on — for example Google Ads, Meta, TikTok, Pinterest and LinkedIn — where those accounts are actually configured. If we are not running on a platform, its tag never loads.
We do not sell your personal data, and we do not pass your order details to advertising platforms as a mailing list.
Marketing emails and messages follow the same rule: sequences such as basket reminders and review invitations only go to people whose consent record allows it. Messages about an order you have actually placed are not marketing and are sent either way.
