Policy version: 2026-04-21
This policy explains which cookies or equivalent storage mechanisms StickAtlas currently uses on the public publication and in the product’s private areas, and how you can review or change your preferences.
Analytics and any future marketing technology stay blocked until the visitor opts in through the CMP. Rejection is available in the first layer and preferences can be reopened at any time.
Consent storage, visitor identifier, and private authentication cookies needed for the service to work.
Google Analytics remains blocked until the analytics category is accepted in the CMP.
No marketing cookies are active today. Any future marketing technology will stay blocked until prior consent.
Measures visits, page views, traffic sources, and aggregated usage patterns on the public site.
Trigger: Loads only after the visitor accepts the analytics category in the CMP.
Fallback when rejected: If rejected, no Google Analytics script is injected and no analytics cookies should be created.
International transfers: United States and other Google processing locations. Standard Contractual Clauses and the safeguards documented by Google for Analytics.
Serves the website, static assets, TLS, and edge delivery needed to provide the service.
Trigger: Always active because the site cannot be delivered without the hosting layer.
Fallback when rejected: No optional cookie banner action affects the delivery of strictly necessary infrastructure services.
Stores uploaded contribution images and serves approved media assets.
Trigger: Used only when the visitor uploads media or views existing media assets.
Fallback when rejected: If a visitor does not submit content, no upload operation is started.
International transfers: Depends on the configured AWS region and any operational support locations. Contractual and organizational safeguards agreed with the provider.
| Cookie | Provider | Purpose | Duration | Type | Scope | Requires consent |
|---|---|---|---|---|---|---|
| stickatlas_cookie_consent | StickAtlas | Stores the visitor cookie choices and the consent timestamp needed to remember the CMP decision. | 180 days | necessary | First-party | No |
| stickatlas_visitor | StickAtlas | Stores an anonymous visitor identifier used for proof-of-consent logging and preference persistence. | 180 days | necessary | First-party | No |
| _ga | Google Analytics | Distinguishes visitors to generate aggregated audience and navigation statistics. | 2 years | analytics | Third-party / Google | Yes |
| _ga_* | Google Analytics | Keeps session and measurement state for the configured Google Analytics property. | 2 years | analytics | Third-party / Google | Yes |
| next-auth.session-token / __Secure-next-auth.session-token | StickAtlas Backoffice | Maintains authenticated admin sessions in the private backoffice. | Session / server-side expiry | necessary | First-party | No |
| next-auth.csrf-token / next-auth.callback-url | StickAtlas Backoffice | Protects sign-in flows and preserves the return URL during authentication. | Session | necessary | First-party | No |