Effective August 19, 2026 · Version 1.2

Cookie policy

This policy describes browser cookies, local storage, pixels, and similar technologies used by supercenter.dev.

1. The short version

Necessary technologies keep authentication, security, checkout, and privacy choices working. Visitors identified as being in Europe must choose before optional analytics or marketing loads. In other regions, optional technologies can start by default where local rules permit. You can turn them off at any time. Rejecting them does not restrict access to the website or product.

2. What these technologies are

Cookies are small text records stored by a browser. Local storage is a similar browser facility. Pixels and scripts can send an event to a provider when a page is viewed or an action occurs. Some technologies are first-party because they are set for supercenter.dev; a provider may still process the resulting event for us.

3. Storage and providers

Supercenter / Better Auth

Necessary
Names:
Session, OAuth state, PKCE, CSRF, and security cookies (names may use a secure prefix)
Purpose:
Keep you signed in, bind OAuth requests, prevent request forgery, and secure accounts and connected agents.
Expected duration:
Session or short-lived for OAuth/security state; authenticated sessions up to 7 days.

Supercenter

Necessary
Names:
sc_privacy, sc_privacy_region, and supercenter:privacy-consent:v1
Purpose:
Remember analytics and marketing choices and whether the regional consent banner applies, without assigning an advertising identifier.
Expected duration:
The choice lasts 180 days. The regional marker lasts for the browser session.

Stripe

Necessary when checkout is requested
Names:
Stripe checkout and fraud-prevention storage on Stripe-controlled pages
Purpose:
Secure checkout, payment processing, fraud prevention, and payment-method continuity.
Expected duration:
Varies by Stripe technology and legal/security need; see Stripe’s cookie and privacy information.

PostHog

Analytics: consent required
Names:
ph_<project>_posthog and related first-party analytics storage
Purpose:
Distinguish pseudonymous sessions, measure feature use and performance, and provide masked session replay across public and signed-in pages. Replay masks all text and inputs and excludes request headers and bodies.
Expected duration:
Up to 12 months under the intended configuration, or earlier withdrawal/deletion.

Google Analytics

Analytics: consent required
Names:
_ga and _ga_<measurement-id>
Purpose:
Distinguish pseudonymous visitors and sessions and report site usage statistics.
Expected duration:
Up to 2 years under Google’s default documented duration, subject to our configured retention.

Meta Pixel

Marketing: consent required
Names:
_fbp and, after an ad click, _fbc
Purpose:
Attribute visits and conversions, measure campaigns, and support Meta advertising audiences.
Expected duration:
Generally up to 90 days according to Meta’s published cookie information.

Google advertising tools

Marketing: consent required
Names:
_gcl_au, _gcl_* and related Google advertising identifiers
Purpose:
Attribute advertising clicks and conversions and measure campaign effectiveness.
Expected duration:
Typically up to 90 days for first-party conversion storage; Google-controlled storage may vary.

LinkedIn Insight Tag

Marketing: consent required
Names:
li_fat_id, bcookie, lidc, AnalyticsSyncHistory, and UserMatchHistory
Purpose:
Attribute visits and conversions and measure LinkedIn campaigns.
Expected duration:
Up to 6 months, based on the specific LinkedIn identifier.

TikTok Pixel

Marketing: consent required
Names:
_ttp and related TikTok advertising identifiers
Purpose:
Attribute visits and conversions and measure TikTok campaigns.
Expected duration:
Up to 13 months, based on the specific TikTok identifier.
The exact names present depend on which features are configured and used. For visitors identified as being in Europe, the relevant consent category must be granted before an optional technology loads.

4. Consent and legal basis

Under § 165(3) of the Austrian Telecommunications Act 2021 and the ePrivacy rules, storage or access that is not technically necessary requires prior consent. Where it also processes personal data, consent is the legal basis under Article 6(1)(a) GDPR. Necessary authentication and security storage is used to provide the service you requested and protect it.

In Europe, the first choice offers equally accessible acceptance and rejection. Optional categories are off before that choice. Outside Europe, optional categories can start by default where local rules permit. Privacy choices and Global Privacy Control remain available. We store the choice for 180 days and ask again when required after it expires or when a material purpose changes.

5. Withdrawing consent

Use “Privacy choices” in the footer or the button above at any time. Withdrawal takes effect for future processing and does not affect processing already carried out lawfully. When a category is refused, we signal configured providers and remove known first-party analytics or marketing storage that the browser allows us to delete. Provider-controlled third-party storage may also need to be cleared in browser or provider settings.

If your browser sends Global Privacy Control, we treat it as a decline for optional analytics and marketing. You can also block or delete cookies in browser settings, though blocking necessary session storage can prevent sign-in or checkout from working.

6. Provider information

The Austrian Data Protection Authority’s current guidance explains that behavior-tracking and social advertising technologies are not technically necessary and that consent must be obtained before they load. See Datenschutz & Cookies.