COOKIE POLICY
YACHTPOINT BG OOD
Effective from: 4 June 2026 · Last updated: 2 July 2026
1. What this Policy is
This Cookie Policy explains how YACHTPOINT BG OOD (UIC 208803797, Burgas, info@yachtpoint.bg) uses cookies and similar technologies on the website yachtpoint.bg. It is an integral part of, and should be read together with, the Privacy Policy.
“Cookies and similar technologies” means small files or records stored or read on your device — including cookies, local storage (localStorage/sessionStorage) and pixels. For brevity we refer to all of these as “cookies” below.
2. Legal basis and consent
- Strictly necessary cookies are used on the basis of Art. 4a(4) of the Electronic Commerce Act (ЗЕТ) and do not require consent, as they are necessary for the site to function and for its security.
- All other (optional) cookies — for analytics and advertising — load only after your prior, informed and explicit consent, given via the consent banner (Art. 4a(1) ЗЕТ in conjunction with Art. 6(1)(a) of Regulation (EU) 2016/679 — GDPR).
Consent is freely given, specific and active. We do not use pre-ticked boxes. You can accept all, reject all (with an equally easy action), or customize your choice by category.
3. How to manage and withdraw your consent
- On your first visit, a banner is shown through which you make your choice.
- You can change or withdraw your consent at any time via the “Cookie settings” link in the site footer. Withdrawal is as easy as giving consent.
- We keep a record of your consent. Consent is renewed periodically (typically about every 12 months).
- You can also manage and delete cookies via your browser settings:
Chrome · Firefox · Safari · Edge
4. What happens if you reject
If you reject or do not consent, we do not load optional cookies and the relevant analytics and advertising tools are not loaded and send no data. Strictly necessary cookies and security measures (such as spam and bot protection on forms) remain active, as the site cannot function without them.
5. Cookie categories and list
We use cookies in the following categories. The current full list of cookies used is maintained in this Policy:
| Cookie | Provider | Purpose | Duration | Category |
|---|---|---|---|---|
pll_language |
Polylang | Remembers the selected language | 1 year | Strictly necessary |
wp_woocommerce_session_* |
WooCommerce | Session and cart | 2 days | Strictly necessary |
woocommerce_cart_hash, woocommerce_items_in_cart |
WooCommerce | Cart contents | Session | Strictly necessary |
wordpress_logged_in_*, wordpress_sec_* |
WordPress | User login | Session / up to 14 days | Strictly necessary |
__stripe_mid, __stripe_sid |
Stripe | Payment fraud prevention | 1 year / 30 minutes | Strictly necessary |
cmplz_id, cmplz_policy_id, cmplz_banner-status, cmplz_functional, cmplz_preferences, cmplz_statistics, cmplz_marketing, cmplz_saved_categories, cmplz_consented_services |
Complianz | Stores your consent choices | 12 months | Strictly necessary |
_ga, _ga_* |
Google Analytics 4 | Site usage statistics | Up to 2 years | Analytics |
_fbp, _fbc |
Meta | Ad measurement and optimisation | 90 days | Marketing |
sbjs_* |
WooCommerce (order attribution) | Attributing the source of an order | Up to 6 months | Marketing |
Cloudflare Turnstile does not set any first-party cookies on this site.
5.1. Strictly necessary (no consent)
Needed for the core functioning and security of the site — language, session and cart, login, payment security, protection of forms against spam and abuse. Examples: pll_language (language, Polylang), wp_woocommerce_session_*, woocommerce_cart_hash, woocommerce_items_in_cart (cart/session, WooCommerce), WordPress cookies for logged-in users, __stripe_mid / __stripe_sid (Stripe — fraud prevention at payment), and Cloudflare Turnstile (form protection against bots and abuse — sets no first-party cookies).
5.2. Analytics (consent required)
Help us understand how the site is used (number of visitors, most-viewed pages). Provider: Google Analytics 4 (e.g., _ga, _ga_*).
5.3. Marketing / advertising (consent required)
Used to measure and optimise our advertising and for retargeting. Providers: Meta Pixel (e.g., _fbp, _fbc), Google Ads (e.g., _gcl_au), and WooCommerce order attribution (sbjs_*). These cookies share data with the relevant advertising platforms (see section 6).
5.4. Protection of forms against spam and abuse (strictly necessary)
Protection of the contact and registration forms against spam and bots is provided by Cloudflare Turnstile. Turnstile is classified as a strictly necessary security measure under Art. 4a(4) ЗЕТ and loads without consent, because without it the forms cannot be protected against automated abuse.
Turnstile does not set any first-party cookies on this site. To perform the challenge, your browser connects to the Cloudflare domain (challenges.cloudflare.com) and Cloudflare may set short-lived state on its own domain for the purposes of the challenge. For the international transfer of data to Cloudflare, see section 6.
6. Third parties and international data transfers
Some of the listed cookies belong to third parties that may process data outside the European Economic Area (e.g., in the United States):
- Google (Google Analytics, Google Ads) — Google Cookie Policy
- Cloudflare (Turnstile) — Cloudflare Privacy Policy
- Meta (Meta Pixel) — Meta Cookie Policy
- Stripe — Stripe Privacy Policy
Transfers to the US are protected by EU Standard Contractual Clauses and/or the EU-U.S. Data Privacy Framework. For details of personal-data processing, see our Privacy Policy.
7. Supervisory authority
You have the right to lodge a complaint with the Commission for Personal Data Protection (KZLD): 2 Prof. Tsvetan Lazarov Blvd, Sofia 1592, Bulgaria; email kzld@cpdp.bg; website www.cpdp.bg.
8. Changes and language
We may update this Policy. The current version is published on the site with a last-updated date. This Policy is drawn up in Bulgarian, which is the legally binding version; the English translation is for convenience only, and in case of discrepancy the Bulgarian version prevails.