Skip to content
Stylaform

Legal

Cookie Policy

Which cookies and browser storage Stylaform uses, what they do and which of them require consent.

Version
1.0
Effective
18 August 2026
Last updated
18 August 2026

Stylaform keeps client-side storage to a minimum. We use no advertising cookies, no tracking pixels, no cross-site tracking, no social media trackers and no session replay.

This policy covers cookies as well as equivalent technologies such as localStorage and sessionStorage.

1. Strictly necessary storage

This storage is required to deliver the Service you request. It does not need consent under the ePrivacy rules, and it cannot be switched off without breaking the application.

Name / purposeTypeWhyDuration
Authentication session and refresh tokenCookie and localStorageKeeps you signed in and lets the server verify who you are on each requestUntil sign-out, or until the session expires
Active workspace and brand selectionlocalStorageRemembers which Workspace and brand you were working inUntil cleared
Security and rate-limit protectionServer-side, no client cookieProtects sign-in and metered endpoints against abuseShort lived
Consent and notice choiceslocalStorageRemembers that you dismissed a notice or made a storage choice12 months

2. Functional preferences

These entries store interface state so the application behaves the way you left it. They stay on your device, are not shared with third parties and are not used to profile you.

  • Remembered email address on the sign-in screen, when you choose that option.
  • Sidebar collapsed or expanded state, theme preference and view density.
  • List filters, sorting and tab selection.
  • Unsaved draft state for forms and editors, so work is not lost on reload.

You can remove all of this at any time by clearing site data in your browser. Doing so signs you out and resets your interface preferences.

3. Optional storage requiring consent

We currently use none. There is no analytics cookie, no advertising cookie, no tracking pixel, no session replay, no third-party error tracking and no third-party performance monitoring on the website or in the application.

If we introduce any such technology, we will ask for consent before it is placed, provide a way to withdraw consent, and update this policy first.

4. Third-party requests

The public website currently loads web fonts from Google Fonts. This does not set a cookie, but the request means your IP address and browser details reach Google as a technical necessity of delivering the file. We consider this a privacy consideration and intend to self-host the fonts so no third-party font request is made.

The application is served through Cloudflare, which processes request metadata such as IP address for delivery, caching and protection against attacks. Payment pages are handled by Stripe, which sets its own strictly necessary and fraud-prevention storage when a payment is made; Stripe's own notices apply there.

Other than these, no third-party scripts are loaded.

5. Managing storage

Browsers let you view, block and delete cookies and site storage. Blocking strictly necessary storage will prevent sign-in and stop the application from working.

Questions about this policy: stylaform@turtleworks.nl.

Version history

  • v1.0 - 18 August 2026 - First published version.