Cookie Policy Icon

Cookie Policy — Smoothie Architect

This page explains, in plain language, how Smoothie Architect ("we", "us") uses cookies and similar technologies across our website, web app, APIs, and mobile apps (the "Service"). For broader privacy details (e.g., your rights, data transfers), see our Privacy Policy.

Effective date: Sept 6, 2025Last reviewed: Sept 6, 2025

Quick Summary (layered notice)

  • We use strictly necessary cookies/SDKs to sign you in, keep sessions secure, and run core features.
  • We use functional storage for preferences (e.g., language, theme, filters) to make the app nicer to use.
  • We use analytics (GA4) to understand usage and improve performance. These are optional and controlled by your consent where required by law.
  • We do not use advertising pixels for cross‑context behavioral ads.

Key Details

  • Cookies are small text files placed on your device by a website. They can be “session” (deleted when you close the browser) or “persistent”.
  • LocalStorage/SessionStorage store data in your browser for speed and convenience.
  • Service Worker caches store static files so pages load faster.
  • SDK identifiers in our web/mobile apps (e.g., Firebase, Google Analytics) generate pseudonymous IDs to provide functionality and analytics.

4) Categories and purposes we use

  • Purpose: authentication; session security; fraud prevention; load balancing; basic routing and availability.
  • Examples: sign‑in tokens, CSRF protection cookies, Stripe fraud prevention tokens.
  • Impact if disabled: the Service will not function correctly.

5) Representative cookie & storage list

Names and lifetimes may change as providers update their services. We review and refresh this list regularly.

ProviderDomainExample namesPurposeCategoryTypeTypical retentionOpt-out/info
Smoothie Architect.smoothiearchitect.comsa_session, sa_csrf, sa_locale, sa_themeSign‑in/session; CSRF; language/theme prefsStrictly necessary / FunctionalFirst‑partySession to 12 months
Firebase (Google).smoothiearchitect.com__session (cookie), firebase:authUser:* (LocalStorage), firebase:previous_websocket_failureAuth session; routing; stability flagsStrictly necessary / PerformanceFirst-party SDKSession or persistent until sign-out/clearGoogle Privacy Policy
Stripe.stripe.com, .stripe.network__stripe_mid, __stripe_sidFraud prevention & checkoutStrictly necessary (for payments)Third-party__stripe_mid ~1 year, __stripe_sid ~30 minStripe docs; manage via browser settings
Google Analytics 4.smoothiearchitect.com_ga, _ga_*, _gidUsage analytics (pages/screens, events, device/browser)Analytics (consent‑based)First-party_ga/_ga_* up to 2 years; _gid 24hOpt-out add-on
App preferencesdevice storagefavorites, lastViewed, filter settings (LocalStorage)Faster access to your own preferencesFunctionalFirst-partyUntil cleared by you/app

Notes

  • During embedded or redirected Stripe Checkout, Stripe may set additional cookies on its own domains solely to operate payment and prevent fraud. We do not control Stripe’s cookie names or durations.
  • Service worker caches may store static files (images, scripts) to improve performance; you can clear these in your browser.

6) Your choices & how to manage cookies

A) Consent banner & preferences

In regions that require it, we only set non‑essential (Functional/Analytics) cookies after you consent.

B) Browser & device controls

Block or delete cookies in your browser settings. Blocking strictly necessary cookies breaks sign‑in and core features. Clear LocalStorage/Service Worker caches via your browser.

Mobile apps: use your OS privacy settings to reset ad IDs and limit tracking (we do not use ad IDs for behavioral ads).

C) Google Analytics controls

Install Google’s opt‑out browser add‑on: https://tools.google.com/dlpage/gaoptout?hl=en

Read Google’s Privacy Policy: https://policies.google.com/privacy

D) Global Privacy Control (GPC) & Do Not Track (DNT)

We recognize GPC signals where required by law; when detected in applicable regions, we treat analytics as opt‑out by default.

We do not currently respond to legacy DNT signals; please use the controls above.

7) Data retention, international transfers & safeguards

Cookie lifetimes are listed above. GA4 event retention is typically 14 months.

Processing may occur in Canada, the U.S., the EEA, and other regions where our providers operate. We use appropriate safeguards (e.g., Standard Contractual Clauses) where required. See our Privacy Policy for details.

We also retain records of your consent selections as required by law.

8) Keeping this page up to date

We review this policy and our cookie inventory regularly—especially when we add features or vendors. When changes are material, we’ll notify you (e.g., banner or in‑app message). The Effective date and Last reviewed dates are shown at the top, and previous versions are archived.

9) Contact us

Questions about this Cookie Policy or your choices? Email support@smoothiearchitect.com (Attention: Privacy Officer / Cookies)