Cookie Policy
Last updated: 2026-08-30
1. What cookies are
Cookies are small text files stored in your browser. Lucanto may also use similar technologies, such as local storage or SDK identifiers. In this policy we refer to all of these together as "cookies".
2. Categories and legal basis
Necessary cookies
These are needed for sign-in, Cloudflare proxy/CDN and Turnstile bot protection, security, order processing, storing your privacy choice, traffic routing and basic functionality. They do not require consent because without them the Service you requested, or its security, would not work. We do not use them for optional advertising or analytics. Turnstile may process IP, TLS fingerprint, user-agent, sitekey/origin and a security token; the Turnstile Privacy Addendum also explains Cloudflare's role.
Analytics cookies
These help us understand visits and product usage. Google Tag Manager is a container, not analytics by itself: the local dataLayer only makes values available to tags. The Better Stack browser tag may capture a frontend error and, subject to the selected sampling, a session replay. The external GTM script, analytics or marketing tags, and the entire Better Stack browser tag do not load until you give analytics consent. Before consent, no cookieless ping is sent to Google either, and Better Stack does not create its _bs cookie or a local identifier. In Better Stack, unnecessary web analytics, event autocapture and browser fingerprinting are turned off. Declining does not affect Lucanto's core functionality or server-side security logging.
Marketing cookies
We only use these if we actually deploy them, list them in this register, and obtain separate consent. The default setting is off.
3. Register of cookies and similar technologies
| Name / pattern | Provider | Category | Purpose | Lifetime |
|---|---|---|---|---|
| Lucanto session cookie | Lucanto | necessary | sign-in and keeping the session | until sign-out or a maximum of 30 days of inactivity |
| Lucanto CSRF/security token | Lucanto | necessary | protection of forms, requests and the session | for the duration of the session |
| Lucanto consent preference | Lucanto | necessary | stores your cookie choice, its date and the settings version | 6 months |
| __cf_bm | Cloudflare | necessary when bot protection is active | computing a bot score and protecting against malicious traffic | 30 minutes of inactivity |
| cf_clearance, _cfuvid and related security cookies | Cloudflare | necessary when the relevant security feature responds | proving a passed challenge, rate limiting and distinguishing visitors from the same IP | for the security session set for the relevant feature |
| Turnstile token and browser signals (not always a cookie) | Cloudflare Turnstile | necessary | distinguishing a human from a bot at registration and protecting the form | token valid 5 minutes and for a single verification only |
| Google OAuth / Sign in with Apple cookies | Google or Apple | necessary only after choosing external sign-in | authentication with the chosen provider | per the chosen provider's settings and policy |
| Google Tag Manager container (not a cookie) | analytics/depends on tag | loading and managing optional tags | loads only after the relevant consent and for the duration of the visit | |
| _bs cookie and related local identifier | Better Stack | analytics | session identifier, frontend error sampling and, after consent, an optional session replay | up to 90 days or until consent is withdrawn and the identifier is deleted |
| Stripe Checkout cookies and local storage | Stripe | necessary for the chosen payment | payment security, fraud prevention and completing checkout | for the period necessary for security and fraud prevention set out in Stripe's rules |
3A. External resources without cookies
Loading Google Fonts, jsDelivr or UNPKG directly creates a network request in which the provider receives at least an IP address, user-agent, requested URL and, depending on the browser, referrer. This is not necessarily a cookie, but it is still processing of technical personal data. We use these requests only to the extent necessary for display or technical functionality and do not use them for marketing profiling.
4. Setting and withdrawing consent
On your first visit you can accept all optional cookies, decline them, or open the settings. The "Accept all" and "Reject optional" buttons carry equal visibility. No analytics or marketing runs before you choose "Accept" for the relevant category.
You can change your choice at any time through the Cookie Settings link in the footer. Withdrawal stops future collection and removes the Better Stack _bs cookie and related local identifier set by Lucanto; it does not necessarily retroactively delete aggregated statistics already lawfully obtained. You can also delete cookies in your browser, which may sign you out or remove saved settings.
5. Transfers and providers
Google, Better Stack, Cloudflare, Stripe and CDN providers may process data outside the EEA under the transfer safeguards described in the Privacy Notice. We use analytics and marketing tags, including the Better Stack browser tag, only after consent. Cloudflare/Turnstile and Stripe may use technologies necessary for security, bot prevention or fraud prevention without optional consent; server-side logging and backend error reporting do not use the Better Stack browser cookie.
6. Contact and changes
Send questions to hello@lucanto.eu. When we add a new optional purpose, we update the register and request consent before activating it. The date of the last change is shown above.
Operated by: Stark Codes, s.r.o.