Cookie Policy
COOKIE POLICY
Last updated: September 13, 2026
WHAT IS A COOKIE?
A cookie is a small text file that a website stores on your device when you visit. Cookies help websites remember your preferences, keep you logged in, and understand how you use a service.
COOKIES WE USE TODAY
We use a minimal set of cookies — only what is needed to operate the Service.
Authentication cookie (essential)
Name: sb-[project]-auth-token (set by Supabase)
Purpose: Keeps you logged in across page loads. Without this cookie, you would be logged out every time you navigate to a new page.
Duration: Session (expires when you close your browser or after your session token expires, typically 1 hour; refreshed automatically while you use the app)
Third party: Supabase (supabase.com)
Analytics (privacy-preserving)
Provider: Vercel Analytics
Purpose: Measures aggregate page views, performance metrics (Core Web Vitals), and general traffic patterns so we can improve the Service.
Tracking method: Vercel Analytics does not use cookies for tracking. It uses a privacy-preserving approach that does not identify individual users, does not build cross-site profiles, and does not share data with advertising networks.
PLANNED ADDITION: POSTHOG ANALYTICS (NOT YET ACTIVE)
We are planning to add PostHog, a product analytics platform, to the Service. As of this policy's last-updated date, PostHog is not yet installed and none of the tracking described in this section is happening — it is documented here in advance, before it goes live, so members can see what is coming.
When PostHog is turned on, it is expected to set cookies and/or use browser local storage for:
Product analytics
Purpose: Page views, feature usage, and funnels (e.g., how members move through signing up, adding a polish, or logging a wear), so we can see what's working and what isn't.
Session replay
Purpose: Records how members interact with the Service (clicks, scrolling, navigation) to help us diagnose bugs and confusing flows. Session replay does not capture information typed into password fields, and we intend to mask other sensitive form inputs before this launches.
Error and performance tracking
Purpose: Captures crashes, slow requests, and performance data so problems can be found and fixed.
Contribution/moderation visibility (admin only)
Purpose: Internal-only reporting for admins (e.g., seeing who is approaching the daily contribution cap). This does not add any new tracking of members beyond what's described above — it's a different view onto the same product-analytics data.
We will update this policy with real cookie names, durations, and any consent controls before PostHog goes live, not after. If member consent needs to be collected for any of this (for example, under GDPR for EU visitors), we will add that mechanism before switching it on, not describe it here as a formality.
COOKIES WE DO NOT USE
- Advertising or targeting cookies
- Social media tracking pixels
- Third-party analytics that share data with ad networks (e.g., Google Analytics advertising features)
- Persistent tracking identifiers beyond what is required for authentication
HOW TO MANAGE COOKIES
You can control cookies through your browser settings:
- Chrome: Settings → Privacy and Security → Cookies and other site data
- Firefox: Settings → Privacy & Security → Cookies and Site Data
- Safari: Preferences → Privacy → Manage Website Data
- Edge: Settings → Privacy, search, and services → Cookies
Note: Disabling the authentication cookie will prevent you from staying logged in to Polish Me Pink.
CHANGES TO THIS POLICY
We will update this policy whenever we introduce new cookies or tracking technologies — including when PostHog moves from planned to active. The "Last updated" date at the top reflects the most recent revision.
CONTACT
Questions? Email us at: hello@polishmepink.com