Cookie Policy

Last updated: 2026-08-30

1. What cookies are

Cookies are small text files stored in your browser. Lucanto may also use similar technologies, such as local storage or SDK identifiers. In this policy we refer to all of these together as "cookies".

2. Categories and legal basis

Necessary cookies

These are needed for sign-in, Cloudflare proxy/CDN and Turnstile bot protection, security, order processing, storing your privacy choice, traffic routing and basic functionality. They do not require consent because without them the Service you requested, or its security, would not work. We do not use them for optional advertising or analytics. Turnstile may process IP, TLS fingerprint, user-agent, sitekey/origin and a security token; the Turnstile Privacy Addendum also explains Cloudflare's role.

Analytics cookies

These help us understand visits and product usage. Google Tag Manager is a container, not analytics by itself: the local dataLayer only makes values available to tags. The Better Stack browser tag may capture a frontend error and, subject to the selected sampling, a session replay. The external GTM script, analytics or marketing tags, and the entire Better Stack browser tag do not load until you give analytics consent. Before consent, no cookieless ping is sent to Google either, and Better Stack does not create its _bs cookie or a local identifier. In Better Stack, unnecessary web analytics, event autocapture and browser fingerprinting are turned off. Declining does not affect Lucanto's core functionality or server-side security logging.

Marketing cookies

We only use these if we actually deploy them, list them in this register, and obtain separate consent. The default setting is off.

3. Register of cookies and similar technologies

Register of cookies and similar technologies
Name / patternProviderCategoryPurposeLifetime
Lucanto session cookieLucantonecessarysign-in and keeping the sessionuntil sign-out or a maximum of 30 days of inactivity
Lucanto CSRF/security tokenLucantonecessaryprotection of forms, requests and the sessionfor the duration of the session
Lucanto consent preferenceLucantonecessarystores your cookie choice, its date and the settings version6 months
__cf_bmCloudflarenecessary when bot protection is activecomputing a bot score and protecting against malicious traffic30 minutes of inactivity
cf_clearance, _cfuvid and related security cookiesCloudflarenecessary when the relevant security feature respondsproving a passed challenge, rate limiting and distinguishing visitors from the same IPfor the security session set for the relevant feature
Turnstile token and browser signals (not always a cookie)Cloudflare Turnstilenecessarydistinguishing a human from a bot at registration and protecting the formtoken valid 5 minutes and for a single verification only
Google OAuth / Sign in with Apple cookiesGoogle or Applenecessary only after choosing external sign-inauthentication with the chosen providerper the chosen provider's settings and policy
Google Tag Manager container (not a cookie)Googleanalytics/depends on tagloading and managing optional tagsloads only after the relevant consent and for the duration of the visit
_bs cookie and related local identifierBetter Stackanalyticssession identifier, frontend error sampling and, after consent, an optional session replayup to 90 days or until consent is withdrawn and the identifier is deleted
Stripe Checkout cookies and local storageStripenecessary for the chosen paymentpayment security, fraud prevention and completing checkoutfor the period necessary for security and fraud prevention set out in Stripe's rules

3A. External resources without cookies

Loading Google Fonts, jsDelivr or UNPKG directly creates a network request in which the provider receives at least an IP address, user-agent, requested URL and, depending on the browser, referrer. This is not necessarily a cookie, but it is still processing of technical personal data. We use these requests only to the extent necessary for display or technical functionality and do not use them for marketing profiling.

4. Setting and withdrawing consent

On your first visit you can accept all optional cookies, decline them, or open the settings. The "Accept all" and "Reject optional" buttons carry equal visibility. No analytics or marketing runs before you choose "Accept" for the relevant category.

You can change your choice at any time through the Cookie Settings link in the footer. Withdrawal stops future collection and removes the Better Stack _bs cookie and related local identifier set by Lucanto; it does not necessarily retroactively delete aggregated statistics already lawfully obtained. You can also delete cookies in your browser, which may sign you out or remove saved settings.

5. Transfers and providers

Google, Better Stack, Cloudflare, Stripe and CDN providers may process data outside the EEA under the transfer safeguards described in the Privacy Notice. We use analytics and marketing tags, including the Better Stack browser tag, only after consent. Cloudflare/Turnstile and Stripe may use technologies necessary for security, bot prevention or fraud prevention without optional consent; server-side logging and backend error reporting do not use the Better Stack browser cookie.

6. Contact and changes

Send questions to hello@lucanto.eu. When we add a new optional purpose, we update the register and request consent before activating it. The date of the last change is shown above.

Operated by: Stark Codes, s.r.o.

Unlock your financial superpowers

Start for free