1. About this policy
This Cookie Policy explains what cookies and similar technologies we use on snowcone.app, developers.snowcone.app, and related properties (the "Service"); why we use them; how to manage them; and how regional rules apply. It supplements our Privacy Policy β read both together.
2. What cookies and similar technologies are
Cookies are small files a website stores on your device. They are used for many purposes β for example, keeping you signed in, remembering your country, and measuring how the site performs.
This policy uses "cookies" as shorthand for cookies and any similar technology that stores or reads information on your device, including localStorage, IndexedDB, web beacons / pixels, SDK identifiers, and server-side identifiers we set in HTTP responses. The European Court of Justice (Planet49, C-673/17) and the regulator guidance from CNIL and the UK ICO treat these technologies the same way for consent-and-information purposes.
We do not use canvas fingerprinting, audio fingerprinting, or other browser-fingerprinting techniques to identify devices. Bot detection on the Service is performed via Cloudflare Turnstile, which uses challenge-response (not fingerprinting) to assess whether a request is automated.
3. The categories we use
We organise cookies into four categories. Each category can be turned on or off independently from the cookie banner or from the persistent footer link "Cookie preferences". Strictly necessary cookies cannot be turned off β without them the Service does not work.
3.1 Strictly necessary
These are cookies and similar technologies that are essential for the Service to function: signing you in, keeping items in your cart, preventing fraud, balancing load across our servers, and remembering your cookie preferences themselves.
| Name (or pattern) | Purpose | Set by | Lifetime |
|---|---|---|---|
__Secure-snowcone.session_token | Authentication session | Snowcone (first-party) | Up to 30 days; rotated on sign-in |
__Host-snowcone.csrf | Cross-site request forgery protection | Snowcone (first-party) | Session |
cart_token | Maintain your cart between page loads | Snowcone (first-party) | 30 days |
guest_id | Anonymous-shopper identity (per ADR-0061) | Snowcone (first-party) | Up to 30 days; cleared on sign-in |
sc_consent | Stores your cookie-consent decision | Snowcone (first-party) | 1 year |
activeOrganizationId | Remembers which of your organisations you are currently acting on (only set if you belong to more than one) | Snowcone (first-party) | 1 year |
sc_ref, sc_ref_fresh | Referral attribution β records which creator or affiliate link sent you to Snowcone, so any commission earned on a purchase is paid to them | Snowcone (first-party) | 30 days |
cf_clearance, __cf_bm | Bot detection and fraud prevention via Cloudflare | Cloudflare (sub-processor) | Session to 30 minutes |
3.2 Functional
These remember your preferences so the site works the way you configured it. They are off by default in opt-in regions (EEA, UK, CH, IS, NO) and on by default elsewhere with notice.
| Name (or pattern) | Purpose | Set by | Lifetime |
|---|---|---|---|
lang | Remember your language preference | Snowcone (first-party) | 1 year |
shipping_country | Remember the country you selected for shipping, currency, and tax | Snowcone (first-party) | 1 year |
theme | Remember light / dark / system theme | Snowcone (first-party, localStorage) | Until cleared |
recently_viewed | Show you the last few designs you looked at | Snowcone (first-party, localStorage) | 30 days |
3.3 Analytics
These help us understand how the Service is used so we can improve it. They are off by default in opt-in regions and on by default elsewhere with notice.
| Name (or pattern) | Purpose | Set by | Lifetime |
|---|---|---|---|
tb_session, tb_anon_id (localStorage) | Aggregate usage events. We do not link this to your identity unless you are signed in. | Tinybird (sub-processor) | 13 months |
dash0_* | Client-side error monitoring and performance tracing | Dash0 / Sentry (sub-processor) | Session |
Cloudflare Web Analytics (server-side beacons) | Aggregated, privacy-preserving page-load metrics | Cloudflare (sub-processor) | n/a |
3.4 Marketing
Marketing cookies and pixels would be used for retargeting and attribution. v1 of the Service does not load any marketing cookies or pixels. If we add them in the future they will require affirmative consent everywhere β in opt-in regions and in opt-out regions alike β and we will publish the change at least 30 days before it takes effect.
4. One global default: opt-in everywhere
Non-essential cookies are off by default for every Snowcone user, in every country we serve. Functional, analytics, and marketing cookies require your affirmative consent before they load. Strictly necessary cookies (section 3.1) load without consent because the Service does not work without them. We do not vary this posture by country.
Why a single global default rather than per-region settings: the regulatory direction of travel β EU EDPB transparency enforcement, the UK ICO's post-DUAA-2025 PECR ceiling (Β£17.5 million / 4% global turnover), the California Attorney General's Disney $2.75M cross-device-opt-out theory, the UK CMA's dark-patterns priority β converges on the EEA opt-in floor as the operating standard. Per-region defaults would be a maintenance and audit liability with no user benefit. ADR-0068 Β§6 records this decision.
The cookie banner is the same in every market: a modal with equal-weight Accept and Reject buttons, with a "Manage preferences" option surfaced before "Accept all" (the EEA / UK shape, generalised). The Global Privacy Control signal (section 5) is honored everywhere as a declined-consent decision and skips the banner entirely.
Sensitive personal information. Where processing involves sensitive personal information (for example, photos of identifiable individuals submitted with reviews), we obtain a separate explicit opt-in at the point of submission, on top of the cookie consent above. This posture applies globally as a uniform standard.
Country detection remains operationally relevant for tax, currency, language, fulfillment, and the selection of country-mandated parallel documents β it is just no longer used for cookie-default differentiation.
5. Global Privacy Control (GPC)
We honor the Global Privacy Control signal. If your browser is configured to send navigator.globalPrivacyControl = true (built into Brave, DuckDuckGo Browser, Firefox, and a number of privacy-focused extensions), we treat it as your decision and:
- In US states with comprehensive privacy laws β we treat the signal as a "do not sell or share" instruction under CCPA / CPRA Cal Civ Code Β§1798.135(b) and equivalent state-law provisions.
- In the EEA and UK β we treat the signal as a declined-consent decision: marketing and analytics are off, the banner is skipped, and a consent-log row is recorded with
surface = 'gpc_inferred'. - Cross-device propagation. Once you sign in, the GPC decision propagates to your account and applies on every other device you sign in with β not only the device that originally sent the signal. This addresses the operative theory in California Attorney General People v. Walt Disney Co. (CCPA settlement, early 2026).
- Propagation to third-party tags. When GPC is signaled, the consent gate that controls third-party tag-injection drops every queued analytics and marketing tag β propagation is not "first-party only".
You can override GPC for our Service by visiting the persistent footer link "Cookie preferences" and choosing categories manually β your manual choice always wins over the automatic signal.
6. "Do Not Sell or Share My Personal Information"
We do not sell personal information for money, and we do not share personal information for cross-context behavioral advertising as those terms are defined under the California CCPA / CPRA and analogous state laws. This is the v1 posture and it does not depend on any opt-out by you.
California, Colorado, Connecticut, Virginia, Utah, Texas, and other state laws still give you a right to opt out preemptively. Use the footer link "Do Not Sell or Share My Personal Information" or set GPC in your browser. The opt-out is recorded on your account and propagates across devices once you sign in.
California residents may also limit our use of sensitive personal information (CPRA Β§1798.121) β for example, to constrain how we use review photos that depict you. Use /privacy-requests for that request.
7. How to manage or withdraw your consent
- From the cookie banner β when it first appears, choose Accept all, Reject all, or Manage preferences.
- From the persistent footer link β "Cookie preferences" reopens the banner from any page. Withdrawing a category causes the corresponding cookies to be deleted on next page load.
- From your browser β most browsers let you delete cookies for a site or block them entirely. Doing this for strictly necessary cookies will prevent the Service from working.
- Via Global Privacy Control β see section 5.
- Via /privacy-requests β for a record of every consent decision tied to your account.
Withdrawing consent does not affect the lawfulness of processing carried out before your withdrawal (GDPR Art 7(3)).
8. What we do not do
- We do not use canvas, audio, or other browser-fingerprinting techniques.
- We do not use session-replay, heatmap, or screen-recording tools (FullStory, Hotjar, LogRocket, or equivalents). If we ever add one we will treat it as a major Cookie Policy change with prior notice and explicit consent.
- We do not run cross-context behavioral advertising; we do not place retargeting pixels on other sites.
- We do not use the IAB Transparency and Consent Framework (TCF) consent string in v1; if we ever join an adtech ecosystem that requires it we will say so.
- We do not load Google Analytics, Meta Pixel, TikTok Pixel, LinkedIn Insight, or similar third-party advertising tags.
9. Sub-processors
The third parties that receive cookie-derived data are listed on our public sub-processor page at /legal/sub-processors. That page is the canonical disclosure; the cookie-table references in section 3 above are summary entries.
10. Children
Snowcone is not directed to children. We do not knowingly set non-essential cookies on devices used by children below the minimum age in your country. Minimum-age detail is in the Privacy Policy, section 14.
11. Changes to this policy
The version number and effective date appear at the top of this page. If we add a new processing purpose, a new category of cookie, or a new sub-processor that meaningfully changes who receives your cookie-derived data, we treat the change as material: we re-prompt your consent on the next page load, post notice at least 30 days before the change takes effect, and email signed-in users.
12. Contact us and how to complain
For cookie-related questions, write to privacy@snowcone.app or visit /privacy-requests.
If you are not satisfied with our response, you can complain to a regulator. The list is in our Privacy Policy section 17. The most relevant authorities for cookie issues:
- EEA β your national data protection authority; France's CNIL has been the most active enforcer of cookie rules in recent years.
- United Kingdom β the Information Commissioner's Office: ico.org.uk. The ICO has been auditing the top 1,000 UK websites for cookie compliance and has the power to issue fines up to Β£17.5 million or 4% of global turnover under PECR (as amended by the Data (Use and Access) Act 2025).
- California β the California Privacy Protection Agency (CPPA) and the California Attorney General.
13. Document version
The current version and effective date appear at the top of this page. Sub-processor changes are tracked separately at /legal/sub-processors.
Last updated . Previous versions available on request.
Read the sub-processor list β
