All policies

COOKIE POLICY

COOKIE POLICY

Effective Date: September 13, 2026
Last Updated: September 13, 2026

This Cookie Policy explains how Doshe LLC (“DOSHE,” “we,” “us,” or “our”) may use cookies and similar technologies when users access or interact with doshe.store and related DOSHE services.

This Policy should be read together with the DOSHE Privacy Policy.

Operator: Doshe LLC
United States

Email: info@doshe.store
Website: doshe.store

1. Purpose

Cookies and similar technologies may be used to:

* operate DOSHE;
* authenticate users;
* maintain account sessions;
* remember preferences;
* maintain shopping-cart functionality;
* process transactions;
* improve security;
* prevent fraud;
* understand service performance;
* measure usage;
* improve user experience;
* support permitted analytics;
* provide other functions described in this Policy.

DOSHE will not describe or deploy tracking technologies in a manner inconsistent with their actual operation.

2. What Is a Cookie?

A cookie is a small data file that a website may store on a user’s browser or device.

Cookies may allow a website to:

* recognize a browser or device;
* maintain a session;
* remember settings;
* retain shopping-cart information;
* support security;
* measure interactions.

3. Similar Technologies

This Policy also applies, where relevant, to technologies that may store or access information on a user’s device or otherwise recognize or measure interactions.

These may include:

* pixels;
* tags;
* local storage;
* software development kits;
* device identifiers;
* scripts;
* web beacons;
* similar technologies.

The legal treatment of these technologies may depend on jurisdiction and purpose.

4. First-Party Cookies

First-party cookies are set by or on behalf of DOSHE through doshe.store.

They may support functions such as:

* login;
* account management;
* cart functionality;
* security;
* language preferences;
* cookie preferences.

5. Third-Party Cookies and Technologies

Certain third-party service providers may place or access cookies or similar technologies when providing services to DOSHE.

Potential categories of providers may include:

* payment providers;
* security providers;
* hosting or infrastructure providers;
* analytics providers;
* customer-support services;
* embedded-content providers;
* other technology vendors.

DOSHE will identify actual providers in its cookie-management interface or cookie inventory where legally required and technically applicable.

6. No Invented Vendor List

DOSHE does not state in this Policy that a particular analytics, advertising, social-media, or tracking provider is in use unless that provider is actually deployed.

The live cookie inventory should reflect the technologies actually present on doshe.store.

7. Strictly Necessary Cookies

Strictly necessary technologies may be required for core functionality such as:

* account authentication;
* security;
* fraud prevention;
* shopping-cart operation;
* checkout;
* load balancing;
* network communications;
* storing privacy choices;
* other functionality specifically requested by the user.

Where applicable law permits, these technologies may operate without consent because they are necessary for the requested service or another applicable exemption applies.

8. Security Cookies

DOSHE may use cookies or similar technologies to:

* detect suspicious activity;
* protect accounts;
* reduce fraud;
* prevent unauthorized access;
* maintain session integrity;
* defend the website against abuse.

Where legally permitted, necessary security technologies may operate without optional cookie consent.

9. Shopping-Cart Technologies

Cookies may be necessary to:

* remember products placed in a cart;
* associate cart contents with a session;
* support checkout;
* preserve information during transaction flow.

These technologies may qualify as necessary where applicable law permits.

10. Authentication Technologies

DOSHE may use technologies required to:

* keep a user logged in;
* recognize an authenticated session;
* protect account access;
* maintain requested account functionality.

11. Preference Cookies

Preference technologies may remember choices such as:

* language;
* region;
* interface settings;
* display preferences;
* other user-selected settings.

Whether consent is required depends on the technology, purpose, and applicable law.

12. Analytics Technologies

DOSHE may use analytics technologies to understand:

* website traffic;
* page performance;
* feature usage;
* errors;
* navigation patterns;
* aggregate interaction trends.

Where applicable law requires consent before such technology is used, DOSHE will seek the required consent before activating it.

13. Advertising and Behavioral Tracking

DOSHE currently does not operate a paid seller advertising program.

This fact does not automatically determine whether every third-party website technology constitutes advertising, cross-context behavioral advertising, targeted advertising, sale, or sharing under applicable privacy law.

If DOSHE deploys technologies used for such purposes, DOSHE will provide the required notices, consent mechanisms, and opt-out rights where applicable.

14. No Assumption That Analytics Is Automatically Necessary

DOSHE will not classify analytics or tracking technology as strictly necessary merely because the information is useful to DOSHE.

Each technology should be classified based on its actual purpose and applicable legal requirements.

15. Session Cookies

Session cookies generally remain active only for a browser session and may be removed when the browser is closed.

16. Persistent Cookies

Persistent cookies may remain on a device for a defined period or until deleted.

The applicable cookie inventory should identify relevant retention periods where required.

17. Cookie Duration

DOSHE will seek to avoid retaining cookies longer than reasonably necessary for their stated purpose.

Actual cookie duration depends on:

* technology;
* function;
* vendor;
* user choice;
* applicable law.

18. Cookie Consent

Where applicable law requires consent, DOSHE will obtain a valid choice before activating the relevant non-exempt technology.

Consent mechanisms should be:

* informed;
* specific where required;
* freely given;
* based on affirmative action;
* capable of withdrawal.

19. No Consent by Mere Continued Browsing Where Invalid

Where applicable law requires affirmative consent, DOSHE will not treat mere continued browsing, inactivity, or silence as valid consent.

20. Rejecting Non-Essential Cookies

Where consent is required, users should have a meaningful method to reject non-essential technologies.

DOSHE should not intentionally make rejection materially more difficult than acceptance where applicable law requires equivalent ease of choice.

21. Cookie Banner

Where required, DOSHE may display a cookie or privacy banner allowing users to:

* accept permitted categories;
* reject non-essential technologies;
* manage preferences;
* obtain additional information.

22. Recommended Banner Structure

Where required by applicable law, the first consent layer should provide clear choices such as:

Accept Optional Cookies

Reject Optional Cookies

Manage Preferences

The interface should avoid deceptive design.

23. No Pre-Ticked Optional Consent

Where affirmative consent is legally required, optional cookie categories should not be treated as consent merely because a pre-selected option was displayed to the user.

24. Granular Choices

Where appropriate, users may be allowed to choose among categories such as:

* Necessary;
* Preferences;
* Analytics;
* Advertising or Targeting.

The categories displayed must correspond to technologies actually used.

25. Withdrawal of Consent

Where processing relies on consent, users must be able to withdraw that consent where required by law.

Withdrawal should be reasonably accessible.

26. Changing Cookie Preferences

DOSHE should provide an accessible Cookie Settings, Privacy Choices, or equivalent control where needed.

Users should not be required to clear all browser data merely to withdraw optional cookie consent if a simpler platform mechanism is required.

27. Consent Records

Where necessary to demonstrate compliance, DOSHE may retain records such as:

* consent status;
* timestamp;
* policy or banner version;
* categories accepted or rejected;
* technical identifiers reasonably necessary to document the choice.

Such records are subject to the Privacy Policy.

28. Consent Renewal

DOSHE may seek renewed consent when:

* purposes materially change;
* vendors materially change;
* law requires renewed consent;
* an appropriate consent period expires;
* previous consent is no longer sufficiently informed.

UNITED STATES AND CALIFORNIA

29. U.S. Privacy Laws

Cookie-related obligations vary among U.S. states.

DOSHE will apply state privacy requirements where they apply to Doshe LLC and the relevant processing.

30. California

California privacy law may regulate certain online technologies where they result in the collection, use, sale, or sharing of personal information by a covered business.

DOSHE’s Privacy Policy describes California privacy rights in greater detail.

31. CCPA Applicability

Nothing in this Policy states that Doshe LLC necessarily meets every statutory threshold for treatment as a “business” under the California Consumer Privacy Act.

Where the CCPA applies, DOSHE will honor applicable requirements.

32. Sale and Sharing

DOSHE does not represent that it sells personal information for monetary compensation.

However, California law may define “sale” or “sharing” more broadly than an ordinary monetary sale.

If DOSHE’s technology practices constitute sale or sharing under applicable California law, required notices and opt-out mechanisms will be provided.

33. Global Privacy Control

Where Doshe LLC is legally required to honor an opt-out preference signal such as Global Privacy Control (GPC), DOSHE will treat a qualifying signal as required by applicable law.

34. GPC and Cookie Preferences

A GPC signal may have legal consequences separate from ordinary cookie consent.

DOSHE’s consent-management implementation should therefore be capable of appropriately processing GPC where legally required.

35. Do Not Sell or Share

Where legally required, DOSHE will provide an appropriate method to exercise the right to opt out of sale or sharing of personal information.

This may include a Your Privacy Choices or equivalent interface.

36. Sensitive Personal Information

DOSHE should not use optional tracking technologies to process sensitive personal information in a manner inconsistent with applicable California law.

EUROPEAN UNION AND EEA

37. EU/EEA Users

Where EU or EEA electronic-privacy and data-protection rules apply, DOSHE will apply the applicable requirements concerning storage of or access to information on users’ devices.

38. Prior Consent for Non-Exempt Technologies

Where required under applicable EU/EEA rules, non-essential cookies or similar technologies will not be activated before valid consent has been obtained.

39. Necessary Technologies

Consent may not be required for technologies that fall within an applicable legal exemption, including certain technologies strictly necessary to provide a service expressly requested by the user.

40. Equal Ability to Refuse

Where applicable EU rules require it, refusing optional cookies should be as easy as accepting them.

DOSHE should not use interface design intended to pressure users into accepting optional tracking.

41. No Cookie Wall Unless Lawful

DOSHE should not make access to ordinary services conditional on optional tracking consent unless such an arrangement is lawful under the circumstances.

42. Consent and GDPR

Where cookie-derived information constitutes personal data, subsequent processing may also be governed by the GDPR.

Obtaining cookie consent does not by itself satisfy every separate GDPR requirement.

43. Legal Bases

Where GDPR applies, DOSHE will identify an appropriate legal basis for processing personal data obtained through cookies or similar technologies.

44. International Transfers

Where cookie or analytics vendors transfer personal data internationally, applicable international-transfer requirements remain subject to the DOSHE Privacy Policy and applicable law.

UNITED KINGDOM

45. UK Users

Where United Kingdom law applies, DOSHE will comply with applicable requirements under PECR, the UK GDPR, and relevant amendments.

46. UK Storage and Access Technologies

UK rules may apply not only to conventional cookies but also to other technologies that store information on or access information from a user’s device.

47. UK Consent

Where no applicable exception applies, DOSHE will obtain the legally required consent before using covered storage or access technologies.

48. UK Exceptions

Certain technologies may qualify for statutory exceptions.

DOSHE will determine eligibility based on:

* actual purpose;
* applicable law;
* current regulatory guidance.

A technology will not be labeled exempt solely for convenience.

PAYMENT TECHNOLOGIES

49. Stripe

DOSHE currently uses Stripe and Stripe Connect for payment-related services.

Stripe may use cookies or similar technologies in connection with:

* checkout;
* fraud prevention;
* payment security;
* authentication;
* payment processing;
* legal compliance.

Stripe’s own processing may also be governed by Stripe’s privacy and cookie disclosures.

50. Payment Security

Technologies necessary to securely complete a buyer-requested payment may qualify for an applicable exemption in certain jurisdictions.

This does not mean every technology used by a payment provider is automatically exempt from consent requirements.

EMBEDDED AND THIRD-PARTY CONTENT

51. Embedded Services

If DOSHE embeds third-party services such as:

* video;
* maps;
* social-media content;
* support tools;
* other external functionality,

those services may use their own technologies.

Where legally necessary, DOSHE should prevent non-essential third-party technologies from activating until the relevant user choice is obtained.

52. Social Media

Social-media integrations can potentially transmit information to external platforms.

DOSHE will not state that such integrations are active unless they are actually implemented.

TECHNICAL COOKIE INVENTORY

53. Cookie Inventory

DOSHE should maintain a current internal inventory identifying, where applicable:

* cookie or technology name;
* provider;
* domain;
* purpose;
* category;
* first-party or third-party status;
* duration;
* legal or consent status.

54. Public Cookie List

Where appropriate or legally required, relevant information from the inventory should be made available through the cookie-management interface or a public table.

55. Dynamic Cookie Inventory

Because website technologies may change, DOSHE may maintain the detailed cookie list dynamically rather than hard-coding an inaccurate permanent list into this Policy.

56. Vendor Changes

Before introducing a new tracking or analytics vendor, DOSHE should evaluate:

* what information it collects;
* purposes;
* duration;
* third-party sharing;
* international transfers;
* consent requirements;
* applicable privacy rights.

57. Cookie Scanner

DOSHE may use technical scanning tools to help identify cookies and tracking technologies.

Automated scanning should be supplemented by configuration and vendor review where necessary because scanners may not detect every technology.

58. Periodic Audit

DOSHE should periodically audit:

* cookies;
* scripts;
* pixels;
* embedded services;
* tag managers;
* analytics;
* consent behavior.

59. Blocking Before Consent

Where prior consent is legally required, DOSHE’s consent system should technically prevent applicable optional technologies from firing before consent.

A banner that merely displays text without actually controlling tracking may be insufficient.

60. Withdrawal Testing

DOSHE should test whether withdrawing consent actually stops future activation of the relevant optional technologies where required.

61. Consent Logs

DOSHE should maintain sufficient records to demonstrate that the consent system is functioning as represented where legally necessary.

62. Dark Patterns

DOSHE should not use manipulative interface design intended to impair privacy choices.

Examples may include:

* hidden reject controls;
* misleading button labels;
* materially unequal choice paths;
* repeated pressure after refusal.

63. Children

DOSHE does not intend its seller services for children.

If cookie or tracking practices implicate children’s privacy laws, DOSHE will apply additional legally required protections.

64. Browser Controls

Users may also control cookies through browser or device settings.

Blocking necessary cookies may affect functionality such as:

* login;
* shopping cart;
* checkout;
* account preferences.

65. Browser Controls Do Not Replace Required Platform Controls

Where law requires DOSHE to provide a consent or opt-out mechanism, DOSHE will not rely solely on a user’s ability to change browser settings.

66. Do Not Track

Traditional browser Do Not Track (DNT) signals do not have a universally adopted legal or technical standard.

DOSHE’s treatment of DNT may differ from legally recognized signals such as GPC.

67. Security

DOSHE applies reasonable measures to protect information processed through its systems.

Cookies should not be used as a substitute for appropriate security controls.

68. Personal Information

Information collected through cookies or similar technologies may constitute personal information or personal data under applicable law.

Such information is also governed by the DOSHE Privacy Policy.

69. Third-Party Responsibility

Third-party providers may process information under their own privacy terms and legal roles.

DOSHE does not control every independent activity of a third-party provider.

DOSHE remains responsible for its own obligations concerning vendor selection, disclosure, consent, contracts, or other requirements where applicable.

70. Changes to This Policy

DOSHE may update this Cookie Policy when:

* technologies change;
* vendors change;
* purposes change;
* laws change;
* regulatory guidance changes;
* website functionality changes.

The Last Updated date will be revised when appropriate.

Where legally required, DOSHE will seek renewed consent or provide additional notice.

71. Relationship to the Privacy Policy

This Cookie Policy supplements the DOSHE Privacy Policy.

If cookie-derived information is personal information, all applicable Privacy Policy provisions continue to apply.

72. Relationship to Regional Addenda

Additional requirements may be described in:

* California privacy notices;
* EU/EEA Addendum;
* UK Addendum;
* other regional privacy notices.

Mandatory local law controls where it cannot lawfully be waived.

73. Contact

Questions about cookies, similar technologies, or privacy choices may be directed to:

Doshe LLC
7689 Palmilla Dr
San Diego, CA 92122
United States

Email: info@doshe.store
Website: doshe.store

74. Implementation Requirement

This Policy describes DOSHE’s legal and operational framework.

It must be implemented consistently with the website’s actual technical configuration.

Before publication or whenever material technology changes occur, DOSHE should confirm:

* the actual cookies and trackers in use;
* which technologies load before consent;
* vendor identities;
* retention periods;
* consent categories;
* GPC behavior;
* withdrawal functionality.

No statement in this Policy should be interpreted as authorizing technology that would otherwise violate applicable law.

75. Acceptance and User Choices

Use of strictly necessary technologies may occur as permitted by applicable law.

Optional technologies that legally require consent will be governed by the user’s applicable privacy choices.

Continuing to browse DOSHE does not by itself constitute consent where applicable law requires an affirmative choice.