Cookie Policy
This policy describes in detail how Value2Exit uses HTTP cookies, browser storage, and similar technologies. It should be read together with our Privacy Policy.
Last updated:
Scope and who this applies to
This Cookie Policy applies to visitors and users of websites and web applications operated under the Value2Exit brand (the “Service”), when accessed from a browser or webview that supports cookies and storage APIs. Mobile apps may use different identifiers — those are covered in the relevant app privacy notice where applicable.
Cookies and similar technologies
HTTP cookies are small text files placed on your computer or device when you visit a site. They are widely used to make sites work more efficiently, keep you signed in, remember preferences, and (where permitted) measure audience engagement.
We also use similar technologies that perform a comparable role, including:
- Local storage and session storage (HTML5 Web Storage API) — key/value stores in the browser, often used for UI state or caching non-sensitive data;
- IndexedDB — structured client-side database storage (we use it sparingly, if at all);
- Pixels / tags — small images or scripts that report when a page loads (for example if marketing tools are enabled with consent).
Throughout this policy, we refer to these together as “cookies” unless we need to distinguish a specific technology.
First-party vs third-party cookies
First-party cookies are set by us (or on our behalf in our domain) when you use the Service. They typically power core features such as security, session continuity, and preferences.
Third-party cookies are set by another domain — for example a payment provider, authentication host, or analytics vendor. Those providers determine their own retention and purposes, subject to their privacy notices and your choices where applicable.
Whether a cookie is “first” or “third” party depends on which site you are browsing: a cookie set while you are on value2exit.com may still be classified as third-party if the domain in the Set-Cookie header belongs to another company (for example stripe.com).
Session vs persistent cookies
Session cookies expire when you close your browser (or when the browsing session ends). They are often used for transient security state or routing.
Persistent cookies remain for a defined period after you leave the site, until they expire, or until you delete them. They are often used to keep you signed in across visits or to remember preferences.
Exact lifetimes vary by cookie: see the inventory below. Where we control renewal (for example sliding session extensions), the clock may reset when you use the Service again.
Categories we use
We group cookies into the following categories:
- Strictly necessary — required to deliver the Service you have asked for (for example security, authentication, network management, load balancing, and fraud prevention in connection with payments). In the UK and EEA, these typically do not require consent when they are strictly necessary.
- Functional (preferences) — remember choices such as language, region, accessibility, or UI settings. If disabled, parts of the experience may reset on each visit.
- Analytics / performance — help us measure traffic, funnels, errors, and performance in aggregate or pseudonymous form. Where required, we ask for consent before loading non-essential analytics.
- Marketing / advertising — used to measure campaign effectiveness or build audiences only if we deploy such tools and obtain consent where the law requires.
Cookie and storage inventory
The table below lists typical cookies and storage keys you may see when using the Service. Exact names can depend on your Supabase project reference, hosting configuration, and feature flags. If a name differs on your device, compare the purpose and provider columns.
| Name / pattern | Type | Category | Purpose | Typical duration |
|---|---|---|---|---|
sb-<project-ref>-auth-token (pattern) | Cookie | Strictly necessary | Supabase session / JWT fragments for authenticated access when using server-side rendering patterns. | Session or short-lived (often hours–days, refreshed on use) |
sb-<project-ref>-auth-token.0, .1 … | Cookie | Strictly necessary | Chunked auth cookie parts when tokens exceed browser cookie size limits. | Same as auth token above |
Other sb-* host cookies | Cookie | Strictly necessary | Supabase may set additional cookies for PKCE/OAuth state or cookie-based session bridging, depending on configuration. | Session or short-lived |
__stripe_mid, __stripe_sid (on Stripe domains) | Cookie (third-party) | Strictly necessary / fraud | Stripe uses cookies on Stripe-hosted pages (for example Checkout or Customer Portal) for fraud prevention, session continuity, and compliance. You interact with Stripe when paying. | Often 1 year / session variants (see Stripe’s policy) |
| Hosting / CDN edge cookies | Cookie | Strictly necessary | Our hosting provider may set cookies for routing, bot protection, or TLS/session stickiness (names vary by provider). | Session to short |
| Region / locale preference (if set) | Cookie or local storage | Functional | Remember UK / EU / US region choice or language where we store it client-side. | Often 6–12 months unless cleared |
_ga, _ga_* (if GA4 enabled) | Cookie | Analytics | Google Analytics 4 — distinguishes users and sessions when we enable it and obtain consent where required. | Up to 2 years (Google default; configurable) |
_gid (legacy GA) | Cookie | Analytics | Session grouping if Universal Analytics remnants exist. | 24 hours typical |
If we add or remove a vendor, we will update this table and the “Last updated” date at the top of this policy.
Authentication and payments
Supabase. Authentication uses HTTP-only and/or secure cookies (depending on environment) so your session can be validated on our servers. These cookies are integral to sign-in, password recovery, and OAuth flows. Supabase’s documentation and privacy materials describe how they process data.
Stripe. When you start Checkout or manage billing, you may be directed to stripe.com or subdomains. Stripe sets its own cookies subject to Stripe’s policies. We do not control those cookies, but we choose Stripe as a processor for payments.
Analytics and marketing
Analytics. We may use first-party or third-party analytics to understand aggregate usage (page views, conversion funnels, JavaScript errors). Where analytics cookies are not strictly necessary, we will request your consent in the UK/EEA before loading them, and we will honour your choices via our cookie banner or preference centre when available.
Marketing. If we use advertising pixels (for example Meta, Google Ads, LinkedIn), those vendors may set third-party cookies or read identifiers. We only enable such tools where permitted and after appropriate consent where the law requires.
Web storage and pixels
We may store small pieces of non-sensitive data in localStorage or sessionStorage — for example UI state, draft form fields, or feature flags. Unlike cookies, storage items are not sent automatically on every HTTP request; they are read by our JavaScript in your browser.
We do not use storage to replace secure server-side session management for authentication secrets; sensitive tokens should remain in HTTP-only cookies where our stack supports it.
Pixels (1×1 images or inline scripts) may be used by analytics or advertising partners when enabled. They can report page loads, approximate location at IP level, and device characteristics as described in the partner’s policy.
Consent (UK / EEA)
Under UK and EU ePrivacy rules, we must obtain prior consent before storing or accessing non-essential cookies or similar technologies on your device, unless an exemption applies (for example strictly necessary cookies).
When you first visit, you may see a cookie banner or preference centre allowing you to accept, reject non-essential categories, or customise choices. Your preferences are stored (typically in a cookie or in local storage) so we do not have to ask on every visit — you can change your mind at any time via the same UI or browser controls.
How to control and opt out
Browser settings. All major browsers let you delete cookies, block third-party cookies, or block all cookies. Blocking all cookies may break sign-in and payments.
Industry opt-outs. For interest-based advertising in some regions, you can use tools such as the Your Online Choices (EU) or DAA WebChoices (US) — availability depends on your location and participating vendors.
Google Analytics. If GA is enabled, Google provides a browser add-on to opt out of GA in supported browsers.
For personal data rights (access, erasure, etc.), see our Privacy Policy.
Do Not Track and global privacy controls
Some browsers send a “Do Not Track” (DNT) signal. There is no consistent industry interpretation of DNT. We currently do not respond to DNT signals as a standalone compliance mechanism; we rely on applicable law, our cookie banner (where shown), and your explicit choices in product settings.
Modern platforms increasingly offer global privacy controls (for example mobile OS advertising IDs). Those sit outside browser cookies — refer to your device documentation.
Changes
We may update this Cookie Policy when we change technologies, vendors, or legal requirements. The “Last updated” date at the top of this page will change, and we may provide additional notice for material changes where required.
Contact
Questions about this Cookie Policy: use our Contact page or loadcircle.app/contact.