Cookie Policy
This Cookie Policy explains how HOLO uses cookies, local storage, session storage, and similar browser technologies. It should be read together with our Privacy Policy.
1. What these technologies do
Cookies are small values a website asks your browser to store and send with later requests. Local storage and session storage are browser-managed stores that are not automatically sent to the server. In this policy, “storage” covers all of these technologies.
We use storage either because it is necessary to provide the service safely, or—only after your permission—to understand how customers use the public HOLO experience.
This Cookie Policy distinguishes browser storage and optional browser analytics from HOLO's limited server-side transaction measurement and strictly necessary Sentry operational/security monitoring, neither of which reads or writes browser cookies, local storage, or session storage.
2. Essential storage and storage-free monitoring
Essential storage cannot be switched off through the HOLO consent controls because the platform cannot operate safely without it.
- Authentication session: keeps you signed in, protects account-only routes, and expires when you sign out or the authentication session expires.
- Language preference (`locale`): remembers Thai or English for up to one year.
- Privacy preference (`holo.cookie-consent` in local storage): records whether analytics is allowed, the policy version, and timestamps for up to 180 days.
- Temporary security and checkout state: preserves short-lived flows such as two-factor authentication and payment navigation for the current tab or transaction.
- Sentry Web monitoring: the browser and server SDKs may report sanitized errors because this is strictly necessary operational/security monitoring under HOLO's legitimate interests. Performance timing and span transmission is disabled at the initial rollout and requires a separate review before enablement. Sentry does not set HOLO cookies or use local or session storage under this integration; Session Replay is disabled, `sendDefaultPii` is `false`, and dynamic path segments, URL queries/hashes, cookies, authorization headers, and request/response bodies are removed before transmission.
3. On-request customer-support storage
HOLO does not load the Chatwoot SDK or write customer-support storage until you click Help. This action requests the live-chat service.
After you click Help, HOLO may store `holo.chatwoot-conversation` in local storage for up to 365 days. It contains a signed conversation identifier so your requested support conversation can continue across page navigation and return visits. It is not used for product analytics or advertising, and clearing it may end browser-side conversation continuity.
The support widget runs in an isolated frame and does not receive the parent page path, query string, or URL tokens from HOLO.
4. Optional analytics storage
If you enable Analytics, the Amplitude Browser SDK may store a pseudonymous device identifier, session timing, and a small retry queue in this browser. HOLO sends pathname-only page views, session activity, and explicit Buy button events.
We do not enable Session Replay, form or element capture, network capture, URL query collection, remote capture overrides, or IP-address collection in the browser SDK.
The Amplitude Browser SDK is not initialized before you consent. If you later disable Analytics, HOLO opts the SDK out and removes its browser identifiers and queued-event storage. Analytics remains off until you enable it again.
5. Your choices
On your first visit, choose Accept all, Reject optional, or Manage settings. Rejecting optional storage does not affect sign-in, purchases, or other core HOLO features.
Rejecting or withdrawing Analytics consent stops browser collection only. The preference is stored on this device and is not sent to the backend, so it does not control the server-side Purchase Completed event described below.
You can reopen Cookie settings from the site footer at any time. We ask again when the stored choice reaches 180 days or when the consent-policy version changes.
Cookie settings controls optional Analytics. Chatwoot remains unloaded until you request it by clicking Help; after that request, Cookie settings does not remove its customer-support conversation storage.
Cookie settings does not disable Sentry operational error monitoring because it is not product analytics and does not use browser storage under HOLO's integration. Sentry may initialize before you make an optional Analytics choice or after you reject it.
You may also clear website data in your browser. Clearing the privacy preference makes the consent notice appear again on your next visit.
6. Service providers, monitoring, and server-side measurement
Chatwoot provides the public customer-support live chat after you click Help. Its widget may process technical or session information and the messages, attachments, and contact details you choose to submit so HOLO can answer and reconnect the conversation. HOLO does not use Chatwoot for advertising or product analytics.
Amplitude provides the optional browser analytics service. Analytics data may be processed outside Thailand subject to the safeguards described in our Privacy Policy. Amplitude does not receive your password, OTP, payment slip, bank details, phone number, shipping address, email, or username through this browser analytics contract.
Sentry provides sanitized browser/server error reporting for Web reliability and security; performance monitoring is disabled at the initial rollout. HOLO does not use it for advertising or product analytics. It does not use HOLO browser storage under this integration, and sensitive URL/request context is removed before transmission. Sentry data location and retention are governed by HOLO's configured organization/project settings and Sentry's applicable privacy and data-processing terms; our Privacy Policy explains this processing and your rights.
Separately, after an order is fulfilled as paid, HOLO sends a server-to-server Purchase Completed event to Amplitude to measure completed purchases, product performance, and revenue. The event contains an internal user ID, order and product identifiers, product type, payment-method category, quantity, item count, amount in THB, and analytics environment. It does not read or write browser cookies, local storage, or session storage and continues when optional browser analytics is rejected or unset.
The server-side event does not contain your email, username, password, OTP, authentication tokens, payment slip, bank details, phone number, or shipping address. See our Privacy Policy for further information about data sharing, international transfers, and your privacy rights.
7. Changes and contact
We update this policy when storage purposes, providers, or retention practices materially change. A material change to optional browser storage or consent purposes also advances the consent-policy version so that you can make a fresh choice; adding storage-free strictly necessary monitoring does not turn that monitoring into optional Analytics.
Questions or privacy-right requests: dpo@hologacha.com