What Are Cookies
Cookies are small data files stored on your device by your browser when you visit a website. We also use similar technologies such as local storage, session storage, and web beacons (collectively "cookies" in this policy).
Categories We Use
- Strictly necessary: authentication tokens, session identifiers, CSRF protection, and load balancing. The Service cannot function without these; you cannot opt out and remain logged in.
- Functional / preference: remember display preferences, onboarding progress, and last-visited pages.
- Analytics / performance: aggregated usage measurement, error monitoring, and performance diagnostics via our hosting and analytics providers.
- Payment: Stripe sets its own cookies during checkout for fraud detection and 3-D Secure. These are governed by Stripe's cookie policy.
- Affiliate attribution: when you click an affiliate link (including Travelpayouts partners), the destination network may set attribution cookies subject to its own policy.
We do not use advertising or cross-site behavioral advertising cookies.
Third-Party Cookies
Some cookies are set by third parties we integrate with, including Stripe (payments), Supabase (auth/session), Google (OAuth, fonts, analytics if enabled), and affiliate networks. Their use is governed by their own privacy and cookie policies.
Consent & Google Consent Mode v2
On your first visit every optional cookie is denied by default. We implement Google Consent Mode v2, which means Google Analytics 4 and any tag managed through Google Tag Manager start in a cookieless state — the signals ad_storage, ad_user_data, ad_personalization, analytics_storage, and personalization_storage are set to denied before any tag loads. Only security_storage and functionality_storage (login, session, checkout) are granted, because the Service cannot run without them.
When you choose in the banner, we store your decision — and the date of it — in a first-party cookie named ee_consent for 180 days, then send a consent update to Google so tags may set cookies for the categories you allowed. Microsoft Clarity session replay loads only after analytics consent. We also enable ads_data_redaction and url_passthrough so measurement without consent stays non-identifying.
Managing Cookies
You can change or withdraw your consent at any time using the link — available here and in the footer of every page. You can also control or delete cookies through your browser settings. Blocking strictly-necessary cookies will break login, checkout, and generation features.
We honor Global Privacy Control (GPC): if your browser sends a GPC or Do-Not-Track signal, we record a reject-all decision automatically and never show the banner.
Contact
Questions? Email hello@empireexperience.org.