We follow the ePrivacy Directive (cookie law) and GDPR. Cookies that are strictly necessary to operate the site (login, cart, checkout) do not require consent. Everything else — analytics, ads — only runs after you click “Accept all” in our banner.
Strictly necessary
- sb-access-token / sb-refresh-token (Supabase) — keep you signed in. Session lifetime.
- modestly.cookie-consent (localStorage) — remembers your choice on this banner. 12 months.
- __stripe_* (Stripe) — fraud prevention during checkout. Set only when you reach the Stripe-hosted checkout page.
Functional (only after “Accept all”)
- Vercel Analytics — anonymised page views, no cross-site tracking. 14 months.
- Sentry — error session identifiers. Up to 30 days.
How to change your choice
Clear your site data in your browser settings to be shown the banner again. We will also add an account-level toggle: Account > Data & privacy.
More information
See our Privacy Policy for the legal bases and full processor list.
