Cookie Policy

Last updated: 8 April 2025

What are cookies?

Cookies are small text files that a website stores on your device when you visit it. They allow the website to remember your actions and preferences over time or for the duration of a session. This policy explains what cookies FanLuma uses, why we use them, and how you can control them.

Cookies we set

FanLuma currently sets only strictly necessary cookies. We do not use third-party advertising cookies or tracking pixels for marketing. If we introduce analytics or marketing cookies in the future, we will update this policy and seek your consent as required by PECR.

av_confirmedStrictly necessary

Provider

FanLuma

Duration

1 year

Purpose

Records that you have passed the age verification gate (18+). An HMAC-signed cookie — if tampered with, the gate is shown again. Required by the Online Safety Act 2023.

Can you opt out?

No — this cookie is required for the platform to function correctly. Disabling it will prevent you from signing in or using the service.

sb-*-auth-tokenStrictly necessary

Provider

Supabase (supabase.co)

Duration

Session / up to 1 hour (automatically refreshed)

Purpose

Stores your encrypted authentication session so you remain logged in across pages. Set when you sign in. Required for the platform to function.

Can you opt out?

No — this cookie is required for the platform to function correctly. Disabling it will prevent you from signing in or using the service.

sb-*-auth-token-code-verifierStrictly necessary

Provider

Supabase

Duration

Short-lived (minutes)

Purpose

A PKCE code verifier used during the OAuth sign-in flow. Deleted once sign-in completes.

Can you opt out?

No — this cookie is required for the platform to function correctly. Disabling it will prevent you from signing in or using the service.

__stripe_midStrictly necessary

Provider

Stripe, Inc.

Duration

1 year

Purpose

Fraud detection and security. Required by Stripe to protect payment transactions. Set when you reach a checkout or payment page.

Can you opt out?

No — this cookie is required for the platform to function correctly. Disabling it will prevent you from signing in or using the service.

__stripe_sidStrictly necessary

Provider

Stripe, Inc.

Duration

30 minutes

Purpose

Session identifier used by Stripe to associate your session with a payment attempt. Required for payment processing.

Can you opt out?

No — this cookie is required for the platform to function correctly. Disabling it will prevent you from signing in or using the service.

_vercel_no_cacheStrictly necessary

Provider

Vercel / Replit (hosting)

Duration

Session

Purpose

Infrastructure cookie used by the hosting provider to manage CDN caching. Not used to track you.

Can you opt out?

No — this cookie is required for the platform to function correctly. Disabling it will prevent you from signing in or using the service.

Local storage

In addition to cookies, FanLuma may use browser localStorage for UI preferences such as theme (light/dark mode). This data never leaves your device and is not used for tracking.

How to manage cookies

You can control and/or delete cookies through your browser settings. Disabling strictly necessary cookies will prevent you from signing in and using FanLuma. Here is how to manage cookies in common browsers:

  • Google Chrome: Settings → Privacy and Security → Cookies and other site data
  • Mozilla Firefox: Settings → Privacy & Security → Cookies and Site Data
  • Apple Safari: Preferences → Privacy → Manage Website Data
  • Microsoft Edge: Settings → Cookies and site permissions → Cookies and site data

For more information about cookies generally, visit aboutcookies.org or the ICO's guide to cookies.

Legal basis

Strictly necessary cookies are set on the basis of our legitimate interest in providing a functioning, secure service (UK GDPR Art. 6(1)(f)) and, for authentication and age verification cookies, our legal obligation under the Online Safety Act 2023 (UK GDPR Art. 6(1)(c)). No consent is required for strictly necessary cookies under PECR regulation 6(4). Should we introduce non-essential cookies, we will obtain your prior consent.

Changes to this policy

We will update this policy when we introduce new cookies or change how we use existing ones. Please check this page periodically. If you have questions, email privacy@fanluma.com.