Legal
Cookie Policy
Last updated: pending publication
This is a working draft published for structure and review. It is not yet the final, lawyer-reviewed agreement and should not be relied upon. The definitive version will replace this text before StageLink opens to the public.
1. What cookies are
Cookies and similar technologies are small files or storage items a site uses to keep you signed in, remember preferences, and understand usage. This policy explains which ones StageLink uses and how to control them.
2. Strictly necessary
Used for authentication and session management, PKCE/state/CSRF protection, locale and basic UI preferences, and security, rate limiting, and abuse prevention. These are required for the service and cannot be turned off in-product, though you can control them in your browser.
3. Analytics
Used to understand page visits, link clicks, public-page performance, and product usage, and to give artists dashboard metrics. Your choice is stored in the `sl_ac` cookie (1 = accepted, 0 = rejected); product analytics such as PostHog are gated by consent.
Where the GDPR and the ePrivacy rules apply, the analytics cookies described here are set only after you opt in. Strictly necessary cookies are exempt from consent because the service cannot run without them.
4. Marketing
Used for campaign attribution, retargeting, advertising, or marketing pixels. No marketing pixels are assumed active today; any such cookies would require opt-in consent with preference and opt-out controls.
5. Cookie inventory
WorkOS session cookie (Necessary, WorkOS/StageLink) — auth session.
PKCE/state cookie (Necessary, StageLink/WorkOS) — OAuth security.
`NEXT_LOCALE` (Necessary/preference, StageLink) — language.
`sl_consent` (Analytics preference, StageLink) — versioned consent record, 180 days.
`sl_ac` (Analytics preference, StageLink) — compact mirror of the consent decision, sent to our API, 180 days.
`sl_attribution` (Necessary, StageLink) — records which campaign or referral link brought you here, so a signup can be attributed. 90 days.
`sl_qa` (Necessary, StageLink) — marks a QA session so test traffic is excluded from analytics. Browser session only, set via a URL parameter.
`sl_debug` (Necessary, StageLink) — opt-in click-tracking debugging. 1 hour, set via a URL parameter.
PostHog cookies/local storage (Analytics, PostHog) — product analytics, only after consent where required.
This list reflects the cookies the application actually sets. Third-party names and lifetimes (PostHog, Umami, Crisp, Stripe) are controlled by those providers and may change.
6. Managing your choices
You can accept all, reject non-essential, or manage categories through the in-product consent control, and change your choice at any time. You can also manage cookies through your browser settings.
7. Changes and contact
We may update this Cookie Policy. Questions can be sent to the contact channel published here. Questions: hola@stagelink.art.