Fashion Brand Finder

Legal

Cookies & Tracking — Fashion Brand Finder

1. The short version

Almost everything this website stores on your device exists to sign you in and keep you signed in. There is exactly one optional thing: Google Analytics, which counts visits so we can see how many people come, from where, and which pages they read. Its advertising features are switched off, we look at aggregate reports, and the site works exactly the same if you say no.

Because that one thing is optional, you get a real choice about it:

What there is not: no advertising cookies, no retargeting pixels, no cross-site tracking, no device fingerprinting, and no open or click tracking in the emails we send. The website also does not run FBF's own brand-view counter — that is a mobile-app feature — so "Trending" is powered by the app, not by watching you browse here.

Who is responsible for this, and where to write: M8 Media by Manuel Bucher, Kaffeestrasse 6C, 8180 Bülach, Switzerland (CHE-203.493.947), hello@fashionbrandfinder.com. The full details are in the imprint, and what we do with personal data is in the privacy policy.

2. What is actually stored, item by item

Written from the code, not from a template. The same inventory drives the banner, the settings panel and this page — an automated test fails our build if they ever disagree.

On the website (fashionbrandfinder.com and the studio at studio.fashionbrandfinder.com)

Required — always on:

ItemTypeWhat it isWhy it is necessaryHow long
sb-<project>-auth-tokenFirst-party cookieYour sign-in session: the tokens that prove to the server that you are you. <project> is our Supabase project reference, so you can find it in your browser's cookie listWithout it, every page load would sign you out. It only appears once you start signing inSet to expire after 400 days. Deleted when you sign out or clear your browser
sb-<project>-auth-token-code-verifierFirst-party cookieA short-lived random value created when you ask for a sign-in linkIt makes sure the emailed link only works in the browser that asked for itAlso set to 400 days by the library, although it stops being useful the moment you finish signing in
fbf_consentFirst-party cookieThe answer you gave on the cookie banner or in Cookie settings: which categories you allowed, when, and under which version of this pageRemembering your choice is the only alternative to asking on every page. It contains a random id and your yes/no answers — nothing about you12 months, then we ask again

Both sign-in cookies may be split into two (…-auth-token.0 and .1) when the value is long. That is one item stored as two pieces, not two different things.

Optional — "Statistics", only with your permission where consent is required:

ItemTypeWhat it isWhat it doesHow long
_gaFirst-party cookie, set by Google's scriptA random client idLets Google Analytics tell "one visitor, five pages" apart from "five visitors". Set only after the Statistics category is allowedUp to 2 years; deleted the moment you turn Statistics off
_ga_<container>First-party cookie, set by Google's scriptSession state for our specific Google Analytics property (the site and the studio each have their own)Groups your page views into a visitUp to 2 years; deleted the moment you turn Statistics off

With Statistics allowed, page addresses you visit here are sent to Google, our processor for this purpose (Google Ireland Ltd for European visitors, with transfers to Google LLC in the USA under the EU–US Data Privacy Framework and Standard Contractual Clauses). We have switched off Google's advertising signals for these properties, we do not use the data for ads, and we read aggregate reports — pages, countries, referrers — not individual journeys. If you say no — or never answer, in a country where we must ask first — Google's script is never even loaded, and turning it off later deletes its cookies on the spot.

We do not set a cookie for a theme, an A/B test, or a language; if we ever add one, it appears in these tables first.

Your browser also talks directly to our database provider, Supabase, whose servers hold the data and serve the images. That is a connection to another company's server on every page, so we mention it — but it is our processor doing our work, it sets no storage of its own on your device, and there is no third party involved.

Web fonts are served from our own domain. The site uses Next.js's font pipeline, which downloads the font files at build time and ships them with the site. Loading a page makes no request to Google or to any other font host — Google only becomes involved at all if you allow Statistics.

In the mobile app (iOS and Android)

ItemTypeWhat it isWhyHow long
sb-<project>-auth-tokenThe app's own private storageThe same session token as above, kept in app storage rather than in a cookieIt is what keeps you signed in between launchesUntil you sign out or delete the app
fbf.analytics.anon-idThe app's own private storageA random id with no link to your account, your name or your emailLets a brand's views count one person once per day instead of counting taps — the app's Trending rail. Our servers keep only daily totals per brand, never a browsing historyUntil you clear the app's storage or delete the app
Cached images and fontsThe app's own private cacheCopies of pictures and font files the app has already downloadedSo the app does not download the same picture twice. Not tracking, and not linked to youUntil the cache is cleared or the app is deleted

Cookies do not really exist in a native app, so this is app storage, not a cookie — but it is the same data doing the same job. The id lives only in the app's own private storage, is never shared with anyone, and deleting the app deletes it. There is no Google Analytics in the app, no advertising identifier, no attribution SDK; the App Tracking Transparency prompt does not appear because there is nothing to ask about.

What is stored about you on our servers, so this page is complete

Full detail is in the privacy policy.

3. When we ask first, and where an off switch is enough

Two families of law, two behaviours — this is exactly what the site's code does:

Ask-first countries. In the EU/EEA the ePrivacy Directive (Art 5(3)) requires consent before anything is stored on or read from your device unless it is strictly necessary for a service you asked for. Keeping you signed in after you asked to sign in is exempt; analytics is not, so Google's script waits for your yes. The UK (PECR), Brazil (LGPD), Quebec (Law 25) and most newer privacy laws work the same way — and so does our default whenever we cannot tell where you are.

Notice-and-opt-out countries. Switzerland (nDSG/FMG Art 45c, and the FDPIC's cookie guidance) and the United States' state privacy laws do not require an "ask first" banner for analytics; they require honest information and a real, immediate way to refuse. This page is the information; Cookie settings in the footer of every page is the refusal, one click, no account needed. Several US states also give legal force to the browser's Global Privacy Control signal — we honour it everywhere as an automatic no. Japan, Australia and New Zealand are handled the same way.

What we never do, anywhere: pre-ticked boxes, "by continuing you agree", consent walls, or a reject button hidden behind a settings screen.

4. Turning it off

Blocking everything is fine — you simply cannot stay signed in, and the public pages keep working without an account.

5. What would change this

ChangeWhy it changes the answerWhat it then needs
FBF's own view counting on the websiteDeliberately removed (23 August 2026): the website's directory does not feed Trending. Bringing it back means storing another id on visitors' devicesA registry entry, banner copy, and a row in §2 — the same as everything optional
Turning on any Google advertising feature (signals, remarketing, linked Ads)It would turn an analytics tool into cross-site tracking, and flip Switzerland into ask-first territory tooA "Marketing" consent category, new banner copy, and a rewrite of §2's promises
OneSignal push notifications (planned — roadmap D5)A push token is a persistent device identifier, and OneSignal is a third-party processor that segments audiencesOS-level notification permission and a consent record, a subprocessor entry, and a decision on whether segments count as profiling
Marketing attribution, install referrers, ad SDKs, retargeting pixelsStraightforwardly non-necessary, and on iOS pulls in App Tracking TransparencyA "Marketing" category in the consent registry, ATT prompt, App Store privacy-label changes
Embedded third-party content (Instagram or TikTok embeds, YouTube, a map iframe)The embed sets its own storage the moment it loads, before we can askClick-to-load placeholders, or a consent-gated category

Rule of thumb for whoever ships next: if it stores or reads anything on the device that is not the sign-in token, it goes into the consent registry first (apps/web/src/lib/consent/registry.ts) — the banner, the settings panel and this page all read that one list, and a build test fails if this page does not name every stored item in it.

6. Changes to this page

If we add anything to the inventory in §2, we publish an updated version of this page, dated, before the new thing loads — and where consent is needed we ask you first. Bumping the consent policy version makes every stored choice expire, so the banner asks again rather than stretching an old yes over a new question. Each version is dated so you can see what changed.

If you are under 16, some countries require a parent's agreement before you can consent to anything optional. The only optional thing here is visit counting, but the same country rule described in the privacy policy §7 applies, and we will not treat a child's tap as consent where the law does not.