Legal
Cookie Policy
Last updated: June 17, 2026 · Effective: June 17, 2026
Operated by Black Snow (www.blacksnow.com.np) at sparkd.social
1. What Are Cookies?
Cookies are small text files that a website places in your browser when you visit it. They are stored on your device (computer, phone, or tablet) and sent back to the website on subsequent visits. Cookies allow the website to remember things about you — for example, that you are logged in, that you have already seen the cookie consent banner, or which language you prefer.
In addition to traditional cookies, websites also use related technologies such as:
- Local storage: a browser-based key-value store similar to cookies but with larger capacity, not automatically sent with every request.
- Session storage: like local storage but cleared when you close the browser tab.
- Pixels and web beacons: tiny invisible images embedded in pages that signal a page view to a third party. We do not use advertising pixels.
This policy covers all of these technologies collectively as “cookies.”
2. Legal Basis for Cookie Use in Nepal
Nepal’s Individual Privacy Act, 2075 (2018) (IPA 2075) establishes that personal information may only be collected with the individual’s informed consent, or where necessary for the performance of a service the individual has requested. Nepal’s Electronic Transactions Act, 2063 (2006) and its accompanying Regulations govern electronic services and data practices.
Under these laws:
- Strictly necessary cookies do not require separate consent because they are essential for the service you have requested (your account session). Their use is justified under the performance-of-service basis in IPA 2075.
- Analytics cookies collect information about how you use our site, which is not strictly necessary. These require your explicit, informed consent before activation, consistent with IPA 2075’s consent requirements.
We align our practices with international best practice (particularly the EU’s GDPR cookie consent standards) because our platform may be accessed by users in multiple jurisdictions, and because these standards represent the highest reasonable bar for user transparency.
3. Cookies and Technologies We Use
Authentication Session (Supabase Auth)
When you log in to Sparkd, Supabase Auth sets session cookies in your browser. These cookies contain an encrypted session token that identifies you as logged in. Without these cookies, you would be logged out on every page load and could not use any authenticated feature of the Platform.
These cookies are HttpOnly (not readable by JavaScript) and Secure (sent only over HTTPS). They cannot be intercepted by scripts on the page.
| Cookie Name | Purpose | Duration |
|---|---|---|
sb-[project]-auth-token | Supabase authentication session token | 1 hour (auto-refreshed while active) |
sb-[project]-auth-token-code-verifier | PKCE code verifier for OAuth flows | Session (cleared on tab close) |
Set by: Supabase Inc. (Tokyo, Japan) · Cannot be disabled
Security (CSRF Protection)
Cross-Site Request Forgery (CSRF) protection tokens are used by our server-side API routes to verify that form submissions and state-changing requests originate from your browser session and not from a malicious third-party site. These are a standard web security measure.
| Cookie Name | Purpose | Duration |
|---|---|---|
__Host-next-auth.csrf-token | CSRF token for form and API security | Session |
Set by: sparkd.social · Cannot be disabled
Cookie Consent Preference
When you make a choice on the cookie consent banner (accept or decline analytics cookies), we store your preference so we do not show you the banner on every page visit. Without this cookie, you would be asked to consent on every visit.
| Cookie Name | Purpose | Duration |
|---|---|---|
sparkd_cookie_consent | Stores your analytics cookie consent choice (accepted / declined) | 1 year |
Set by: sparkd.social · Can be cleared by deleting browser cookies
PostHog Product Analytics
PostHog is a product analytics tool that helps us understand how users interact with the Platform — which features are used most, where users drop off in workflows, and how to improve the user experience. PostHog is not initialised in your browser until you accept analytics cookies. If you decline, PostHog is never loaded and no PostHog cookies are set.
PostHog data is processed in the United States. We use PostHog exclusively for product improvement — data is never sold or shared for advertising purposes.
| Cookie Name | Purpose | Duration |
|---|---|---|
ph_[project_key]_posthog | Anonymous user identifier for session tracking | 1 year |
ph_[project_key]_posthog_ses | Session identifier for grouping pageviews | 30 minutes (session) |
Set by: PostHog Inc. (US) · Privacy policy: posthog.com/privacy · Only active with consent
Google Analytics 4 (GA4)
Google Analytics 4 helps us understand traffic sources, geographic distribution of visitors, device types, and high-level page performance metrics. Like PostHog, GA4 is not loaded until you accept analytics cookies. We have configured GA4 with IP anonymisation enabled — your IP address is truncated before storage. We do not use GA4 for remarketing or advertising.
GA4 data is processed by Google LLC in the United States. We have configured a maximum data retention period of 13 months in GA4.
| Cookie Name | Purpose | Duration |
|---|---|---|
_ga | Distinguishes unique users (anonymous client ID) | 2 years |
_ga_[MEASUREMENT_ID] | GA4 session and engagement state | 2 years |
Set by: Google LLC (US) · Privacy policy: policies.google.com/privacy · Only active with consent
Sentry Error Monitoring
Sentry is our error monitoring service. When the Platform encounters a JavaScript error or performance issue in your browser, Sentry captures a diagnostic report (stack trace, browser version, operating system, and Platform context such as which page you were on). This helps us identify and fix bugs quickly.
Sentry may set a cookie to assign a session identifier for correlating error reports from the same browser session. Sentry data is processed in the European Union. We configure Sentry to minimise capture of personally identifiable information in error payloads — for example, we do not send full user email addresses to Sentry.
Sentry’s error monitoring is considered necessary for maintaining the security and stability of the Platform and therefore operates under the legitimate interest basis rather than requiring separate analytics consent.
| Storage Key | Purpose | Duration |
|---|---|---|
sentry-sc | Sentry session context for error correlation | Session |
Set by: Functional Software Inc. / Sentry (EU) · Privacy policy: sentry.io/privacy
4. No Advertising or Tracking Cookies
We want to be clear about what we do not do:
- We do not use advertising cookies or retargeting pixels (Facebook Pixel, Google Ads, TikTok Pixel, etc.).
- We do not track you across other websites.
- We do not sell your data to advertising networks, data brokers, or any third party.
- We do not use interest-based or behavioural advertising.
- We do not create advertising profiles about you.
Our analytics tools (PostHog and GA4) are used exclusively to understand and improve the Platform — not to serve you targeted advertisements.
5. Cookie Consent — How It Works
5.1 First Visit
When you visit sparkd.social for the first time, a cookie consent banner appears at the bottom of the screen. The banner presents two options:
- Accept analytics: activates PostHog and GA4 for your session and future sessions.
- Decline analytics: PostHog and GA4 are never loaded. Only essential cookies (auth session, CSRF, consent preference, Sentry) are used.
5.2 Consent is Stored
Your choice is stored in the sparkd_cookie_consent cookie for 1 year. We do not ask again unless you clear your cookies or 1 year has elapsed.
5.3 Withdrawing Consent
You may withdraw your analytics consent at any time by clearing your browser cookies for sparkd.social. On your next visit, the consent banner will reappear and you can make a new choice. Withdrawing consent stops future analytics data collection but does not delete data already collected by PostHog or GA4 — to request deletion of that data, contact us at hello@sparkd.social.
5.4 Essential Cookies Cannot Be Declined
Authentication session cookies, CSRF protection cookies, and the consent preference cookie are strictly necessary for the Platform to function. They cannot be declined via the consent banner. You may delete them via your browser settings, but doing so will log you out and may impair Platform functionality.
6. How to Control and Delete Cookies in Your Browser
Every major browser provides tools to view, block, and delete cookies. Instructions for the most common browsers:
Google Chrome
- Click the three-dot menu (⋮) in the top-right corner
- Go to Settings > Privacy and security > Cookies and other site data
- To delete all cookies: click See all site data and permissions > Delete all
- To delete cookies for sparkd.social only: search for “sparkd.social” in the search box and click the delete icon
Full guide: support.google.com/chrome/answer/95647
Mozilla Firefox
- Click the hamburger menu (☰) in the top-right corner
- Go to Settings > Privacy & Security
- Scroll to Cookies and Site Data and click Clear Data
- To manage specific site cookies: click Manage Data and search for “sparkd.social”
Full guide: support.mozilla.org
Apple Safari (macOS)
- Go to Safari menu > Settings (or Preferences) > Privacy
- Click Manage Website Data
- Search for “sparkd.social” and click Remove, or click Remove All to clear all cookies
Full guide: support.apple.com
Apple Safari (iOS / iPadOS)
- Open Settings app on your device
- Scroll down and tap Safari
- Tap Clear History and Website Data to clear all cookies
- For per-site control: tap Advanced > Website Data, search for “sparkd” and swipe to delete
Microsoft Edge
- Click the three-dot menu (⋯) in the top-right corner
- Go to Settings > Cookies and site permissions > Manage and delete cookies and site data
- Click See all cookies and site data and search for “sparkd.social”
- Click the delete icon next to any entry to remove it
Full guide: support.microsoft.com
Note: Deleting cookies for sparkd.social will log you out of the Platform and reset your cookie consent preference. The consent banner will reappear on your next visit.
7. Complete Cookie Duration Reference
| Cookie / Key | Category | Set By | Duration |
|---|---|---|---|
sb-[project]-auth-token | Essential | Supabase | 1 hour (auto-refreshed) |
sb-[project]-auth-token-code-verifier | Essential | Supabase | Session |
__Host-next-auth.csrf-token | Essential | sparkd.social | Session |
sparkd_cookie_consent | Preference | sparkd.social | 1 year |
ph_[key]_posthog | Analytics | PostHog (consent only) | 1 year |
ph_[key]_posthog_ses | Analytics | PostHog (consent only) | 30 minutes |
_ga | Analytics | Google (consent only) | 2 years |
_ga_[ID] | Analytics | Google (consent only) | 2 years |
sentry-sc | Monitoring | Sentry | Session |
8. Third-Party Privacy Policies
Each third-party service that may set cookies through the Platform has its own privacy policy. We encourage you to review these:
- Supabase: supabase.com/privacy
- PostHog: posthog.com/privacy
- Google Analytics: policies.google.com/privacy
- Sentry: sentry.io/privacy
9. Changes to This Cookie Policy
We may update this Cookie Policy when we add new cookies, remove existing ones, or change how they are used. When we make material changes, we will update the “Last updated” date at the top of this page and notify registered users by email at least 30 days before the changes take effect. If changes affect consent requirements (e.g., a new analytics cookie is added), we will re-display the consent banner to existing users.
10. Contact
For questions about our use of cookies or to exercise your rights under Nepal’s Individual Privacy Act, 2075 in relation to cookie-derived data, please contact: