Cookie Policy
Last updated: August 25, 2026
This Cookie Policy explains how Neapolitan Group Inc., doing business as Match Kicks, uses cookies and similar technologies on matchkicks.com and our subdomains. It should be read together with our Privacy Policy, which explains what we do with the information these technologies collect and what rights you have.
1. What these technologies are
A cookie is a small text file a website asks your browser to store. We also use technologies that behave like cookies:
- Local storage and session storage — larger stores of data kept in your browser. Unlike cookies, they are not sent to our servers with every request; our code reads them when you are on the site.
- Pixels, tags and web beacons — tiny transparent images or snippets of code that tell us or an advertising partner that a page was viewed or an email was opened.
- Software development kits (SDKs) and tag managers — code libraries that load and configure the above.
- Server-side event forwarding — our servers send event information directly to advertising platforms without going through your browser. This is described in Section 6, because a cookie banner alone does not cover it.
Cookies are first-party when they are set by matchkicks.com, and third-party when they are set by another domain. They are session cookies if they disappear when you close your browser, and persistent if they last for a set period.
2. Your choices
- Strictly necessary cookies are always on. Without them the site cannot keep you logged in, keep items in your cart, or protect itself from fraud and bot attacks. They do not require consent, but we list them below anyway.
- All other cookies — functional, analytics and advertising — are non-essential. You can refuse or remove them at any time using the controls below, and you can ask us to stop sharing your information with advertising platforms altogether by contacting us.
- Browser controls. Every major browser lets you block or delete cookies, and most offer a setting to block third-party cookies specifically. Blocking all cookies will break parts of the site — the cart and checkout in particular. Instructions: Chrome, Safari, Firefox, Edge.
- Ask us directly. Email support@matchkicks.com with the subject "Privacy Request" and we will apply your opt-out to your customer record, so it covers every browser and device rather than just one.
- Advertising opt-outs. You can also opt out of interest-based advertising at optout.aboutads.info (US), optout.networkadvertising.org (US), or youronlinechoices.eu (Europe), and directly in your Meta, Google and Microsoft ad settings.
- To stop marketing entirely, email support@matchkicks.com, use the unsubscribe link in any email, or reply STOP to any text message.
3. Strictly necessary
These run the site. They cannot be switched off through a consent banner.
| Name | Set by | Purpose | Type & duration |
|---|---|---|---|
sb-*-auth-token | Match Kicks (Supabase) | Keeps you signed in to your account and refreshes your session securely. | First-party · session to 1 year |
auth_token | Match Kicks | Authenticates you to our own API for account and order pages. | Local storage · until sign-out |
cartId, checkout_shipping | Match Kicks | Remembers the contents of your cart and the shipping details you entered, so you do not lose them between pages. | Local storage · until cleared |
mk_express | Match Kicks | Remembers which express payment method (Apple Pay, Google Pay, PayPal) you used, so we can offer the same one again at checkout and on any post-purchase offer. | First-party · up to 1 year |
__cf_bm, cf_clearance | Cloudflare | Bot management and challenge clearance — distinguishes real visitors from automated traffic and protects the site from abuse. | Third-party · 30 minutes to 1 year |
__stripe_mid, __stripe_sid | Stripe | Fraud prevention and payment processing. Required to take payment. | Third-party · session to 1 year |
| PayPal session cookies | PayPal | Enables PayPal checkout and protects against payment fraud. | Third-party · session to 3 years |
4. Functional
These remember your preferences and make the site more useful. Turning them off will not break checkout, but the site will forget things about you.
| Name | Set by | Purpose | Type & duration |
|---|---|---|---|
mk_subscribed | Match Kicks | Notes that you have already signed up, so we stop showing you sign-up offers. | First-party · up to 1 year |
mk_welcome_code, mk_welcome_code_expires_at | Match Kicks | Holds a welcome discount code issued to you and its expiry, so it can be applied automatically at checkout. | First-party · up to 30 days |
mk_popup_* (dismissed_at, pageviews, pscroll, teaser, variant) | Match Kicks | Frequency-caps our on-site offers so you are not shown the same pop-up repeatedly. | First-party · up to 90 days |
mk_cw | Match Kicks | Keeps your live-chat conversation open across pages so you do not lose the thread. | First-party · up to 30 days |
mk_search_focus, mk_recent_searches, mk_search_sid | Match Kicks | Remembers your recent searches and links a search to the result you clicked, so we can improve relevance. | Local storage / first-party · up to 90 days |
latestSize, matchKicksShipping, matchKicksShippingAddress, userContactInfo, matchKicksEmail | Match Kicks | Pre-fills your size and delivery details so you do not have to retype them. | Local storage · until cleared |
customerUploads | Match Kicks | Links your browser to sneaker photos you have uploaded, so you can see your match results again. | Local storage · until cleared |
mk_upsell_offers_v1, mk_upsell_shown_*, mk_upsell_dismissed_*, neverShowSocksUpsell, offerBoxDismissed | Match Kicks | Remembers which post-purchase offers you have already seen or dismissed. | Local storage · up to 90 days |
mk_store_rating, mk_tp_summary_v*, mk_recent_orders_v* | Match Kicks | Caches our store rating and recent-order banner so pages load faster. | Local storage · up to 24 hours |
| Currency preference | Match Kicks & IP-geolocation provider | Shows prices in your local currency, based on the country inferred from your IP address. | First-party · up to 1 year |
| Trustpilot widget cookies | Trustpilot | Displays our review widgets and verifies review submissions. | Third-party · session to 1 year |
| Bunny Stream player cookies | Bunny.net | Plays customer unboxing videos and remembers playback preferences. | Third-party · session to 1 year |
5. Analytics and advertising
These tell us how the site is used and let us advertise to you and measure whether our ads worked. Disclosing information through the advertising technologies below is treated as "sharing" for cross-context behavioral advertising — and in some states as a "sale" — under US state privacy laws. See our Privacy Policy for how to opt out.
Analytics and testing
| Name | Set by | Purpose | Type & duration |
|---|---|---|---|
_ga, _ga_<id>, _gid | Google Analytics (via Google Tag Manager) | Counts visits, distinguishes returning visitors, and reports which pages and products perform. | First-party · _gid 24 hours, _ga up to 2 years |
mk_anon_id | Match Kicks | A random pseudonymous visitor ID. Links your activity across visits for analytics and advertising measurement. It is not your name or email. | First-party · 2 years |
mk_ab_visitor_id, mk_ab_session_id, mk_ab_variant | Match Kicks | Keeps you in the same version of an A/B test so your experience is consistent and the result is valid. | First-party · up to 1 year |
| Sentry error diagnostics | Sentry | Captures technical details when something breaks so we can fix it. | Third-party · session |
Advertising and attribution
| Name | Set by | Purpose | Type & duration |
|---|---|---|---|
_fbp, _fbc | Meta (and written by our own code) | Identifies your browser to Meta and records which Facebook or Instagram ad click brought you here, so we can measure conversions and show you relevant ads. | First-party · 90 days |
_gcl_au, _gcl_aw | Google Ads | Attributes conversions to Google ad clicks. | First-party · 90 days |
_uetsid, _uetvid, MUID | Microsoft Advertising | Measures conversions from Bing and Microsoft Audience Network ads and builds remarketing audiences. | First-party / third-party · _uetsid 24 hours, _uetvid up to 13 months, MUID up to 13 months |
mk_gcl | Match Kicks | Stores the Google click ID (gclid/gbraid/wbraid) from your ad click so we can report the sale back to Google Ads. | First-party · 90 days |
mk_msclkid, mk_msclkid_t | Match Kicks | Stores the Microsoft click ID and its timestamp so we can report the sale back to Microsoft Advertising. | First-party · 90 days |
mk_attr | Match Kicks | Records the first campaign, referrer and landing page that brought you to the site, so we know which channel earned the sale. | First-party · 90 days |
mk_ad, plus mk_asid / mk_adid tags in ad links | Match Kicks | Records which specific ad creative and ad set you clicked, for campaign-level reporting. | First-party · 90 days |
__usr_id, __sub_id | Match Kicks | Encrypted references to your customer and marketing-subscriber records. They let us recognise you when you arrive from one of our emails and attach your activity to the right record. | First-party · long-lived; cleared when you opt out or ask us to delete your data |
__kla_id | Legacy email platform | A subscriber identifier left over from our previous email platform. We read it only to match older email links to the right subscriber and no longer set new ones. | First-party · legacy |
mk_guest_identity_v1, user_data | Match Kicks | Caches contact details you have already given us (for example, after entering your email to get your match results) so our advertising events can be matched more accurately without asking you again. | Local storage · until cleared |
| Google Tag Manager container | Loads and configures the tags above. It does not itself store personal information. | Third-party · n/a |
6. Server-side tracking — the part a cookie banner does not cover
In addition to the browser technologies above, our servers send event information directly to advertising platforms. This is sometimes called "server-side tagging", the "Conversions API" or "offline conversion import". We use it for:
- Meta Conversions API — page views, product views, add-to-cart, checkout starts and purchases.
- Google Ads API conversion upload — purchases matched to a Google ad click.
- Microsoft UET Conversions API — purchases and add-to-cart events matched to a Microsoft ad click.
- Product catalogue feeds to Google Merchant Center and Meta so our products can appear in shopping ads. These contain product data, not customer data.
What we send with these events: your IP address and browser user agent, the page URL, the products and order value involved, the advertising click ID from the cookies above, our pseudonymous visitor ID, and — where we hold them — your email address and phone number in irreversibly hashed form (SHA-256). We never send your plain-text email address, phone number or payment details to advertising platforms.
Because this happens on our servers rather than in your browser, blocking cookies or using an ad blocker will not stop it. Asking us to opt you out will. Email support@matchkicks.com and we will stop attaching your identifiers to these events.
7. Cookies in our emails
Our marketing emails contain small tracking pixels and tagged links that tell us whether the email was opened and which links were clicked, so we can send fewer and better emails. To avoid this, turn off image loading in your email client, or unsubscribe using the link in any email.
8. Third parties we allow to set cookies
The companies below may set or read cookies on our site. Each is independently responsible for its own use of that data — please read their notices:
Google · Meta Platforms · Microsoft · Stripe · PayPal · Cloudflare · Bunny.net · Trustpilot · Sentry · Vercel · Supabase
9. How long your choices last
Where you tell us to opt out, we record it against your customer record and keep it in force until you tell us otherwise — we do not quietly re-enrol you. Where we rely on your consent, we will ask again if we add a tracking technology or a purpose your earlier choice did not cover.
10. Do Not Track
We do not respond to the "Do Not Track" browser header, because the industry has never agreed a common standard for it. To opt out, please use the controls in Section 2 or contact us — an opt-out you send us is applied to your customer record and stays in force.
11. Changes to this policy
We review this policy regularly and update it whenever we add, remove or change a cookie or tracking technology. The "Last updated" date at the top tells you when it last changed.
12. Contact
Questions about cookies, or want to exercise a privacy right?
- Email: support@matchkicks.com
- Text or call: (844) 234-5684
- Post: Neapolitan Group Inc. (d/b/a Match Kicks), Attn: Privacy, 1712 Pioneer Ave, Ste 500, Cheyenne, WY 82001, United States