Legal · draft for review

Cookie Policy.
What is actually set, and why.

Cookies and similar technologies the platform sets, scoped to what a fresh Vantly deploy actually uses. This is a first-pass draft — not final, counsel-approved text.

Draft banner.

This page is a draft produced for the operator to review before general access. The disclosure should be reviewed and finalized alongside the Privacy Policy by qualified counsel familiar with the e-privacy rules in the jurisdictions where Vantly operates.

01

What cookies are and why we use them.

A cookie is a small piece of data placed by a website on the device you use to visit it. Cookies and similar technologies (local storage, session storage, and similar) are how the platform recognises you between requests, keeps you signed in, and remembers platform-level preferences.

Some cookies are essential for the platform to operate. Without them, sign-in, age verification state, and basic content delivery would not work.

Other cookies are non-essential: they are used for analytics, for remembering preferences, or for measuring the reach of platform communications. We keep non-essential cookies in a separate category so they can be opted out of without breaking the platform.

02

What we set on a fresh deploy.

Vantly ships a small, deliberate set of cookies on a fresh deploy. The categories and the purpose of each are described below — and only what is actually present is described here.

Essential cookies — session and authentication cookies set when a user signs in. These cookies are set by the platform itself and are required for the platform to operate. They are not used for advertising and they are not shared with third parties.

Analytics cookies — the deploy-injected platform analytics slug fires only when the slug is set at deploy time. Cookies in this category are used to attribute traffic to a session and to understand the platform’s reach. They are surfaced through the consent flow before they are set.

No marketing cookies on a fresh deploy. The platform does not run marketing-tracking pixels on first-party pages, does not place retargeting cookies, and does not share first-party identifiers with advertising third parties.

03

Third-party cookies.

Some of the cookies set on a Vantly session are set by third parties — payment processors, the verification vendor, the infrastructure provider. The categories below are the third-party cookies a deploy may set.

Payment-processor cookies — set by the payment processors in the adult-friendly processor stack. These cookies enable transaction routing on the same domain and are required for the platform to process payments. They are not used for the processors’ own advertising.

Verification-vendor cookies — set by the identity and age verification vendor during onboarding. They are scoped to the verification flow and are not used by the vendor for any other purpose.

Infrastructure-provider cookies — where the infrastructure provider sets cookies through CDN or security features, those cookies are described in the platform’s published security statement.

04

Opting out and controlling cookies.

You can control cookies in the platform’s cookie preferences surface, in your browser’s cookie settings, and through the do-not-track signal. Each of those is described in this section.

In the platform — the cookie preferences surface lets you opt out of non-essential categories (analytics) without affecting essential cookies. The preferences surface is opened from the cookie banner or from the footer.

In your browser — every modern browser lets you block or delete cookies, with controls typically under Settings → Privacy or Settings → Cookies. Blocking all cookies will break parts of the platform; blocking non-essential categories keeps the platform usable while suppressing the categories you have opted out of.

Mobile-device controls — iOS and Android expose advertising-identifier controls that limit cross-app tracking. The platform does not currently use mobile advertising identifiers, but where the underlying operating system exposes a privacy signal it is respected.

05

Do-not-track and global privacy control.

The platform respects browser-level do-not-track signals and the global privacy control signal where the relevant browser exposes them. The handling of those signals is described in this section.

Do-not-track — the platform treats an enabled do-not-track signal as an opt-out of non-essential cookies. Essential cookies (session, authentication) are still set so sign-in can work.

Global privacy control — the platform treats an enabled global privacy control signal as a privacy opt-out signal in line with the relevant regulations. Where local law requires a defined response to a privacy signal, the platform’s response matches the local-law definition.

06

How long cookies last.

Cookies on the platform have lifetime bounded by purpose. Essential cookies are session-scoped where possible; analytics cookies are scoped to the platform’s analytics window. The exact lifetime of each cookie is described below.

Essential session cookies are scoped to the session — they are deleted when you close the browser, except where the platform has a documented reason to retain them longer (for example, "remember me" on sign-in, which uses a longer-lived cookie bound to the account).

Analytics cookies are scoped to the analytics window set by the deploy-injected analytics slug (typically weeks to months). They are renewed on each visit and expire after the configured window.

Third-party cookies are scoped by the third-party process that set them. Where a third-party cookie lifetime is longer than what the third party’s own policies would suggest, the cookie is removed on session validation or on opt-out.

07

Changes to this policy.

We may update this policy as the platform’s cookie surface evolves. Material changes (a new category of cookies, a change in the analytics provider) are flagged prominently inside the platform.

Non-material changes (clarifications, contact details, lifetime tweaks) do not trigger a separate notification. The current version is always the one published at this URL.

Material changes (a new category of cookies, a change in the analytics provider, a change to the opt-out flow) are communicated through the cookie preferences surface and, where appropriate, by email.

08

Contact.

For questions about the platform’s cookie surface, write to the inbox below. Mark the subject line clearly so the message is routed correctly.

Cookie-policy questions: trovewell-we9yit@polsia.app. Mark the subject line with a short description of the topic.

For data-handling questions, see the Privacy Policy. For terms-of-service questions, see the Terms of Service.

trovewell-we9yit@polsia.app

This document is published in good faith as a first-pass draft. Specific clauses should be reviewed and adapted by qualified counsel before the platform is opened to general access.

See also the Privacy Policy, the 2257 compliance statement, and the Terms of Service.