Skip to main content
Eligible orders over US$80 ship free by sea No minimum order US · UK · CA · AU
SanYuan Herbs · current evidence and product facts take priority
Storage & Access Technologies · Live Inventory Required

Cookie Policy

Understand how cookies, local storage, pixels, tags and embedded content are controlled—using the technologies actually detected on the site rather than a guessed plugin list.
P057 = storage/access ownerLive Cookie RegisterReject / Accept / Customize must workNo pre-choice firing where consent is required
01Do not guess cookie names before a real scan
02A technology is not 'necessary' just because marketing wants it
03Preference controls must actually block optional technologies when required
04Cookie wording and consent logic must match the current market/legal configuration
CATEGORYStrictly Necessary / Excepted

Keep only technologies that truly meet the applicable exemption/necessity test.

CATEGORYPreferences / Analytics

Purpose, vendor, duration and consent status come from the live inventory.

CATEGORYMarketing / Embedded

Third-party pixels and embeds must not disappear from the policy if they actually run.

CONTROLPreference Center

Users need a real way to review and change choices.

Cookie Policy

SanYuan Herbs uses browser and device technologies to operate the ecommerce site, maintain security, remember choices and—only where configured—measure or market the site.

This policy covers more than traditional cookies.

It can include:

  • cookies;
  • local storage;
  • session storage;
  • pixels;
  • tags;
  • embedded third-party storage/access;
  • similar technologies.

The exact list comes from our live technology register, not from a generic template.

CTA: Manage Cookie Preferences


What Is a Cookie?

A cookie is a small piece of data stored by a website/browser for purposes such as:

  • session management;
  • cart;
  • login;
  • preferences;
  • measurement.

Other technologies can perform similar storage/access functions without using a traditional cookie.


Strictly Necessary / Validly Excepted Technologies

Some technologies may be necessary for a service the user requests.

Examples can include:

  • cart/session;
  • checkout;
  • account login;
  • security;
  • load balancing;
  • consent preference itself.

Each technology must still be assessed.

Do not label:

  • analytics;
  • advertising;
  • A/B testing

“necessary” only because it is useful to the business.

Current necessary register: Not publicly specified · Necessary Tech Register


Preference / Functional Technologies

These may remember:

  • language;
  • display choices;
  • non-essential personalization

depending on actual setup.

Legal treatment:

Not publicly specified · Functional Tech Consent Rule

Do not assume all “functional” tools are exempt.


Analytics

Possible analytics technologies:

Not publicly specified · Analytics Technologies

For each:

  • provider;
  • cookie/storage name;
  • purpose;
  • data;
  • duration;
  • first/third party;
  • consent/status

must be recorded.

If analytics requires consent for a user:

rejection must actually prevent the technology from loading/storing/accessing as required.


Marketing / Advertising

Current status:

Not publicly specified · Marketing Tech Status

Potential technologies can include:

  • ad pixels;
  • remarketing;
  • conversion measurement;
  • cross-site identifiers.

Do not state:

“we do not sell/share data”

solely because the company does not receive cash.

P055 controls legal sale/share disclosures after audit.


Embedded Content

Third-party embeds may trigger their own technologies.

Examples:

  • YouTube;
  • maps;
  • social embeds;
  • payment widgets;
  • review widgets.

Current embed register:

Not publicly specified · Embed Tech Register

Prefer:

  • privacy-enhanced mode;
  • click-to-load;
  • consent gating

where appropriate.


Live Cookie / Technology Register

Public table should be generated from the verified register:

NameProviderTypePurposeCategoryFirst/Third PartyDurationConsent/Exception
Not publicly specified · Tech 1Not publicly specified · Provider 1Not publicly specified · Type 1Not publicly specified · Purpose 1Not publicly specified · Category 1Not publicly specified · Party 1Not publicly specified · Duration 1Not publicly specified · Legal Rule 1

Never publish placeholder rows.


How Consent Works

For users/uses where consent is required:

  1. optional technologies are blocked or held;
  2. the banner provides clear information;
  3. the user can make a real choice;
  4. the choice is recorded;
  5. the user can change it later.

No Pre-Ticked Consent

Optional categories must not be enabled merely by:

  • scrolling;
  • continuing to browse;
  • a prechecked box

where valid consent requires an affirmative choice.


Reject / Accept / Customize

Recommended interface:

  • Accept optional
  • Reject optional
  • Customize

The labels should be equally understandable.

Avoid:

  • dark patterns;
  • hiding Reject three screens deep;
  • misleading button colors/text;
  • making a user register to reject cookies.

Consent Record

Maintain:

Consent ID
anonymous/user ID where appropriate
region/rule set
policy version
categories
vendors
timestamp
choice
withdrawal/update
CMP version

Do not retain consent records longer than necessary.


Change Your Preferences

Persistent footer link:

Cookie Settings

Clicking it should reopen the real consent manager.

Do not create a dead link.


Browser Controls

Users can also manage cookies/storage through their browser.

Browser controls do not remove SanYuan’s obligation to provide required transparency/consent.


United Kingdom

Current ICO guidance applies PECR to cookies and broader storage/access technologies.

As of 29 April 2026, the ICO’s final Storage and Access Technologies guidance reflects changes following the Data (Use and Access) Act.

P057 must therefore be implemented against:

  • the current technology;
  • its purpose;
  • current exception/consent criteria.

Do not use an obsolete consent table without review.


European Union

The current SanYuan target-market architecture is:

US / Canada / UK / Australia.

Do not claim the site is “GDPR compliant across the EU” merely because UK users are served.

If SanYuan intentionally targets EU/EEA users or otherwise falls within applicable EU rules:

perform a separate scope/legal review.


United States

US cookie/tracking obligations vary by state and practice.

P055 owns:

  • CCPA/other state applicability;
  • sale/share/targeted advertising;
  • GPC.

P057 implements the actual browser/storage controls.

If opt-out signals apply:

they need backend behavior, not policy text only.


Canada

Cookie/tracking consent and marketing/privacy obligations should be assessed under applicable Canadian privacy/electronic-marketing rules and actual technology sensitivity.

No one UK rule should be mechanically labeled “Canadian law.”


Australia

Australian privacy/direct-marketing requirements depend on actual privacy-law scope and data handling.

Use the current site register and P055 applicability matrix.


Changes

Run periodic scans:

  • after plugin update;
  • after new analytics/ad tag;
  • after checkout integration;
  • after video/embed change;
  • after AI feature change.

Last Scan: Not publicly specified · Cookie Scan Date

Policy Version: Not publicly specified · Cookie Policy Version


Privacy

Read:

Privacy Policy

Contact:

Not publicly specified · Privacy Contact Channel