Cookie Policy

Version: 1.4 · Last updated: 30 July 2026 · Effective from: 30 August 2026

1. What are cookies

Cookies are small text files stored by a browser. Lucanto may also use similar technology such as local storage or SDK identifiers. This Policy calls all of them “cookies”.

2. Categories and legal basis

Necessary cookies

These support login, Cloudflare proxy/CDN and Turnstile anti-bot protection, security, order operation, privacy choice, traffic routing and core features. They do not need consent because the requested Service or its security cannot function without them. We do not use them for optional advertising or analytics. Turnstile may process IP, TLS fingerprint, user-agent, sitekey/origin and a security token; the Turnstile Privacy Addendum also explains Cloudflare’s role.

Analytics cookies

These help us understand visits and product use. Google Tag Manager is a container, not analytics itself: the local dataLayer only makes values available to tags. The Better Stack browser tag can capture frontend errors and, according to the selected sampling, a session replay. Neither the external GTM script, any analytics or marketing tag, nor the Better Stack browser tag loads until you give analytics consent. Before consent, no cookieless ping is sent to Google and Better Stack does not create an _bs cookie or local identifier. Unnecessary Better Stack website analytics, event autocapture and browser fingerprinting are disabled. Refusal does not affect core Lucanto features or server-side security logging.

Marketing cookies

We use these only if actually deployed, added to this register and separately consented to. They are off by default.

3. Cookie and similar technology register

Name / pattern

Provider

Category

Purpose

Lifetime

Lucanto session cookie

Lucanto

necessary

login and session continuity

until logout or up to 30 days of inactivity

Lucanto CSRF/security token

Lucanto

necessary

form, request and session security

session duration

Lucanto consent preference

Lucanto

necessary

store cookie choice, date and settings version

6 months

__cf_bm

Cloudflare

necessary when bot protection is activated

bot-score calculation and malicious-traffic protection

30 minutes of inactivity

cf_clearance, _cfuvid and related security cookies

Cloudflare

necessary when the relevant security feature is triggered

successful-challenge evidence, rate limiting and distinction between visitors sharing an IP

security-session duration configured for the relevant feature

Turnstile token and browser signals (not always a cookie)

Cloudflare Turnstile

necessary

distinguish humans from bots at signup and protect forms

5-minute, single-use token

Google OAuth / Sign in with Apple cookies

Google or Apple

necessary only after external login is selected

authentication at selected provider

Google/Apple setting and policy

Google Tag Manager container (not a cookie)

Google

analytics/tag-dependent

load and manage optional tags

loads only after relevant consent and for the visit

_bs cookie and related local identifier

Better Stack

analytics

session identifier, frontend-error sampling and, after consent, possible session replay

up to 90 days or until consent is withdrawn and the identifier is erased

Stripe Checkout cookies and local storage

Stripe

necessary for the selected payment

payment security, fraud prevention and checkout completion

for the security and fraud-prevention period stated in Stripe's policies

3A. External resources without cookies

Direct loading from Google Fonts, jsDelivr or UNPKG creates a network request in which the provider receives at least the IP address, user-agent, requested URL and, depending on the browser, referrer. This is not necessarily a cookie but is still processing of technical personal data. We use these requests only as necessary for display or technical function and not for marketing profiling.

4. Consent settings and withdrawal

On first visit you may accept all optional cookies, reject them, or open settings. “Accept all” and “Reject optional” have equivalent prominence. No analytics or marketing loads before you select “Accept” for that category.

Change your choice any time through Cookie Settings in the footer. Withdrawal stops future collection and removes the Better Stack _bs cookie and related local identifier set through Lucanto; it need not erase lawfully obtained aggregated statistics. Browser deletion may log you out or remove saved preferences.

5. Transfers and providers

Google, Better Stack, Cloudflare, Stripe and CDN providers may process data outside the EEA under the transfer safeguards described in the Privacy Notice. Analytics and marketing tags, including the Better Stack browser tag, activate only after consent. Cloudflare/Turnstile and Stripe may use technology necessary for anti-bot, payment or fraud security without optional consent; server-side logging and backend error reporting do not use the Better Stack browser cookie.

6. Contact and changes

Questions: hello@lucanto.eu. Before a new optional purpose is activated, we update the register and request consent. The last-updated date appears above.