First draft — v0.1, not yet legally reviewed, not published. Every document on this site must be reviewed by a solicitor before it is relied on. See the status note on the home page.

Cookie Policy

Last updated: [PUBLISH DATE] · Version: 0.1 (first draft — not yet legally reviewed, not yet published)

This is a first draft, not yet legally reviewed or published.

This policy covers cookies and similar technologies (local storage, advertising identifiers, pixels). For what personal data sits behind them, see the Privacy Policy.

1. Today, without ads enabled

Hostable sets two cookies and uses two localStorage items (covered by this policy the same way cookies are — PECR regulation 6 is technology-neutral). We do not currently run analytics or advertising cookies. There is a storage notice on first visit — not a full opt-in/opt-out ad-consent banner (nothing here needs one yet, since nothing below is advertising/analytics), but a genuine choice for the one item that isn't strictly necessary, presented with "Accept" and "Essential only" given equal visual weight.

ItemTypePurposeDurationRequired or optional?
hostable_sessionCookie (httpOnly)Keeps you signed in30 days (or until you sign out)Required — the portal cannot function without it; not offered as a choice
hostable_trusted_deviceCookie (httpOnly)"Remember this browser" — skips the two-factor prompt on a browser you've already verified14 days, rolling (renewed each time it's used); set only after you complete a two-factor check and choose to be rememberedRequired for the feature it supports — only set if you use "remember this browser" during 2FA; not set otherwise, not offered as a general-purpose toggle
hostable-themelocalStorageRemembers your light/dark theme choice between visitsUntil you clear it or opt outOptional — this is the one choice the storage notice actually offers
hostable-storage-consentlocalStorageRemembers which choice you made in the storage notice, so it doesn't reappear every visitUntil you clear itRequired — without it the notice couldn't honor a decision you already made, and would reappear on every page load

We use no analytics, advertising, or tracking storage of any kind today.

This changes the moment Google AdSense (or any ad/survey network) goes live — see §2. Until then, the sections below describe what will be built before that switch is flipped, not what's live now.

2. When advertising is enabled (Google AdSense)

Google AdSense sets advertising and measurement cookies/identifiers that are not strictly necessary, so they require a consent mechanism before they load — and the mechanism differs by where you are, because UK/EU and US law take opposite defaults.

UK / EU — opt-in consent (PECR / ePrivacy)

United States — opt-out (CCPA/CPRA and similar state laws)

US law does not require opt-in consent for advertising cookies by default; instead it requires a clear way to opt out of "sale or sharing" of personal information, which under CCPA's broad definition can include advertising-identifier sharing with an ad network even without a cash transaction.

Categories of personal information "sold or shared" (CCPA sense)

If AdSense is enabled, advertising identifiers and browsing behavior on Hostable may be considered "shared" with Google in the CCPA-defined sense, even though no data is sold for money. [Full CCPA category table to be completed once AdSense is actually configured and its data flows are known — placeholder.]

3. Under-18 users and advertising

Because Hostable allows 16–17 year old accounts (see Privacy Policy §3), any ad network we enable must support non-personalized ad delivery as an option we can apply to those accounts, and we will not enable behavioral/personalized ads for any account that declares an age under 18 by default. [Product requirement — not yet implemented, tracked in TODO.md.]

4. Cookies from other providers

ProviderPurposeCategory
CloudflareEdge/TLS termination, DDoS protectionStrictly necessary (no separate cookie set today; Cloudflare Web Analytics, if enabled, is cookieless by design)
StripeFraud prevention during checkoutStrictly necessary for the transaction you initiate

5. How to control cookies and storage

For the one optional item today (your theme preference), you can change your choice at any time using the storage notice, or by clearing hostable-theme directly in your browser's storage settings — clearing it just means we forget your theme, nothing else breaks.

Beyond that, you can block or delete cookies and site storage in your browser settings at any time. Blocking hostable_session will sign you out and prevent signing back in, since the portal cannot function without it. Blocking hostable_trusted_device only means you're asked for a two-factor code again on that browser — everything else keeps working.

6. Contact

privacy@hostable.games

↑ Back to top