Cookie policy
This Cookie Policy explains how SOUQ.GG uses cookies and similar technologies (local storage, session storage, IndexedDB) on souq.gg. For broader information about how we handle personal information, see the Privacy Policy.
We classify cookies into four categories: strictly necessary, functional, analytics, and marketing. Today we only use the first two; if we add optional analytics or marketing cookies, we will request consent first where required.
Contents
10 sections1. What cookies are
#Cookies are small text files stored on your device when you visit a website. They allow a site to remember actions or preferences over time. We also use related browser technologies such as local storage and HTTP-only cookies for authentication. Where this Policy says “cookies”, it also covers those related technologies unless we say otherwise.
2. Categories we recognize
#- Strictly necessary — required for the Service to work (sign-in, security, checkout). These cannot be disabled without breaking the Service.
- Functional — remember your preferences (theme, locale) and minor UI state. Disabling them means small inconveniences (you re-pick your theme on each visit).
- Analytics — help us understand traffic and product usage. Not in use today.If we add analytics, we will publish the specific cookies and request consent where required.
- Marketing — used to measure or personalize advertising. Not in use today.We have no plans to add cross-site advertising cookies; if we ever do, we will request consent.
3. Cookies we use today
#| Name | Purpose | Category | Party | Expiry |
|---|---|---|---|---|
| sb-access-token | Supabase Auth access token used to keep you signed in across pages and API calls. Refreshed automatically. | Strictly necessary | First-party | ~1 hour, rotating |
| sb-refresh-token | Supabase Auth refresh token used to obtain new access tokens without re-authenticating. | Strictly necessary | First-party | Up to 7 days, rotating |
| souq_session | Legacy HMAC-signed session cookie used in some flows during the v2-to-v3 transition. | Strictly necessary | First-party | 7 days |
| NEXT_LOCALE | Stores your locale preference so the site renders in the language you chose. | Functional | First-party | 1 year |
| theme | Remembers your light/dark theme preference. | Functional | First-party | 1 year |
| consent | Records your cookie-consent choices (introduced when we add optional analytics/marketing categories). | Strictly necessary | First-party | 12 months |
| Local storage (UI state) | Cached UI state (cart drafts, recently viewed products, dismissed banners). Not transmitted to our servers automatically. | Functional | First-party | Until cleared by you |
| Stripe cookies (when checkout is open) | Stripe sets cookies on its own checkout pages and embedded widgets for fraud prevention, session continuity, and consent. Governed by Stripe's privacy and cookie notices. | Strictly necessary | Third-party | Per Stripe policy |
4. Local & session storage
#The Service uses your browser’s local storage for non-sensitive UI state such as your cart contents before checkout, recently viewed products, and dismissed banners. This data lives on your device only and is not transmitted to our servers unless you take an action that requires it (such as completing a purchase).
We do not use IndexedDB for personal data. If we add IndexedDB-backed offline features in the future, we will update this Policy and identify the specific objects stored.
5. Third-party cookies
#We do not currently use third-party advertising or cross-site tracking cookies. Two third-party domains may set cookies during your use of the Service:
- Stripe — sets cookies on its own checkout pages and embedded widgets to authenticate sessions, prevent fraud, and meet local cookie-consent obligations. See the Stripe Privacy Policy and Stripe Cookie Policy for details.
- Supabase — Supabase Auth cookies are first-party to souq.gg (we proxy them) and are covered in the table above.
6. Your choices & opt-out
#You can control cookies through your browser settings, blocking all cookies, blocking third-party cookies, or deleting cookies for souq.gg. Blocking strictly necessary cookies will sign you out and may prevent access to account features.
If we introduce optional analytics or marketing cookies in the future, we will surface a consent banner letting you accept, reject, or customize categories before any non-essential cookies are set.
7. Do Not Track and Global Privacy Control
#Browsers have inconsistent “Do Not Track” (DNT) and “Global Privacy Control” (GPC) signals. Where you send a clear opt-out preference signal (such as GPC) and California law treats it as a valid opt-out of sale or sharing, we will honor it. Since we do not currently sell or share personal information for cross-context behavioral advertising, no change to our processing is triggered today, but we record the signal for future configurations.
8. Managing cookies in your browser
#Here are the cookie-control pages for major browsers:
- Google Chrome: settings → Privacy & security → Cookies and other site data
- Mozilla Firefox: settings → Privacy & Security → Cookies and Site Data
- Apple Safari: Preferences → Privacy → Manage Website Data
- Microsoft Edge: settings → Cookies and site permissions → Cookies and site data
- Brave: settings → Shields → Cookies
On mobile, similar controls are available under the browser settings; some apps may use OS-level controls.
9. Changes
#We may update this Cookie Policy as our technology evolves. Material changes will be reflected by updating the “Updated” date and, where appropriate, by an in-product notice or consent banner.
10. Contact
#Questions: privacy@souq.gg.