What is the cto_bundle cookie?
cto_bundle is an HTTP cookie set by Criteo, a European-based ad retargeting platform widely used by online retailers and publishers to show personalized ads to visitors who have already browsed their site or partner sites.
The cookie typically appears when a Criteo script is loaded on a page — either directly by the site or through a tag manager — most commonly on e-commerce sites, product or cart pages, and on media sites displaying ads from the Criteo network.
What data it stores
cto_bundle generally stores a unique identifier associated with the visitor's browser, along with technical data related to ad display preferences (for example, which combination of ads or campaigns has already been served). The exact value format is not publicly documented by Criteo and may vary.
The data is sent to Criteo's servers; Criteo is headquartered in France with global operations, and as part of its retargeting activity, this data may be processed outside the European Economic Area depending on the infrastructure used.
What it is used for
The main purpose is ad retargeting: Criteo uses this cookie to recognize the visitor across other sites in its network and show ads relevant to products or services previously viewed.
For the website owner, the cookie supports remarketing campaigns run through Criteo, helping recover visitors who left the site without completing an action (such as a purchase), and enabling measurement of campaign performance.
Does it require consent?
cto_bundle falls under the marketing / advertising and tracking category. Under GDPR and the ePrivacy Directive (transposed in Romania via Law 506/2004), this type of cookie cannot be placed before the visitor's explicit consent is obtained.
- The site owner must declare the cookie in the cookie policy, under the correct category (marketing).
- The Criteo script must load only after the visitor consents to the marketing category.
- Refusing consent must not affect the site's core functionality.
How to block or delete cto_bundle
A visitor can delete or block cto_bundle through browser cookie settings, dedicated tracker-blocking extensions, or Criteo's own opt-out mechanisms (such as Criteo's ad preferences page or European opt-out platforms like Your Online Choices).
At the site level, the safest approach is for the owner to use a consent management platform (CMP) such as CookieFix, which automatically blocks the Criteo script until the visitor explicitly accepts the marketing category, preventing the cookie from being set prematurely.
Frequently asked questions
It's a marketing cookie set by Criteo, used for ad retargeting and to display personalized ads based on the visitor's browsing behavior.
Its typical duration is about 13 months, after which it expires automatically and may be reset on a new visit if the Criteo script runs again.
It's not dangerous in a technical sense, but it is a tracking cookie that collects data about online behavior, which is why the law requires the visitor's explicit consent.
Yes. As a marketing cookie, it should only be set after the visitor explicitly accepts the marketing/advertising category in the cookie banner.