Effective August 19, 2026 · Version 1.2
Cookie policy
This policy describes browser cookies, local storage, pixels, and similar technologies used by supercenter.dev.
1. The short version
Necessary technologies keep authentication, security, checkout, and privacy choices working. Visitors identified as being in Europe must choose before optional analytics or marketing loads. In other regions, optional technologies can start by default where local rules permit. You can turn them off at any time. Rejecting them does not restrict access to the website or product.
2. What these technologies are
Cookies are small text records stored by a browser. Local storage is a similar browser facility. Pixels and scripts can send an event to a provider when a page is viewed or an action occurs. Some technologies are first-party because they are set for supercenter.dev; a provider may still process the resulting event for us.
3. Storage and providers
Supercenter / Better Auth
Necessary- Names:
- Session, OAuth state, PKCE, CSRF, and security cookies (names may use a secure prefix)
- Purpose:
- Keep you signed in, bind OAuth requests, prevent request forgery, and secure accounts and connected agents.
- Expected duration:
- Session or short-lived for OAuth/security state; authenticated sessions up to 7 days.
Supercenter
Necessary- Names:
- sc_privacy, sc_privacy_region, and supercenter:privacy-consent:v1
- Purpose:
- Remember analytics and marketing choices and whether the regional consent banner applies, without assigning an advertising identifier.
- Expected duration:
- The choice lasts 180 days. The regional marker lasts for the browser session.
Stripe
Necessary when checkout is requested- Names:
- Stripe checkout and fraud-prevention storage on Stripe-controlled pages
- Purpose:
- Secure checkout, payment processing, fraud prevention, and payment-method continuity.
- Expected duration:
- Varies by Stripe technology and legal/security need; see Stripe’s cookie and privacy information.
PostHog
Analytics: consent required- Names:
- ph_<project>_posthog and related first-party analytics storage
- Purpose:
- Distinguish pseudonymous sessions, measure feature use and performance, and provide masked session replay across public and signed-in pages. Replay masks all text and inputs and excludes request headers and bodies.
- Expected duration:
- Up to 12 months under the intended configuration, or earlier withdrawal/deletion.
Google Analytics
Analytics: consent required- Names:
- _ga and _ga_<measurement-id>
- Purpose:
- Distinguish pseudonymous visitors and sessions and report site usage statistics.
- Expected duration:
- Up to 2 years under Google’s default documented duration, subject to our configured retention.
Meta Pixel
Marketing: consent required- Names:
- _fbp and, after an ad click, _fbc
- Purpose:
- Attribute visits and conversions, measure campaigns, and support Meta advertising audiences.
- Expected duration:
- Generally up to 90 days according to Meta’s published cookie information.
Google advertising tools
Marketing: consent required- Names:
- _gcl_au, _gcl_* and related Google advertising identifiers
- Purpose:
- Attribute advertising clicks and conversions and measure campaign effectiveness.
- Expected duration:
- Typically up to 90 days for first-party conversion storage; Google-controlled storage may vary.
LinkedIn Insight Tag
Marketing: consent required- Names:
- li_fat_id, bcookie, lidc, AnalyticsSyncHistory, and UserMatchHistory
- Purpose:
- Attribute visits and conversions and measure LinkedIn campaigns.
- Expected duration:
- Up to 6 months, based on the specific LinkedIn identifier.
TikTok Pixel
Marketing: consent required- Names:
- _ttp and related TikTok advertising identifiers
- Purpose:
- Attribute visits and conversions and measure TikTok campaigns.
- Expected duration:
- Up to 13 months, based on the specific TikTok identifier.
4. Consent and legal basis
Under § 165(3) of the Austrian Telecommunications Act 2021 and the ePrivacy rules, storage or access that is not technically necessary requires prior consent. Where it also processes personal data, consent is the legal basis under Article 6(1)(a) GDPR. Necessary authentication and security storage is used to provide the service you requested and protect it.
In Europe, the first choice offers equally accessible acceptance and rejection. Optional categories are off before that choice. Outside Europe, optional categories can start by default where local rules permit. Privacy choices and Global Privacy Control remain available. We store the choice for 180 days and ask again when required after it expires or when a material purpose changes.
5. Withdrawing consent
Use “Privacy choices” in the footer or the button above at any time. Withdrawal takes effect for future processing and does not affect processing already carried out lawfully. When a category is refused, we signal configured providers and remove known first-party analytics or marketing storage that the browser allows us to delete. Provider-controlled third-party storage may also need to be cleared in browser or provider settings.
If your browser sends Global Privacy Control, we treat it as a decline for optional analytics and marketing. You can also block or delete cookies in browser settings, though blocking necessary session storage can prevent sign-in or checkout from working.
6. Provider information
- Google Analytics privacy and data safeguards
- Meta Cookie Policy
- PostHog Privacy Policy
- LinkedIn Cookie Policy
- TikTok Cookie Policy
- Stripe Privacy Policy
The Austrian Data Protection Authority’s current guidance explains that behavior-tracking and social advertising technologies are not technically necessary and that consent must be obtained before they load. See Datenschutz & Cookies.