Controller: ‹controller_name›, ‹registered_address›
Contact: ‹contact_email› (data-protection requests: also the contact form at /contact)
Effective date: ‹effective_date›
Conditional section — shown only when this is set: ‹dpo_email›
Data Protection Officer: ‹dpo_name›, ‹dpo_email›
Conditional section — shown only when this is set: ‹eu_representative›
EU Representative (Art. 27 GDPR): ‹eu_representative› has been designated as the representative of ‹controller_name› in the European Union for the purposes of Article 27 of Regulation (EU) 2016/679. Data subjects and supervisory authorities in the EU may contact ‹eu_representative› in addition to, or instead of, the controller on all matters relating to the processing of personal data and the exercise of rights under the GDPR.
1. What Are Cookies and Similar Technologies?
Cookies are small text files that a website places on your device (computer, tablet, or mobile phone) when you visit it. They are widely used to make websites function correctly, operate efficiently, and to provide information to the website operator.
Cookies may be session cookies (deleted when you close your browser) or persistent cookies (retained on your device for a defined period or until you delete them). They may be set by the website you are visiting (first-party cookies) or by third-party services operating on that website's behalf (third-party cookies).
Article 5(3) of the ePrivacy Directive (2002/58/EC) covers not only cookies but any storing of information, or access to information already stored, on your device. This Policy therefore also covers the other browser storage technologies we use:
- localStorage and sessionStorage (browser key-value storage — see Section 5);
- the Service Worker cache used by our progressive web app (see Section 5.4); and
- Web Push subscriptions (see Section 6).
This Cookie Policy explains exactly what WAW365 stores on your device, why, and how you can control it.
2. Who Sets Cookies on WAW365?
Cookies on the WAW365 platform (waw365.com — the "Platform") are set by:
- ‹controller_name› (first-party cookies), as controller; and
- Google LLC, for Google Analytics 4 (analytics cookies — only in accordance with your consent, see Section 3.3) and, when you use certain abuse-protected public forms, Google reCAPTCHA (see Section 7).
The third-party surface of the Platform is deliberately limited. We do not use advertising or social-media pixels, Google Ads conversion or remarketing tags, heat-mapping or session-recording tools, third-party error trackers, third-party chat widgets, or client-side third-party geolocation services.
For full details of how we process personal data, including the lawful bases, your rights, and our contact details, please read our Privacy Policy.
3. Categories of Cookies We Use
We group cookies into four categories based on their purpose and the legal basis on which they are used.
3.1 Strictly Necessary Cookies
Legal basis: These cookies are technically essential for the Platform to function. They do not require your consent under Article 5(3) of the ePrivacy Directive because their sole purpose is to carry out the transmission of a communication or to provide a service explicitly requested by the user. Under the GDPR, any personal data these cookies carry is processed on the basis of Article 6(1)(b) (performance of a contract) or, for security cookies, Article 6(1)(f) (legitimate interest in securing the Platform and preventing abuse).
Strictly necessary cookies on the Platform:
| Cookie | Purpose |
|---|---|
waw365_session | Maintains your authenticated session across page requests. Without it, you would be logged out on every page load. Protected with the HttpOnly and Secure flags and SameSite=Lax. |
csrftoken | Carries an anti-cross-site-request-forgery token that prevents malicious third-party sites from submitting forms on your behalf. This cookie is deliberately readable by our own front-end code (not HttpOnly) so that the application can attach the token to API requests; it is Secure with SameSite=Lax. |
waw_pass | A short-lived pass issued after an automatic browser check when our bot protection asks for one, so that you are not checked again on every request. Contains a signed token bound to your network; HttpOnly, Secure, SameSite=Lax. Set only when the check is active. |
cookie_consent | Stores your cookie-preference decision (which categories you accepted, and when) so that we do not ask again on every visit. Consent-storage cookies are themselves exempt from the consent requirement. |
Rate-limiting and request-routing on the Platform are implemented without dedicated cookies (they operate on the session and network level).
You cannot opt out of strictly necessary cookies while continuing to use the Platform. You may delete them at any time via your browser settings; doing so will terminate your session.
3.2 Functional (Preference) Cookies
Legal basis: These store choices you have explicitly made so that the Platform can honour them — a service you have requested. They are exempt from the consent requirement as strictly necessary for the service you asked for; associated processing rests on Article 6(1)(b) GDPR.
| Cookie | Purpose |
|---|---|
waw_locale | Remembers the interface language you selected. Set both by your browser when you change language and by our server when it redirects you to your language version. Mirrored in localStorage under the same key. |
Further functional preferences (currency, region, interface layout) are stored in localStorage rather than cookies — see Section 5.
3.3 Analytics Cookies (Google Analytics 4)
Legal basis: Consent — Article 6(1)(a) GDPR in conjunction with Article 5(3) ePrivacy.
Status: active, consent-based. The Platform uses Google Analytics 4 (GA4) to understand how the Platform is used. GA4 runs under Google Consent Mode v2, live on the Platform since 30 June 2026:
- the Google tag (
gtag.js, fromgoogletagmanager.com) is not loaded at all until you click "Accept all": before that, the Platform sends no request to Google Analytics and nothing is stored on or read from your device for analytics. This applies to visitors in every country; - Google Consent Mode v2 is additionally set to "denied" by default for analytics and advertising storage;
- when you click "Accept all", the tag loads, analytics storage is granted and the GA4 cookies listed in Section 4 are set; when you choose "Only necessary", or your browser sends a Global Privacy Control / Do Not Track signal (Section 8.3), the tag is never loaded;
- if you later withdraw consent via "Cookie settings", analytics storage is denied immediately and the tag is not loaded on later visits.
Retention: GA4 data is kept for 14 months (the maximum standard retention setting of the GA4 property).
Processor and international transfer: GA4 is operated by Google LLC (United States). Google LLC is certified under the EU–US Data Privacy Framework, which is covered by a European Commission adequacy decision (10 July 2023); Google additionally offers Standard Contractual Clauses (Art. 46(2)(c) GDPR) as a fallback safeguard.
3.4 Marketing and Attribution Cookies
Legal basis: Consent — Article 6(1)(a) GDPR in conjunction with Article 5(3) ePrivacy. These cookies are placed only if you have enabled marketing cookies via the consent banner ("Accept all"). If you choose "Only necessary" — or "Only necessary" is applied automatically because of a GPC/DNT signal — they are not set, and any already present are deleted.
These are first-party cookies set by us; no data is sent to any third party when they are set. We use them to understand which advertising campaign or referral brought you to the Platform:
| Cookie | Duration | Purpose |
|---|---|---|
waw_ad_gclid | 90 days | Stores the Google Ads click identifier (gclid) present in the URL when you arrive from an advertisement, so that a later registration or order can be attributed to that campaign. If you place an order, the stored value is linked to the order record. |
waw_ad_utm_source, waw_ad_utm_medium, waw_ad_utm_campaign | 90 days | Store campaign tags (utm_*) from the URL you arrived on, for the same attribution purpose. |
waw_ref | 30 days | Stores a referral code when you arrive via a referral link (/ref/{code} or ?ref=), so the referring user can be credited if you register. Deleted once your account is created. |
4. Cookie Table
Complete list of cookies used on the Platform:
| Name | Provider | Purpose | Category | Expiry |
|---|---|---|---|---|
waw365_session | WAW365 (first-party) | Authenticated session. HttpOnly, Secure, SameSite=Lax. | Strictly necessary | 14 days |
csrftoken | WAW365 (first-party) | CSRF protection. Secure, SameSite=Lax; readable by our own scripts by design. | Strictly necessary | ~12 months |
waw_pass | WAW365 (first-party) | Bot-check pass, bound to your network. HttpOnly, Secure, SameSite=Lax. Set only when the browser check is active. | Strictly necessary (security) | 7 days |
cookie_consent | WAW365 (first-party) | Your consent choice (categories + timestamp). Mirrored in localStorage; also recorded server-side as evidence of consent (Art. 7(1) GDPR). | Strictly necessary | 12 months |
waw_locale | WAW365 (first-party) | Interface language. Mirrored in localStorage. | Functional | 12 months |
_ga | Google LLC (GA4) | Distinguishes visitors for analytics. | Analytics — consent required | 2 years (Google default) |
_ga_<container-id> | Google LLC (GA4) | Keeps the analytics session state. | Analytics — consent required | 2 years (Google default) |
waw_ref | WAW365 (first-party) | Referral attribution; removed after registration. | Marketing — consent required | 30 days |
waw_ad_gclid | WAW365 (first-party) | Google Ads click ID attribution. | Marketing — consent required | 90 days |
waw_ad_utm_source | WAW365 (first-party) | Campaign attribution (source). | Marketing — consent required | 90 days |
waw_ad_utm_medium | WAW365 (first-party) | Campaign attribution (medium). | Marketing — consent required | 90 days |
waw_ad_utm_campaign | WAW365 (first-party) | Campaign attribution (campaign). | Marketing — consent required | 90 days |
All first-party cookies use SameSite=Lax; server-set cookies additionally carry the Secure flag. Google reCAPTCHA may set its own cookies on Google's domains when an abuse-protected form is used (Section 7); those are governed by Google's policies.
5. Local Storage, Session Storage, and Service Worker Cache
In addition to cookies, the Platform stores data in your browser's built-in storage. All of the items below are first-party and functional: they exist solely to provide features you use, are never transmitted to third parties, and fall under the "strictly necessary" exemption of Article 5(3) ePrivacy.
5.1 localStorage (persists until you clear it or we remove it)
Consent and language mirrors
cookie_consent— copy of your consent choice (see Section 4);waw_locale— copy of your language preference.
Currency and region preferences
site_currency— currency you explicitly selected;preferred_currency— currency suggested from your region. Region detection is performed by our own server (first-party API); your browser makes no geolocation request to any third party;selected_country_id,selected_city_id— your chosen country/city for catalogue filtering;geo_detection_done— flag that the one-time region suggestion has already run;geo_banner_dismissed— flag that you dismissed the region-suggestion banner.
Interface preferences
sidebar_collapsed,header_hidden— layout state;price_type,acp:view,workbench:chats-rail:sale,workbench:chats-rail:purchase,products_sort,products_page_size,products_market_country,products_market_scope— view-mode and list preferences in the work areas. These contain no personal data;waw_review_banner_dismissed— flag that you dismissed an informational banner in the orders area.
History and drafts
waw365:recent-searches— your recent search queries (stored locally only);waw:cmdk:recent— recent items in the command palette;waw365:wizard:v1— an unsent draft of a parts request, including part/vehicle details you typed; kept until you submit the request. If you use a shared computer, note that this draft remains in the browser until submitted or until you clear site data;waw365.workbenchTour.shown.{userId}— flag that the onboarding tour was shown;waw365.pushBannerDismissedAt— when you dismissed the push-notification invitation.
5.2 sessionStorage (cleared automatically when the tab closes)
waw_global_filters— currently active catalogue filters;waw_dismissed_uploads— upload notifications you have dismissed.
5.3 How to clear browser storage
You can remove all of the above at any time via your browser's "Clear site data" / "Clear browsing data" function for waw365.com. Clearing storage will log you out and reset your preferences, and will cause the consent banner to appear again.
5.4 Service Worker cache
The Platform registers a Service Worker (/sw.js) to work as a progressive web app. It maintains a cache (currently named waw-v5) containing only static assets — the app manifest, icons, and static files — using a stale-while-revalidate strategy. It never caches pages you view, API responses, or messenger content, and it does not read or transmit any personal data. Outdated cache versions are deleted automatically when the app updates. You can remove the Service Worker and its cache via your browser's site-data settings.
6. Web Push Notifications
Signed-in users can opt in to browser push notifications (e.g. for messages and order events). How it works:
- Notifications are enabled only after you grant permission in your browser's native permission prompt — an explicit action that constitutes your consent. We additionally show our own opt-in invitation first; dismissing it is remembered locally (
waw365.pushBannerDismissedAt) so we do not repeat it. - When you subscribe, your browser generates a push subscription (delivery endpoint and keys), which we store on our own servers, linked to your account.
- Delivery is authenticated with the VAPID standard, and notification content is end-to-end encrypted in transit (RFC 8291): the push relay operated by your browser vendor — Google (Chrome), Mozilla (Firefox), or Apple (Safari) — carries only an encrypted payload and delivery metadata and cannot read the content of notifications. Use of a vendor's push relay is inherent to the Web Push standard.
- To unsubscribe: disable push notifications in your notification settings on the Platform, or revoke the notification permission for
waw365.comin your browser's site settings. Either action stops all further push messages, and we delete inactive subscriptions.
7. Third Parties
The complete list of third parties that may receive requests from your browser in connection with the technologies described in this Policy:
| Third party | When your browser contacts it | Purpose | Transfer safeguard |
|---|---|---|---|
Google LLC (googletagmanager.com, Google Analytics) | On Platform pages; analytics cookies only as described in Section 3.3. | Analytics | EU–US Data Privacy Framework (adequacy decision of 10 July 2023); SCCs as fallback |
| Google LLC (reCAPTCHA) | Only when you use certain abuse-protected public forms (e.g. stock alerts, reviews); the script loads at the moment of use, not on every page. | Security / bot protection (legitimate interest, Art. 6(1)(f)) | EU–US Data Privacy Framework; SCCs as fallback |
| Browser push services — Google, Mozilla, Apple | Only if you have enabled push notifications (Section 6). | Encrypted transport of push notifications | Content end-to-end encrypted (RFC 8291); the relay cannot read it |
| Map tile providers — OpenStreetMap Foundation, CARTO | Only on map pages available to signed-in business users; the browser fetches map images directly from the tile server (disclosing your IP address and the map area viewed). | Displaying maps | Tile requests are not used by us for tracking and set no cookies of ours |
We do not use: advertising or social-media pixels, heat-mapping or session-recording services, third-party error trackers, third-party chat widgets, or payment iframes. Authentication uses only our own first-party session cookie — no tokens are stored in browser storage.
AI services used for catalogue content operate exclusively on catalogue data on the server side; they receive nothing from your browser and no cookies or user-identifying information.
If we add a new integration capable of storing or reading data on your device, we will update this Policy and, where required, request consent before it becomes active.
8. How to Manage and Withdraw Consent
8.1 Consent Banner
When you first visit the Platform (or after clearing your cookies), a consent banner appears with two choices:
- Accept all — enables the analytics and marketing categories in addition to strictly necessary and functional storage; or
- Only necessary — only strictly necessary and functional storage is used; no analytics or marketing cookies are set, and attribution cookies already present are deleted.
Your choice is stored in the cookie_consent cookie (12 months) and also recorded in our server-side consent log so that we can demonstrate consent (Art. 7(1) GDPR). The banner is shown on the public pages of the Platform. When the cookie_consent cookie expires, the banner is shown again.
8.2 Changing or Withdrawing Consent
You may change or withdraw your consent at any time, without detriment. Withdrawal is effective for the future and does not affect the lawfulness of processing carried out before withdrawal (Art. 7(3) GDPR).
Ways to change your choice:
- "Cookie settings" link in the site footer — reopens the consent banner on any page; your new choice replaces the old one immediately and is recorded in the consent log.
- Delete the
cookie_consentcookie forwaw365.com(or clear site data) in your browser; the banner will reappear on your next visit. - Delete the analytics or marketing cookies themselves — removing
_ga,_ga_*,waw_ad_gclid,waw_ad_utm_*, andwaw_refin your browser removes them from your device; with consent withdrawn, they will not be set again. - Browser settings — every major browser allows you to view, block, or delete cookies:
- Chrome: Settings → Privacy and security → Cookies and other site data
- Firefox: Settings → Privacy & Security → Cookies and Site Data
- Safari: Preferences → Privacy
- Edge: Settings → Cookies and site permissions
Blocking or deleting strictly necessary cookies will impair or prevent use of the Platform (in particular, you will be logged out).
8.3 Global Privacy Control and Do Not Track
The Platform honours browser privacy signals. If your browser sends a Global Privacy Control signal (navigator.globalPrivacyControl) or a Do Not Track signal (DNT=1) and you have not yet made a choice, the Platform automatically applies "Only necessary": no analytics or marketing cookies are set, the banner is not shown, and the automatically applied choice is recorded in our consent log as originating from a browser signal. An explicit choice you later make through the "Cookie settings" link takes precedence over the signal.
9. Legal Basis Summary
| Category | ePrivacy (Art. 5(3)) | GDPR |
|---|---|---|
Strictly necessary (waw365_session, csrftoken, waw_pass, cookie_consent) | Exempt — essential to the service | Art. 6(1)(b) (contract) and/or Art. 6(1)(f) (legitimate interest — security) |
Functional (waw_locale, preference storage in Section 5) | Exempt — service explicitly requested by the user | Art. 6(1)(b) |
Analytics (GA4: _ga, _ga_*) | Consent required | Art. 6(1)(a) |
Marketing / attribution (waw_ad_*, waw_ref) | Consent required | Art. 6(1)(a) |
| Web Push | Consent via the browser permission prompt | Art. 6(1)(a) |
Legitimate-interest balancing (security cookies): our interest in protecting the Platform and its users from abuse, unauthorised access, and fraud is not overridden by data-subject interests, given that the security cookies carry minimal personal data and are strictly proportionate to the security objective.
10. Retention
| Item | Retention |
|---|---|
waw365_session | 14 days; the corresponding server-side session record expires on the same schedule |
csrftoken | ~12 months |
waw_pass | 7 days |
cookie_consent | 12 months; on expiry the banner is shown again |
waw_locale | 12 months |
_ga, _ga_* | 2 years on your device (Google default); GA4 data on Google's side — 14 months |
waw_ref | 30 days, or until registration (whichever is earlier) |
waw_ad_gclid, waw_ad_utm_* | 90 days; if you place an order, the attribution values are copied to the order record and retained with it under the retention rules in our Privacy Policy |
| localStorage / Service Worker cache | Until you clear site data (or, for the cache, until an app update replaces it); sessionStorage — until the tab closes |
| Server-side consent log | For the life of the account plus 3 years (for visitors without an account — 3 years from the choice), as proof of consent |
| Push subscriptions | Until you unsubscribe or the subscription becomes inactive, after which it is deleted |
11. Your Rights
11.1 Rights Under GDPR (EEA, EU, and applicable jurisdictions)
Where the GDPR applies to our processing of your personal data via cookies and similar technologies, you have the following rights:
- Right of access (Art. 15): You may request confirmation of whether we process personal data about you derived from cookies, and obtain a copy of that data.
- Right to rectification (Art. 16): You may request correction of inaccurate personal data we hold about you.
- Right to erasure ("right to be forgotten", Art. 17): You may request deletion of your personal data where, for example, it is no longer necessary for the purpose it was collected, or you withdraw consent and there is no other lawful basis.
- Right to restriction of processing (Art. 18): You may request that we restrict processing of your data in defined circumstances.
- Right to data portability (Art. 20): Where processing is based on consent or contract and carried out by automated means, you may receive your personal data in a structured, commonly used, machine-readable format.
- Right to object (Art. 21): You may object at any time to processing based on legitimate interests (Art. 6(1)(f)). We will cease processing unless we demonstrate compelling legitimate grounds which override your interests, or the processing is necessary for legal claims.
- Right to withdraw consent (Art. 7(3)): Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing (see Section 8).
- Right to lodge a complaint: You have the right to lodge a complaint with a supervisory authority, in particular in the EU/EEA Member State of your habitual residence, place of work, or place of the alleged infringement. Our lead supervisory authority is: ‹supervisory_authority›. ⚠ lead supervisory authority — depends on the final seat
To exercise any of these rights, use the contact form at /contact (topic "Data-protection request") or write to ‹contact_email›.
11.2 Users in Ukraine
For users in Ukraine, the processing of personal data is additionally governed by the Law of Ukraine "On Personal Data Protection" (Закон України «Про захист персональних даних»), as amended.
The consent banner, the "Cookie settings" link and the handling of GPC/DNT signals work for Ukrainian visitors on the same terms as for EEA visitors, and marketing and attribution cookies are set only with consent for everyone. The Google tag is not loaded before a choice is made, for visitors from every country (Section 3.3). All data is stored in the EEA; we do not transfer personal data to Ukraine.
Under Ukrainian law, you have the right to:
- know the location of the database containing your personal data, its purpose, and the name and address of the controller;
- receive information about the conditions under which your personal data is disclosed, including to third parties;
- access your personal data and receive a copy;
- request rectification of inaccurate, incomplete, or outdated personal data;
- request destruction of your personal data where it was processed unlawfully or is no longer necessary;
- object to the processing of your personal data;
- file a complaint with the Verkhovna Rada Commissioner for Human Rights (Уповноважений Верховної Ради України з прав людини), the supervisory authority for personal data protection in Ukraine; and
- seek judicial protection of your rights.
To exercise these rights, contact us at ‹contact_email› or through the contact form at /contact.
12. Changes to This Cookie Policy
We may update this Cookie Policy from time to time to reflect changes in the cookies and storage technologies we use, changes in applicable law, or for other operational reasons. When we make material changes, we will update the Effective date at the top of this document and, where required by law, seek fresh consent. In particular, we will update this Policy before adding any new third-party integration capable of storing data on your device (Section 7).
This Policy is written in English; translations are provided for convenience. In case of any inconsistency, the English version prevails. The current version is always available on the Platform at waw365.com/{your language}/cookies.
13. Contact and Further Information
For any questions or concerns about this Cookie Policy or the handling of your personal data:
- Controller: ‹controller_name›, ‹registered_address›
- Contact and data-protection requests: ‹contact_email›, or the contact form at /contact
- Legal notice (operator details): /legal
For EU/EEA users, our competent supervisory authority is ‹supervisory_authority›.
For a complete description of how we collect, use, and protect your personal data beyond cookies, please read our Privacy Policy.