Cookie Policy
Baby Bloom Sydney Pty Ltd | ABN 17 463 812 867
Version 1.0 — Effective 13 March 2026
1. Introduction
This Cookie Policy (“Policy”) explains how Baby Bloom Sydney Pty Ltd (“Baby Bloom,” “we,” “us,” or “our”) uses cookies and similar tracking technologies when you access or use our website at babybloomsydney.com.au and our web application (collectively, the “Platform”).
This Policy should be read in conjunction with our Privacy Policy and applicable Terms of Service. In the event of any conflict between this Policy and the Privacy Policy, the Privacy Policy shall prevail.
By continuing to use the Platform, you acknowledge that you have read and understood this Policy. You may manage your cookie preferences at any time via the cookie consent banner accessible from the footer of the Platform.
2. What Are Cookies?
Cookies are small text files that are placed on your device (computer, tablet, or mobile phone) when you visit a website. Cookies are widely used to make websites function efficiently, to improve user experience, and to provide reporting information to website operators. Cookies set by the website operator are called “first-party cookies.” Cookies set by parties other than the website operator are called “third-party cookies.”
Cookies may be “session cookies” (which are deleted when you close your browser) or “persistent cookies” (which remain on your device for a set period or until you delete them manually).
3. Categories of Cookies We Use
3.1 Essential Cookies (Strictly Necessary)
These cookies are required for the Platform to function correctly. They enable core functionality such as user authentication, session management, security protections, and payment processing. Essential cookies cannot be disabled without impairing the Platform’s functionality. No consent is required for essential cookies under the Privacy Act 1988 (Cth) or the Spam Act 2003 (Cth).
| Cookie Name | Provider | Purpose | Type | Expiry |
|---|---|---|---|---|
| sb-*-auth-token | Baby Bloom (Supabase) | User authentication and session management. Required to maintain login state across page navigations. | First-party | Session / 7 days |
| baby_bloom_consent_preferences | Baby Bloom | Stores your cookie consent preferences to avoid repeated consent prompts. | First-party | 12 months |
| __stripe_mid | Stripe, Inc. (USA) | Fraud prevention and payment security. Required for PCI DSS compliance when processing payments. | Third-party | 1 year |
| __stripe_sid | Stripe, Inc. (USA) | Payment session identification and fraud detection during active checkout sessions. | Third-party | 30 minutes |
3.2 Analytics Cookies (Performance)
Analytics cookies collect information about how visitors interact with the Platform, including which pages are visited most frequently, how long visitors spend on each page, and any error messages encountered. This information is aggregated and anonymised where possible. Analytics cookies are set only with your express consent.
| Cookie Name | Provider | Purpose | Type | Expiry |
|---|---|---|---|---|
| _ga | Google LLC (USA) | Distinguishes unique users by assigning a randomly generated identifier. Used to calculate visitor, session, and campaign data for site analytics reports. | Third-party | 2 years |
| _gid | Google LLC (USA) | Distinguishes unique users within a 24-hour period. Used to throttle request rate and group page views into sessions. | Third-party | 24 hours |
3.3 Marketing Cookies (Advertising & Social)
Marketing cookies are used to track visitors across websites for the purpose of displaying advertisements that are relevant and engaging. These cookies may also be used to measure the effectiveness of advertising campaigns and to limit the number of times you see a particular advertisement. Marketing cookies are set only with your express consent.
| Cookie Name | Provider | Purpose | Type | Expiry |
|---|---|---|---|---|
| _fbp | Meta Platforms, Inc. (USA) | Tracks user interactions for social sharing, community engagement measurement, and targeted advertising within the Meta advertising network. | Third-party | 90 days |
| _gcl_au | Google LLC (USA) | Conversion tracking for Google Ads. Stores a unique identifier to attribute conversions to specific advertising campaigns. | Third-party | 90 days |
4. Managing Your Cookie Preferences
When you first access the Platform, a cookie consent banner is displayed offering three options:
- Accept All Cookies — enables essential, analytics, and marketing cookies.
- Reject Non-Essential — enables essential cookies only. Analytics and marketing cookies are not set.
- Manage Preferences — opens a preferences panel allowing granular control over each cookie category.
Default behaviour: If you do not interact with the consent banner, only essential cookies are set. Non-essential cookies are not loaded until you actively consent. This is consistent with the principle of data minimisation under Australian Privacy Principle (APP) 3.
Within the “Manage Preferences” panel, you may independently toggle:
- Essential cookies — always enabled (cannot be disabled).
- Analytics cookies (Google Analytics) — enable or disable.
- Marketing cookies (Google Ads, Meta Pixel) — enable or disable.
You may change your cookie preferences at any time by clicking the cookie settings icon displayed in the footer of the Platform. Changes take effect immediately; however, cookies already stored on your device will not be removed until they expire or you delete them through your browser settings.
4.1 Browser-Level Cookie Management
In addition to the consent banner, you may manage cookies directly through your web browser settings:
- Google Chrome: Settings > Privacy and Security > Cookies and other site data
- Apple Safari: Preferences > Privacy > Cookies and website data
- Mozilla Firefox: Settings > Privacy & Security > Cookies and Site Data
- Microsoft Edge: Settings > Cookies and site permissions > Manage and delete cookies and site data
For comprehensive browser-specific instructions, visit www.allaboutcookies.org.
Please note that disabling essential cookies via your browser may prevent certain Platform features from functioning correctly, including authentication, payments, and session management.
4.2 Google Analytics Opt-Out
You may opt out of Google Analytics data collection by installing the Google Analytics Opt-Out Browser Add-On, which prevents the Google Analytics JavaScript from sharing information with Google Analytics about visit activity.
5. Other Tracking Technologies
In addition to cookies, the Platform may use the following technologies to collect information about your use of the Platform:
- Web beacons (tracking pixels): Small, transparent image files embedded in web pages or emails that record when a page or email is opened. Used by Google Ads and Meta for conversion tracking and campaign measurement.
- Local storage: A browser-based storage mechanism that allows the Platform to store data persistently on your device. Used for caching user preferences and consent settings.
- Server-side analytics: Aggregated, anonymised data collected at the server level (e.g., page load times, error rates, geographic distribution of requests) that does not involve client-side tracking.
These technologies serve the same purposes as the cookies described in Section 3. You may block web beacons and local storage through your browser’s privacy settings, though doing so may affect Platform functionality.
6. Overseas Data Disclosure
In accordance with Australian Privacy Principle 8.1 (APP 8 — Cross-border disclosure of personal information), Baby Bloom discloses that the following third-party cookie providers process personal information outside Australia:
- Google LLC (United States): Processes analytics data (IP address, device information, browsing behaviour) and advertising conversion data. Google’s privacy policy is available at policies.google.com/privacy.
- Meta Platforms, Inc. (United States): Processes behavioural tracking data for social sharing measurement and targeted advertising. Meta’s privacy policy is available at facebook.com/privacy/policy.
- Stripe, Inc. (United States): Processes fraud detection and payment session data. Because Stripe cookies are classified as essential (required for PCI DSS compliance), they cannot be declined when using payment features. Stripe’s privacy policy is available at stripe.com/au/privacy.
By accepting non-essential cookies, you acknowledge and consent to your personal information being disclosed to and processed by these United States-based entities. United States privacy laws differ from Australian privacy laws, and the Australian Privacy Principles may not be enforceable in the United States. Baby Bloom does not have direct control over third-party data handling practices beyond the terms of our agreements with these providers.
Note: Third-party privacy policy URLs were last verified on 14 March 2026 and may change without notice. Please visit the provider’s website directly for current information.
7. Data Retention
- Session cookies: Deleted when you close your browser or after 30 minutes of inactivity, whichever occurs first.
- Consent preferences cookie: Retained for 12 months from the date of your last preference selection. After expiry, the consent banner will be displayed again.
- Google Analytics (_ga): 2 years from last activity. Refreshed on each visit.
- Google Analytics (_gid): 24 hours from last activity.
- Marketing cookies (_fbp, _gcl_au): 90 days from last activity.
- Stripe cookies: __stripe_mid retained for 1 year; __stripe_sid retained for 30 minutes (session-based).
If you clear your browser cookies, all cookies (including consent preferences) will be deleted. Non-essential cookies will not be re-set until you provide consent again via the consent banner.
8. Marketing Communications
If you accept marketing cookies, Baby Bloom and its advertising partners may serve you targeted advertisements on third-party platforms (e.g., Facebook, Google Display Network). Baby Bloom may also send promotional emails in compliance with the Spam Act 2003 (Cth). All marketing emails include:
- A functioning unsubscribe mechanism.
- Accurate sender identification: Baby Bloom Sydney Pty Ltd, ABN 17 463 812 867.
- A valid reply-to address: contact@babybloomsydney.com.au.
You may opt out of marketing emails at any time by clicking “Unsubscribe” in any email or by adjusting your cookie preferences to disable marketing cookies.
9. Do Not Track (DNT) Signal
Baby Bloom respects the Do Not Track (DNT) browser signal. If your browser is configured to send a DNT signal, the Platform will not set marketing cookies, regardless of your cookie consent preferences. Analytics cookies may still be set if you have expressly consented to them via the consent banner.
10. Consent Withdrawal
You may withdraw your consent to non-essential cookies at any time by accessing the cookie preferences panel via the footer icon. Withdrawal of consent is prospective only — it does not affect the lawfulness of processing carried out prior to withdrawal. Upon withdrawal, non-essential cookies will not be set on subsequent page loads; however, cookies already stored on your device will persist until they expire or are manually deleted through your browser settings.
11. Your Rights Under the Privacy Act 1988
Under the Privacy Act 1988 (Cth), you have the right to:
- Access the personal information we hold about you (APP 12).
- Correct inaccurate or outdated personal information (APP 13). If you believe tracking data has been attributed to you incorrectly, you may request correction.
- Complain about a breach of the Australian Privacy Principles.
To exercise any of these rights in relation to cookie data, contact our Compliance Officer at compliance@babybloomsydney.com.au with the subject line “Cookie Data Request.” Baby Bloom will respond within 30 days.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or by telephone on 1300 363 992.
12. Changes to This Policy
Baby Bloom may update this Cookie Policy from time to time to reflect changes in our practices, technology, or applicable law. Material changes will be communicated by posting the updated Policy on the Platform with a revised “Effective” date. If a change materially affects your rights or requires renewed consent, we will notify you via the consent banner or by email (if you are a registered user).
We recommend reviewing this Policy periodically to stay informed about our use of cookies.
13. Contact Information
Baby Bloom Sydney Pty Ltd
ABN: 17 463 812 867
Sydney, New South Wales, Australia
- General enquiries: contact@babybloomsydney.com.au
- Support: support@babybloomsydney.com.au
- Privacy & Compliance: compliance@babybloomsydney.com.au
This Policy is governed by the laws of New South Wales, Australia. For full details of how Baby Bloom handles your personal information, see our Privacy Policy.
Manage Your Cookie Preferences
Use the toggles below to control which categories of cookies are active. Essential cookies cannot be disabled as they are required for the Platform to function. Changes take effect immediately.
Essential Cookies
Required for the Platform to function. Cannot be disabled.
Analytics Cookies
Google Analytics — helps us understand how visitors use the Platform.
Marketing Cookies
Google Ads & Meta Pixel — used for targeted advertising and campaign measurement.