This is a policy template for a merchant and its customers, not a sales contract between Aster and visitors to this website.
Store policies are templates for merchants to adapt and review against their actual seller, products and sales markets.
1. Operator and technologies
This store is operated by example at https://example.com; contact privacy@example.com. This draft covers cookies, browser storage, pixels, device identifiers and similar access technologies. Before publication the merchant must check actual theme, plugin, PSP, support and analytics scripts. Using an Aster template does not complete that assessment. The Platform marketing site’s Cookie policy cannot replace the store’s actual notice.
2. Shopping and security essentials
The cart, checkout, account sign-in, request security and storage of privacy choices you request may need storage permitted by an applicable exemption. Each entry requires a necessity assessment and proportionate lifetime. Ad attribution, cross-site tracking or unnecessary fingerprinting cannot be labeled checkout essentials. Necessary PSP security technology must identify the provider and its role; “payment security” does not authorize all associated marketing.
3. Optional purposes and initial state
Language and display preferences, traffic statistics, advertising and remarketing are configured separately. Optional purposes are disabled by default and related tools load only after consent where required. Country-specific statistics or appearance exceptions require all conditions and the required objection mechanism and cannot simply be copied across jurisdictions. Current advertising and analytics providers are example (unconfirmed); scripts with unresolved purposes or bases cannot load before disclosure is completed.
4. Accepting, refusing and changing choices
The privacy panel offers understandable, comparably prominent accept, refuse and category settings, without preselected choices or silence treated as consent. You may change preferences through the footer’s Privacy choices link. Refusal does not block purchases that do not require optional tracking. New purposes or providers trigger renewed choices as required instead of indefinite expansion of old consent. Preference evidence records your wishes rather than acting as an advertising identifier.
5. Required technology register
The production register must list each entry’s name example, provider example, domain example.com, purpose example, category example, lifetime example, recipients and countries example, basis example and disablement method example, distinguishing session and persistent storage. Deleting a browser cookie may not delete related server records, whose periods and rights follow the privacy notice. Merchants must rescan periodically and remove unused or no-longer-authorized entries.
6. Third-party pages and opt-out signals
After navigation to payment, shipping or social sites, those providers may process data under their own policies; the transition should be clear rather than disguising the page’s identity. Universal opt-out signals must be recognized and applied where required, without unnecessary repeated identification. Browser deletion or blocking may affect necessary functions, and assistance remains available at privacy@example.com.
7. Updates and contact
Draft version: draft-2026-10-10. Operative date: example. The choice interface, register and privacy notice must be released together; changing text while old scripts continue is insufficient. Material changes are notified in advance, with consent obtained before processing when necessary. Contact privacy@example.com or address example. This policy makes no certification claim under GDPR, PECR or any other law.