Cookie Policy
This policy covers cookies and similar technologies (local storage, advertising identifiers, pixels). For what personal data sits behind them, see the Privacy Policy.
1. Today, without ads enabled
Hostable sets two cookies and uses two localStorage items (covered by this policy the same way cookies are — PECR regulation 6 is technology-neutral). We do not currently run analytics or advertising cookies. There is a storage notice on first visit — not a full opt-in/opt-out ad-consent banner (nothing here needs one yet, since nothing below is advertising/analytics), but a genuine choice for the one item that isn't strictly necessary, presented with "Accept" and "Essential only" given equal visual weight.
| Item | Type | Purpose | Duration | Required or optional? |
|---|---|---|---|---|
hostable_session | Cookie (httpOnly) | Keeps you signed in | 30 days (or until you sign out) | Required — the portal cannot function without it; not offered as a choice |
hostable_trusted_device | Cookie (httpOnly) | "Remember this browser" — skips the two-factor prompt on a browser you've already verified | 14 days, rolling (renewed each time it's used); set only after you complete a two-factor check and choose to be remembered | Required for the feature it supports — only set if you use "remember this browser" during 2FA; not set otherwise, not offered as a general-purpose toggle |
hostable-theme | localStorage | Remembers your light/dark theme choice between visits | Until you clear it or opt out | Optional — this is the one choice the storage notice actually offers |
hostable-storage-consent | localStorage | Remembers which choice you made in the storage notice, so it doesn't reappear every visit | Until you clear it | Required — without it the notice couldn't honor a decision you already made, and would reappear on every page load |
We use no analytics, advertising, or tracking storage of any kind today.
This changes the moment Google AdSense (or any ad/survey network) goes live — see §2. Until then, the sections below describe what will be built before that switch is flipped, not what's live now.
2. When advertising is enabled (Google AdSense)
Google AdSense sets advertising and measurement cookies/identifiers that are not strictly necessary, so they require a consent mechanism before they load — and the mechanism differs by where you are, because UK/EU and US law take opposite defaults.
UK / EU — opt-in consent (PECR / ePrivacy)
- A cookie banner will appear on first visit, with Reject given equal visual prominence to Accept — not a dark pattern, not pre-ticked boxes.
- No advertising cookie loads until you accept.
- We will implement Google's Consent Mode v2, which is Google's own requirement for any site running AdSense to an EEA/UK audience from March 2024 onward — without it, AdSense itself can restrict ad serving to that traffic.
- You can withdraw consent at any time from
[cookie settings link — to be added to the footer].
United States — opt-out (CCPA/CPRA and similar state laws)
US law does not require opt-in consent for advertising cookies by default; instead it requires a clear way to opt out of "sale or sharing" of personal information, which under CCPA's broad definition can include advertising-identifier sharing with an ad network even without a cash transaction.
- A "Do Not Sell or Share My Personal Information" link will be added to the site footer for US visitors.
- We will detect and honor the Global Privacy Control (GPC) browser signal automatically — if your browser sends it, we treat that as a valid opt-out request without you needing to click anything.
- This is a separate mechanism from the EU banner in §2.1 above — we will not try to force one consent flow to serve both an opt-in and an opt-out regime, because they're legally opposite defaults.
Categories of personal information "sold or shared" (CCPA sense)
If AdSense is enabled, advertising identifiers and browsing behavior on Hostable may be considered "shared" with Google in the CCPA-defined sense, even though no data is sold for money. [Full CCPA category table to be completed once AdSense is actually configured and its data flows are known — placeholder.]
3. Under-18 users and advertising
Because Hostable allows 16–17 year old accounts (see Privacy Policy §3), any ad network we enable must support non-personalized ad delivery as an option we can apply to those accounts, and we will not enable behavioral/personalized ads for any account that declares an age under 18 by default. [Product requirement — not yet implemented, tracked in TODO.md.]
4. Cookies from other providers
| Provider | Purpose | Category |
|---|---|---|
| Cloudflare | Edge/TLS termination, DDoS protection | Strictly necessary (no separate cookie set today; Cloudflare Web Analytics, if enabled, is cookieless by design) |
| Stripe | Fraud prevention during checkout | Strictly necessary for the transaction you initiate |
5. How to control cookies and storage
For the one optional item today (your theme preference), you can change your choice at any time using the storage notice, or by clearing hostable-theme directly in your browser's storage settings — clearing it just means we forget your theme, nothing else breaks.
Beyond that, you can block or delete cookies and site storage in your browser settings at any time. Blocking hostable_session will sign you out and prevent signing back in, since the portal cannot function without it. Blocking hostable_trusted_device only means you're asked for a two-factor code again on that browser — everything else keeps working.
6. Contact
privacy@hostable.games