Cookies & Tracking — Fashion Brand Finder
1. The short version
Almost everything this website stores on your device exists to sign you in and keep you signed in. There is exactly one optional thing: Google Analytics, which counts visits so we can see how many people come, from where, and which pages they read. Its advertising features are switched off, we look at aggregate reports, and the site works exactly the same if you say no.
Because that one thing is optional, you get a real choice about it:
- Where the law says "ask first" — the EU/EEA, the UK, and most countries with a consent-based privacy law — a small banner asks before Google Analytics loads. Nothing optional loads before you answer, "reject" is one tap and equal to "accept", and saying no costs you nothing.
- Where the law works on notice and opt-out — the United States, Switzerland, Japan, Australia, New Zealand — it runs by default and Cookie settings in the footer turns it off in one click, which also deletes its cookies. If your browser sends the Global Privacy Control signal, we treat it as an automatic "no" and never load it at all.
- We tell the two situations apart from your device's own timezone — on your device, without asking any location service. When we cannot tell, we ask first.
What there is not: no advertising cookies, no retargeting pixels, no cross-site tracking, no device fingerprinting, and no open or click tracking in the emails we send. The website also does not run FBF's own brand-view counter — that is a mobile-app feature — so "Trending" is powered by the app, not by watching you browse here.
Who is responsible for this, and where to write: M8 Media by Manuel Bucher, Kaffeestrasse 6C, 8180 Bülach, Switzerland (CHE-203.493.947), hello@fashionbrandfinder.com. The full details are in the imprint, and what we do with personal data is in the privacy policy.
2. What is actually stored, item by item
Written from the code, not from a template. The same inventory drives the banner, the settings panel and this page — an automated test fails our build if they ever disagree.
On the website (fashionbrandfinder.com and the studio at studio.fashionbrandfinder.com)
Required — always on:
| Item | Type | What it is | Why it is necessary | How long |
|---|---|---|---|---|
sb-<project>-auth-token | First-party cookie | Your sign-in session: the tokens that prove to the server that you are you. <project> is our Supabase project reference, so you can find it in your browser's cookie list | Without it, every page load would sign you out. It only appears once you start signing in | Set to expire after 400 days. Deleted when you sign out or clear your browser |
sb-<project>-auth-token-code-verifier | First-party cookie | A short-lived random value created when you ask for a sign-in link | It makes sure the emailed link only works in the browser that asked for it | Also set to 400 days by the library, although it stops being useful the moment you finish signing in |
fbf_consent | First-party cookie | The answer you gave on the cookie banner or in Cookie settings: which categories you allowed, when, and under which version of this page | Remembering your choice is the only alternative to asking on every page. It contains a random id and your yes/no answers — nothing about you | 12 months, then we ask again |
Both sign-in cookies may be split into two (…-auth-token.0 and .1) when the value is long. That is one item stored as two pieces, not two different things.
Optional — "Statistics", only with your permission where consent is required:
| Item | Type | What it is | What it does | How long |
|---|---|---|---|---|
_ga | First-party cookie, set by Google's script | A random client id | Lets Google Analytics tell "one visitor, five pages" apart from "five visitors". Set only after the Statistics category is allowed | Up to 2 years; deleted the moment you turn Statistics off |
_ga_<container> | First-party cookie, set by Google's script | Session state for our specific Google Analytics property (the site and the studio each have their own) | Groups your page views into a visit | Up to 2 years; deleted the moment you turn Statistics off |
With Statistics allowed, page addresses you visit here are sent to Google, our processor for this purpose (Google Ireland Ltd for European visitors, with transfers to Google LLC in the USA under the EU–US Data Privacy Framework and Standard Contractual Clauses). We have switched off Google's advertising signals for these properties, we do not use the data for ads, and we read aggregate reports — pages, countries, referrers — not individual journeys. If you say no — or never answer, in a country where we must ask first — Google's script is never even loaded, and turning it off later deletes its cookies on the spot.
We do not set a cookie for a theme, an A/B test, or a language; if we ever add one, it appears in these tables first.
Your browser also talks directly to our database provider, Supabase, whose servers hold the data and serve the images. That is a connection to another company's server on every page, so we mention it — but it is our processor doing our work, it sets no storage of its own on your device, and there is no third party involved.
Web fonts are served from our own domain. The site uses Next.js's font pipeline, which downloads the font files at build time and ships them with the site. Loading a page makes no request to Google or to any other font host — Google only becomes involved at all if you allow Statistics.
In the mobile app (iOS and Android)
| Item | Type | What it is | Why | How long |
|---|---|---|---|---|
sb-<project>-auth-token | The app's own private storage | The same session token as above, kept in app storage rather than in a cookie | It is what keeps you signed in between launches | Until you sign out or delete the app |
fbf.analytics.anon-id | The app's own private storage | A random id with no link to your account, your name or your email | Lets a brand's views count one person once per day instead of counting taps — the app's Trending rail. Our servers keep only daily totals per brand, never a browsing history | Until you clear the app's storage or delete the app |
| Cached images and fonts | The app's own private cache | Copies of pictures and font files the app has already downloaded | So the app does not download the same picture twice. Not tracking, and not linked to you | Until the cache is cleared or the app is deleted |
Cookies do not really exist in a native app, so this is app storage, not a cookie — but it is the same data doing the same job. The id lives only in the app's own private storage, is never shared with anyone, and deleting the app deletes it. There is no Google Analytics in the app, no advertising identifier, no attribution SDK; the App Tracking Transparency prompt does not appear because there is nothing to ask about.
What is stored about you on our servers, so this page is complete
- Brand view counts (recorded by the mobile app only) are stored as a number against a brand and a date — for example, "brand X, 23 August, 143 views." There is no browsing history and no per-person record beyond a same-day duplicate check.
- Consent receipts. When you make an explicit choice on the banner or in Cookie settings, we record it: a random consent id (also shown to you in the panel), which categories you allowed, the date, which rulebook applied, and the version of this page. That is the proof of consent the GDPR requires us to keep. A receipt contains no IP address, no browser details, and no account id, can never be edited by staff, and is deleted automatically after 3 years.
- Paid placements are fixed time slots, bought in advance for a position and a period. They are not targeted at a person, there is no auction, no cost-per-click, and no profile. An advertiser learns that their slot ran; they never learn who saw it.
- Server logs at our hosting providers record requests for security and fault diagnosis in the ordinary way. See the privacy policy for who those providers are.
Full detail is in the privacy policy.
3. When we ask first, and where an off switch is enough
Two families of law, two behaviours — this is exactly what the site's code does:
Ask-first countries. In the EU/EEA the ePrivacy Directive (Art 5(3)) requires consent before anything is stored on or read from your device unless it is strictly necessary for a service you asked for. Keeping you signed in after you asked to sign in is exempt; analytics is not, so Google's script waits for your yes. The UK (PECR), Brazil (LGPD), Quebec (Law 25) and most newer privacy laws work the same way — and so does our default whenever we cannot tell where you are.
Notice-and-opt-out countries. Switzerland (nDSG/FMG Art 45c, and the FDPIC's cookie guidance) and the United States' state privacy laws do not require an "ask first" banner for analytics; they require honest information and a real, immediate way to refuse. This page is the information; Cookie settings in the footer of every page is the refusal, one click, no account needed. Several US states also give legal force to the browser's Global Privacy Control signal — we honour it everywhere as an automatic no. Japan, Australia and New Zealand are handled the same way.
What we never do, anywhere: pre-ticked boxes, "by continuing you agree", consent walls, or a reject button hidden behind a settings screen.
4. Turning it off
- Website: Cookie settings in the footer opens the same panel the banner uses — flip Statistics off and Google's cookies are deleted on the spot, and its script is not loaded again. Your sign-in cookies you remove by signing out, or by clearing cookies for fashionbrandfinder.com in your browser settings.
- Browser-wide: turn on Global Privacy Control (built into several browsers and extensions) and we treat it as a standing no.
- Mobile app: sign out, or delete the app.
Blocking everything is fine — you simply cannot stay signed in, and the public pages keep working without an account.
5. What would change this
| Change | Why it changes the answer | What it then needs |
|---|---|---|
| FBF's own view counting on the website | Deliberately removed (23 August 2026): the website's directory does not feed Trending. Bringing it back means storing another id on visitors' devices | A registry entry, banner copy, and a row in §2 — the same as everything optional |
| Turning on any Google advertising feature (signals, remarketing, linked Ads) | It would turn an analytics tool into cross-site tracking, and flip Switzerland into ask-first territory too | A "Marketing" consent category, new banner copy, and a rewrite of §2's promises |
| OneSignal push notifications (planned — roadmap D5) | A push token is a persistent device identifier, and OneSignal is a third-party processor that segments audiences | OS-level notification permission and a consent record, a subprocessor entry, and a decision on whether segments count as profiling |
| Marketing attribution, install referrers, ad SDKs, retargeting pixels | Straightforwardly non-necessary, and on iOS pulls in App Tracking Transparency | A "Marketing" category in the consent registry, ATT prompt, App Store privacy-label changes |
| Embedded third-party content (Instagram or TikTok embeds, YouTube, a map iframe) | The embed sets its own storage the moment it loads, before we can ask | Click-to-load placeholders, or a consent-gated category |
Rule of thumb for whoever ships next: if it stores or reads anything on the device that is not the sign-in token, it goes into the consent registry first (apps/web/src/lib/consent/registry.ts) — the banner, the settings panel and this page all read that one list, and a build test fails if this page does not name every stored item in it.
6. Changes to this page
If we add anything to the inventory in §2, we publish an updated version of this page, dated, before the new thing loads — and where consent is needed we ask you first. Bumping the consent policy version makes every stored choice expire, so the banner asks again rather than stretching an old yes over a new question. Each version is dated so you can see what changed.
If you are under 16, some countries require a parent's agreement before you can consent to anything optional. The only optional thing here is visit counting, but the same country rule described in the privacy policy §7 applies, and we will not treat a child's tap as consent where the law does not.