Cookie Policy
Last updated: 2 October 2026
This policy explains how BDH Creative uses cookies and similar technologies on bdhcreative.com. BDH Creative is a brand of BDH Collective Inc. Please read it together with our Privacy Policy.
1. What are cookies and similar technologies?
Cookies are small text files stored on your device when you visit a website. They help the site work properly, remember your choices, and understand how the site is used.
This policy also covers similar tools that do not use a cookie: browser storage (localStorage and sessionStorage), tracking pixels inside pages and emails, and scripts that read details about your device.
2. Who is responsible
The company responsible for this site and for the cookies and similar tools it uses is:
- BDH Collective Inc.
- 200-4388 Rue Saint-Denis, Montréal, QC H2J 2L1, Canada
- Quebec enterprise number (NEQ): 1171250237
- Person in charge of personal information: Founder, [email protected]
3. Consent on this site today
Our consent tool is active on this site. On your first visit, a banner asks for your choice, with the buttons Reject all, Choose and Accept all. Nothing optional loads before you choose. It holds back Google Analytics until you allow Analytics, and WooCommerce order attribution until you allow Advertising and social media. The Privacy settings link at the bottom of every page opens a panel where you can change or withdraw your choice at any time, category by category. The Your Privacy Choices link opens the same panel at its US privacy choices. If your browser sends a Global Privacy Control signal, we treat it as a refusal of advertising and data sharing. We keep your choice in your browser for 6 months, in a cookie named bdhc_consent and a copy in your browser’s local storage, and ask again after that. It also sends your choice to this website so the website can set the same cookie. The website does not keep a copy of your choice. To limit abuse, it counts those requests for about an hour under a scrambled form of your IP address. We also keep a record of each choice on our consent server, consent.bcall.dev, as proof of what you chose and when; our Privacy Policy lists what a record contains and how long we keep it. If you allow these tools and later turn them off, they stop loading, but the _ga, _ga_* and sbjs_* cookies they already set can stay in your browser until they expire or you delete them. On a page with a form, turning a tool off takes full effect on the next page you open.
These load whatever you choose: PayPal’s payment buttons on product pages and on the cart and checkout pages, PayPal’s fraud-prevention script on product pages and on the checkout pages, and Stripe’s payment script and Sift’s fraud-check script on the cart and checkout pages. On our shop pages, if you click the grid view or list view button, a cookie may remember your choice. We turned off commenter pictures from Gravatar on 1 October 2026. The tags in our Google Tag Manager container, including Meta, LinkedIn, HubSpot, TikTok and Fraud Blocker, do not run, because our pages do not load that container.
You can write to [email protected] about any of these tools, or delete the cookies for this site in your browser, as section 7 explains.
4. The categories
We sort the tools on this site into seven categories. Two tools are not settled yet, as explained under Necessary. Below, we describe each category and say what actually runs on this site today.
Necessary
These make the site work. They keep your cart and your shopping session, keep our staff logged in, and help protect the site. On payment pages, Stripe may add cookies so your payment can go through. The site cannot work without them.
On this site: WooCommerce cart and session cookies, the WordPress login cookies used by our staff, the LiteSpeed page-cache cookie, Cloudflare’s security cookies, and the wishlist session cookie when you save a product. On the cart and checkout pages, the payment tools of WooPayments (Stripe and Sift) load, and the page scripts may keep a copy of your cart in your browser’s storage. Some pages may also keep small settings in your browser’s storage, as listed in section 5. PayPal’s payment buttons load on product pages and on the cart and checkout pages.
An exception not yet settled: PayPal’s fraud-prevention script (FraudNet) collects information about your device and browser. It loads on our product pages and on the checkout pages as soon as a page opens. That happens before you choose to pay and without asking for your agreement first. We have not yet decided whether it belongs in this category, so we do not describe it as strictly necessary. You can object to it by writing to [email protected]. Our site has no setting today that stops this script for one visitor, so writing to us does not stop it from loading on your next visit.
Also not settled yet: a WooPayments usage-tracking script loads on product pages and on the cart page. It is not needed for the site to work, so we do not describe it as strictly necessary. It sends nothing. Usage tracking is turned off in our store settings, and the script’s settings on our pages tell it not to send anything.
Security and fraud checks
Tools that check for fraud, such as fake clicks on our ads.
On this site: Fraud Blocker, from Fraud Blocker LLC in the United States (account DGc3ioJQKI-7RRyR1zdyq), is set up to spot fake clicks on our ads. It reads details about a device, such as the screen, the fonts, the graphics card and the time zone, and builds an ID from them. This is device fingerprinting, and it sets no cookie. Its tags sit in our Google Tag Manager container (GTM-MM4V9DR). Our pages do not load that container today, so Fraud Blocker does not run on this site.
Preferences
Tools that remember small things you choose, like a display setting.
On this site: the grid view and list view buttons on our shop and product category pages. Our theme (Kadence) may set the bdhcreative-com-shopLayout cookie to remember your choice for 30 days. It is first set only when you click one of these buttons. A later visit that applies your saved choice may renew it for another 30 days.
Our “Hello world!” blog post has a comment form, and our BoldPulse Sports Bra product page has a review form. Both have a box to save your name, email and website in this browser. If you tick it and send the form, WordPress may set comment_author* cookies with those details.
Analytics
Tools that count visits and show us which pages and products people look at.
On this site: Google Analytics 4 (measurement ID G-C0DQL3DDS2), run by Google LLC in the United States. The Site Kit plugin loads it once you allow Analytics in the banner or the Privacy settings panel (Google tag GT-5R89PZD), and it may set the cookies listed in section 5. The settings of that Google tag also have Google’s user-provided data collection turned on. So Google Analytics may pick up an email address, phone number or postal address that you type into a page, and send it to Google. Our Google Tag Manager container (GTM-MM4V9DR) also holds Google Analytics tags that would send events through our server-side container (GTM-TNVFBN8J). The server-side container runs on Google Cloud (App Engine). Our pages do not load the Google Tag Manager container today. Our Google Analytics property is linked to our Google Ads account, so analytics data such as purchases can also be used in Google Ads to measure our ads. Our Privacy Policy explains this link.
Advertising and social media
Tools that record where you came from and what you do here, so that we can show ads, count sales and judge our ad spending. Under some US state laws this counts as selling or sharing your information.
On this site:
- WooCommerce order attribution loads only after you allow Advertising and social media, and then may set seven
sbjs_*cookies that record where you arrived from. - Google can use our analytics data in Google Ads, through the link described under Analytics.
- Meta (Meta Platforms Inc., United States), LinkedIn (LinkedIn Corporation, United States) and HubSpot have tags in our Google Tag Manager container. Our pages do not load that container today, so these tags do not run on this site.
- TikTok: a TikTok pixel is set up in the same container, which our pages do not load today, so it does not run on this site either. TikTok would send data to China. We will not turn it on without updating this policy first. Our server-side container (
GTM-TNVFBN8J) can also hold a TikTok Events API tag. Our pages send nothing to it today.
Email tracking
Tools that record whether you open our emails and which links you click.
On this site: Emailit, for the emails we send you. Recording opens and clicks needs your consent. We do not ask for that consent today. Emailit may record opens and clicks in those emails. It sets nothing on this website.
Embedded content and chat
Video players, booking tools, galleries and chat that other companies run.
On this site: no video players, booking tools, galleries or chat from other companies run on this site today. We turned off commenter pictures from Gravatar on 1 October 2026.
5. Cookies and similar tools on this site
| Name | Provider | Category | What it does |
|---|---|---|---|
wp_woocommerce_session_*, woocommerce_items_in_cart, woocommerce_cart_hash | WooCommerce (this site) | Necessary | Keep your cart and your shopping session while you browse and check out. |
storeApiNonce, storeApiCartHash, storeApiCartData, WOOCOMMERCE_CHECKOUT_IS_CUSTOMER_DATA_DIRTY (browser storage, localStorage) | WooCommerce (this site) | Necessary | May be set by the cart and checkout page scripts. They keep the security token the cart uses and a copy of your cart. That copy can include the delivery and billing details you enter at checkout. They stay in your browser until its site data is cleared. |
WP_DATA_USER_0 (browser storage, localStorage) | WordPress (this site) | Necessary | May be set on the cart and checkout pages to keep settings used by the page scripts. It stays in your browser until its site data is cleared. |
wcpay_appearance_* (browser storage, localStorage) | WooCommerce, Automattic Inc., United States (WooPayments) | Necessary | May be set on the cart and checkout pages to remember how the payment form looks. It holds no information about you. |
wpEmojiSettingsSupports (browser storage, sessionStorage) | WordPress (this site) | Necessary | May be set on most pages. Remembers whether your browser can show emoji. It is cleared when you close the tab. |
yith_wcwl_session_* | YITH WooCommerce Wishlist (this site) | Necessary | Links your browser to the wishlist stored on our website. Set only when you add a product. |
wordpress_*, wp-settings-* | WordPress (this site) | Necessary | Keep our staff logged in. Not set for shoppers, because this site does not offer customer accounts. |
_lscache_vary | LiteSpeed Cache (this site) | Necessary | Tells the page cache which version of a page to serve you. |
__cf_bm, cf_clearance | Cloudflare | Necessary | Bot protection and security checks in front of the site. |
| Cookies set by Stripe, if any, and the Sift fraud check | Stripe and Sift, through WooPayments (WooCommerce, Automattic Inc., United States) | Necessary | Process card payments and detect payment fraud. Stripe’s payment script and Sift’s fraud-check script load on the cart and checkout pages. Sift’s script records the page view with a session ID. When you pay by card, WooPayments may also build an ID from details about your device and browser and send it with your payment. |
| Cookies set by PayPal, if any | PayPal | Necessary | PayPal payment buttons, on product pages and on the cart and checkout pages. |
| Device details, and cookies set by PayPal, if any | PayPal (fraud-prevention script, FraudNet) | Not settled yet (see Necessary) | Collects information about your device and browser to prevent payment fraud. Loads on product pages and checkout pages when a page opens, before you choose to pay. You can object by writing to [email protected], but writing to us does not stop it from loading on your next visit. |
| No cookie | WooCommerce, Automattic Inc., United States (WooPayments) | Not settled yet (see Necessary) | A WooPayments usage-tracking script loads on product pages and on the cart page. Usage tracking is turned off in our store settings, and the script’s settings on our pages tell it not to send anything, so it sends no events. |
| No cookie (device details) | Fraud Blocker LLC, United States | Security and fraud checks | Set up to read details about a device to build an ID (device fingerprinting) and spot fake clicks on our ads. Its tags sit in our Google Tag Manager container, which our pages do not load today, so it does not run on this site. |
bdhcreative-com-shopLayout | Kadence theme (this site) | Preferences | Remembers whether you chose the grid view or the list view on our shop pages, for 30 days. First set only when you click one of those buttons. A later visit may renew it. |
comment_author* | WordPress (this site) | Preferences | Remember the name, email address and website you entered. May be set only if you tick the box to save them when you send a comment or a review. |
_ga, _ga_C0DQL3DDS2 | Google LLC, United States (Google Analytics 4) | Analytics | Tell one visitor apart from another and keep a visit together so pages can be counted. Our Google Analytics property is linked to Google Ads. May be set once you allow Analytics. If you later turn Analytics off, these cookies can stay in your browser until they expire or you delete them. |
sbjs_* (seven cookies) | WooCommerce order attribution (this site) | Advertising and social media | Record where you arrived from, so an order can be linked to the campaign that brought you. May be set once you allow Advertising and social media. If you later turn it off, these cookies can stay in your browser until they expire or you delete them. |
| None today | Meta Platforms Inc., United States (Meta pixel) | Advertising and social media | Tag set up in our Google Tag Manager container. Our pages do not load that container today, so it does not run on this site. |
| None today | LinkedIn Corporation, United States (LinkedIn Insight tag) | Advertising and social media | Tag set up in our Google Tag Manager container. Our pages do not load that container today, so it does not run on this site. |
| None today | HubSpot (tracking script) | Advertising and social media | Tag set up in our Google Tag Manager container. Our pages do not load that container today, so it does not run on this site. |
| None today | TikTok (TikTok pixel) | Advertising and social media | Tag set up in our Google Tag Manager container. Our pages do not load that container today, so it does not run on this site. |
| No website cookie | Emailit | Email tracking | May record opens and clicks in the emails we send. It sets nothing on this website. |
bdhc_consent (cookie, and a copy in local storage) | BDH Collective Inc. (this site’s consent tool) | Necessary | Remembers the choice you make in the banner or the Privacy settings panel, for 6 months. Set when you make a choice. It holds a random identifier, your choice for each category, the language and the dates of your choice. |
The pages of this site no longer load fonts from Google Fonts.
6. What this list does not show
We do not list how long cookies set by other companies last. That is decided by each company and can change, and their own cookie documentation gives the current value. Where we write “if any”, the company decides which cookies it sets. Cookies set by this site last for your browsing session or for the period WordPress, WooCommerce and our site tools set. The wishlist cookie lasts 30 days under the wishlist tool’s default setting, and the shop layout cookie lasts 30 days from when it was last set. Browser storage in localStorage stays until your browser’s site data is cleared, and sessionStorage is cleared when you close the tab.
7. Managing cookies in your browser
Every browser lets you block or delete cookies through its settings. Blocking necessary cookies may break the cart and checkout. Deleting cookies does not stop the tools that run on this site from loading again on your next visit.
8. Third-party cookies
Some cookies and similar tools are set by the companies named in the table above. They have their own privacy and cookie policies, which we encourage you to read.
9. Changes and contact
We update this policy when the site or the tools it uses change, and we change the date at the top. Questions? Write to [email protected], or to BDH Collective Inc., 200-4388 Rue Saint-Denis, Montréal, QC H2J 2L1, Canada. For how we handle personal information, including your rights of access, correction and deletion, see our Privacy Policy.
