fivenines

Cookie Policy

Last updated: June 9, 2026

1. What are cookies?

Cookies are small text files stored on your device by your web browser. Similar technologies include localStorage, which stores data in your browser without an expiration date. We use both Supabase authentication cookies and browser localStorage.

2. How we use cookies & local storage

We categorize our use of cookies and local storage into three groups. Only essential storage is activated by default. Analytics and marketing storage remain off unless you explicitly opt in through the cookie banner, footer preferences, or Settings.

3. Essential storage

These are strictly necessary for the website to function and cannot be disabled.

  • Authentication session — Supabase stores session tokens to keep you signed in. Without these, you would need to log in on every page visit.
  • cookie_consent_choices — stores your cookie consent preferences (analytics and marketing choices) in localStorage so we can respect your decisions across page loads.
  • consent_receipt_id — a unique identifier stored in localStorage that links your consent choices to our server-side consent log, as required for GDPR demonstrability.

4. Analytics storage

These are only activated if you give explicit consent via the cookie banner or in Settings › Privacy & Data.

  • Mixpanel — when analytics consent is granted, Mixpanel uses localStorage persistence and the EU API endpoint to track behavioral events such as page views, tutorial progress, track usage, checkout milestones, subscription conversion status, and feature usage. Mixpanel uses a persistent device ID stored in localStorage. We do not send payment card details or raw Stripe payloads to Mixpanel. This data helps us understand how the product is used and improve features.

No analytics data is collected or transmitted before you give consent. If you withdraw consent, analytics tracking stops immediately, though previously collected data is retained by Mixpanel for up to 12 months unless you request its deletion.

5. Marketing storage

These are only activated if you give explicit consent.

  • Meta Pixel — when marketing consent is granted, Meta's tracking pixel (fbevents.js) is loaded. It sets cookies (including _fbp) and may use localStorage to measure the effectiveness of advertising campaigns, track conversions such as sign-ups, and build audiences for ad targeting on Meta platforms (Facebook, Instagram). Your user ID may be shared with Meta as an external identifier for conversion matching. No Meta tracking occurs before you give consent.
  • Marketing preferences — your marketing consent choice is stored in localStorage as part of your consent preferences. Marketing cookie consent does not subscribe you to product-update emails; newsletter signup is a separate opt-in. You can withdraw marketing cookie consent at any time.

6. Third-party cookies

We self-host our site fonts, so loading fivenines does not send a runtime font request to Google Fonts or another external font provider.

  • Mixpanel — when analytics consent is granted, Mixpanel receives analytics events, including checkout and subscription conversion milestones, and stores identifiers using localStorage in our current configuration. Payment details are not sent to Mixpanel. See Mixpanel's Privacy Policy for details.
  • Meta (Facebook) — when marketing consent is granted, Meta's Pixel sets cookies (e.g. _fbp) and loads a script from connect.facebook.net. See Meta's Privacy Policy for details.

7. Managing your preferences

You can manage your cookie and storage preferences in several ways:

  • Cookie banner — when you first visit fivenines from the EEA, UK, or Switzerland, or when we cannot determine your location, a banner appears letting you accept all, reject all, or choose specific categories. You can reopen this banner at any time by clicking “Cookie preferences” in the footer. Outside those consent markets, the banner may not appear automatically, but optional analytics and marketing tracking still remain off unless you opt in.
  • Settings page — if you have an account, visit Settings › Privacy & Data to toggle analytics and marketing consent.
  • Browser settings — you can clear localStorage and cookies through your browser settings. Note that clearing essential storage will sign you out and reset your consent preferences.

8. Consent records

When you make a consent choice, we log it to our server along with a timestamp, the banner version, source, consent-market status, country code when known, and a unique receipt ID. These records are retained for as long as needed to demonstrate consent choices under Art. 7(1) GDPR; our current implementation retains them indefinitely unless and until they can be safely deleted or aggregated. Consent records do not contain browsing data or your IP address — only your choices and when they were made.

9. Changes to this policy

If we add new cookie categories or make material changes to this policy, we will update the cookie banner and notify you so that you can review and update your preferences. The “last updated” date at the top reflects the most recent revision.

10. Contact

If you have questions about our use of cookies or local storage, contact us at team@firebricklabs.com.