Cookie Policy
Last updated: 23 August 2026
Review status: Customer-facing source update. Deployment-bound cookie/storage evidence, owner approval of the
enabled-processor transfer register and recorded owner-risk acceptance remain separate release evidence. This
policy claims no professional, DPO or regulatory approval.
1. What This Policy Covers
This policy explains the cookies and browser storage used by the current Art Licence Studio consent
control. It distinguishes essential storage from optional functional, analytics and marketing choices.
Cookie choice is separate from acceptance of the Terms of Service and Privacy Policy.
2. Essential Storage
Essential storage is used to authenticate users, protect the service and remember a cookie choice. It is
not switched off by the optional-cookie control because the service cannot reliably provide the related
function without it.
The current consent-control inventory is:
• als_consent_id — a first-party cookie containing a random consent-record identifier. It is created when
you submit a cookie choice, not merely because the banner is displayed. It uses Secure, SameSite=Lax and
a maximum age of approximately 180 days. It links the browser choice to the bounded server-side consent
record; it is not an advertising identifier.
• als_cookie_choice_submitted — local browser storage recording that a first-layer choice was submitted. It is not
server-readable analytics permission and is not Terms acceptance.
• als_cookie_consent — a legacy same-name local browser storage marker and deprecated first-party cookie.
Current source migrates or removes the legacy local marker and expires the deprecated cookie during every
analytics enable or disable choice. It is never enough by itself for statistics or marketing consent.
• als_cookie_prefs — local browser storage containing the selected functional, statistics and marketing
booleans together with the always-true necessary category.
• als_cookie_policy_version — local browser storage containing the Cookie Policy version that applied
when the choice was saved. A new policy version can cause the first-layer choice to be requested again.
• authentication and security cookies — first-party session, refresh, anti-abuse or request-security
storage used by the configured authentication and security services. Supabase authentication can generate
runtime cookie names and exact deployed names can vary by environment.
• als_safety_reporter — a strictly necessary first-party HttpOnly, Secure, SameSite=Lax cookie containing
a random 32-byte opaque browser token for the affected-person safety-report route. It lasts for up to 90
days and is used only to create an HMAC for deduplication and rate limiting. The report database stores
only the HMAC hash, not the raw token, IP address, name or email address.
Local browser storage remains until it is replaced or cleared through the browser. The consent identifier
and safety-reporter cookie expire according to their stated maximum ages. The final production
cookie/storage scan and retention schedule remain separate release evidence and are not approved merely
because this public source copy is updated.
3. Optional Categories
The consent control offers these optional categories:
• Functional — non-essential preferences or convenience behavior.
• Statistics — optional analytics used to understand product performance when an analytics integration
is configured.
• Marketing — optional storage or processing for marketing measurement when a marketing integration is
configured.
When Statistics is enabled, als_analytics_consent is a first-party, server-readable cookie recording that
current choice for up to approximately 180 days. Necessary-only and withdrawal choices delete it. The analytics
ingestion route accepts only this dedicated cookie (or the separate authenticated consent record), never the
deprecated als_cookie_consent cookie.
When Marketing is enabled under the current Cookie Policy, als_referral_code can be stored in a first-party
cookie for up to 30 days and in local browser storage to preserve referral attribution through the requested
signup journey. With no choice, an invalid or stale choice, necessary-only, or marketing withdrawal, both
persistent values are removed. A referral in the current page URL can remain in page memory for that page only.
The repository can contain integrations that are disabled in the current environment. This policy does
not claim that Plausible, Google Analytics, advertising cookies, payment-provider cookies or any other
named optional provider is active without a verified production inventory.
4. Your First-Layer Choice
The first layer presents “Accept optional cookies” and “Reject optional cookies” with the same size,
colour treatment and visual weight. You can instead open “Manage preferences” and choose categories
individually. Rejecting optional cookies keeps all three optional categories off.
No optional category is treated as accepted merely because you visit or continue to use the site.
Submitting a cookie choice does not record acceptance of the Terms of Service or Privacy Policy. Legal
acceptance is handled by a separate, explicit account flow.
5. Changing or Withdrawing Your Choice
Use “Manage cookies” in the site footer to reopen the control. Saving new preferences replaces the
previous optional-cookie choice and updates the server-side consent record where that endpoint is
available. You can also clear cookies and local storage in your browser; doing so may sign you out or
cause the banner to appear again.
6. Third-Party and Payment Storage
Social sign-in can redirect you to Google, Facebook or LinkedIn OIDC only when that provider is
configured and shown. Those providers control storage on their own domains under their own policies.
Paid digital Artwork Licence checkout and ALS Pro checkout, billing recovery and cancellation use Stripe-hosted
pages where the relevant server checkout gate allows the flow. Stripe can set necessary fraud-prevention,
checkout, billing or security storage on its own domains under Stripe's notices. Those provider-domain choices
are separate from the ALS first-party optional-cookie panel.
Resend does not set browser storage through the public website in the current source-controlled paid-release
boundary. If ALS later enables separate transactional email delivery through Resend, that is a processor and
email-delivery disclosure question rather than an ALS browser-cookie category by itself.
7. Updates and Contact
Material changes will use a new policy version and date. The visible Cookie Policy date is derived from
the versioned legal artifact rather than the day on which a page happens to be viewed.
Questions: privacy@artlicencestudio.co.uk
Registered office: Art Licence Studio Ltd, 5 Brayford Square, London, E1 0SG, United Kingdom
Company No. 16440129 · Registered in England and Wales