Cookie Policy
Exactly which cookies and similar technologies we use, for what, for how long, and how you can change your mind at any time.
What are cookies?
Cookies are small text files placed on your device by websites you visit. They help the site remember things like your session, your preferences, and whether you've consented to analytics. Similar technologies (localStorage, sessionStorage, IndexedDB) are covered by the same rules as cookies.
Legal basis
Under the EU ePrivacy Directive (2002/58/EC as amended) and GDPR, we may only store non-essential cookies on your device with your prior, freely-given, specific, informed, and unambiguous consent. "Strictly necessary" cookies — those without which the site cannot function — are exempt from the consent requirement.
Our cookie banner asks for your consent on first visit and you can change your choice at any time via the "Cookie preferences" button in the footer.
The three categories we use
| CATEGORY | PURPOSE | CONSENT |
|---|---|---|
| Strictly necessary | Session authentication, CSRF protection, cookie-consent preference storage | Not required — essential |
| Analytics | Aggregated, anonymised traffic and usage statistics to improve the product | Your opt-in |
| Marketing | Not currently used. Reserved for future advertising / retargeting pixels. | Your opt-in |
Full cookie inventory
Strictly necessary
| NAME | PURPOSE | DURATION | DOMAIN |
|---|---|---|---|
cs_session | Authentication session token | 24 hours / until logout | first-party |
cs_csrf | CSRF protection token | Session | first-party |
cs_cookie_consent_v1 (localStorage) | Remembers your cookie preferences so we don't re-ask | 365 days | first-party |
cs_theme (localStorage) | Remembers your panel theme choice (dark/light/matrix/purple/orange) | Persistent | first-party |
Analytics (only if you opt in)
| NAME | PURPOSE | DURATION | PROVIDER |
|---|---|---|---|
| (none at present) | We do not currently load any analytics provider. If we add one (e.g. Plausible, Simple Analytics, or GoatCounter), we will update this table and re-request consent. | — | — |
Marketing (only if you opt in)
None at present. We do not use Google Ads, Meta Pixel, LinkedIn Insight Tag, or any similar advertising cookies. Should we add them in the future, this section and the consent banner will be updated before any such cookie is placed.
Third-party services that may set cookies
- Stripe (
js.stripe.com) — loaded only on the checkout page, for fraud prevention and 3-D Secure authentication. Strictly necessary for a transaction to complete. - Google Fonts (
fonts.googleapis.com) — does not set cookies per se, but receives referrer URL and IP when serving the fonts. We load fonts withdisplay=swapand over HTTPS with no cookies exchanged. - YouTube (if embedded) — not embedded on the main site. Any legal-page video embeds would use
youtube-nocookie.com(privacy-enhanced mode).
How to manage your preferences
- On this site — click Cookie preferences in the footer of any page.
- In your browser — Chrome, Firefox, Edge, Safari all let you view and delete cookies via their privacy settings.
- Browser-level opt-out — most modern browsers support Do-Not-Track and Global Privacy Control (GPC) headers, which we honour.
Blocking strictly-necessary cookies will prevent the panel from functioning (you will not be able to log in). Blocking analytics has no effect on functionality.
Contact
Cookie & tracking questions
- PRIVACY
- dpo@carbonstealth.eu
- ENTITY
- Carbon Stealth VCC · EIK BG208725180