Cookie Policy

Last updated: 17 August 2026

The present Policy explains how STYLORY LTD uses cookies and comparable technologies on https://www.stylory.io, the categories in which they fall, the consent we seek before any non-essential technology is used, and the means by which a choice already made may be reviewed or reversed. Please read it together with the Privacy Policy, which describes what happens to the personal data obtained through these technologies once it has been collected.

1. Who We Are

1.1 STYLORY LTD is a private limited company incorporated in England and Wales under company number 17152844, with its registered office at 67 Tradescant Road, London, Lambeth, England, SW8 1XJ. We operate the website and the subscription service to which the Policy relates, and we are the controller of the personal data obtained through the technologies described below.

1.2 Questions about the Policy may be sent to dpo@stylory.io.

2. What Cookies and Similar Technologies Are

2.1 A cookie is a small text file placed on a device by a website and returned to that website on each subsequent visit. Cookies allow a site to recognise a device, to remember a preference, to keep a user logged in between pages, and to record how the site is being used.

2.2 A cookie is described as a session cookie where it is deleted when the browser is closed, and as a persistent cookie where it remains on the device until it expires or is removed. A cookie is described as first-party where it is set by the website being visited, and as third-party where it is set by another domain.

2.3 Comparable technologies achieve similar results by other means. Local storage and session storage hold information within the browser itself. Software development kits and pixels embedded in a page or an email can record that a resource has been requested. Device fingerprinting infers an identifier from the characteristics a browser reports. References in the Policy to cookies include all such technologies, since the law that governs them does not turn on the technique employed.

3. The Legal Framework We Apply

3.1 In the United Kingdom, the storage of information on a device, and access to information already stored on it, are governed by regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003. Regulation 6 was substituted with effect from 5 February 2026 by the Data (Use and Access) Act 2025, and the circumstances in which storage or access is permitted are now set out in Schedule A1 to those Regulations.

3.2 Under Schedule A1, consent is the general condition, and it is defined by reference to the standard in the UK GDPR, which requires a freely given, specific, informed, and unambiguous indication given by a clear affirmative act. Paragraph 3 permits technical storage or access carried out solely for the transmission of a communication. Paragraph 4 permits storage or access that is strictly necessary for an information society service requested by the user, which extends to security, fraud prevention, fault detection, and authentication. Paragraph 5 permits collection for statistical purposes aimed at improving the service, and paragraph 6 permits storage or access that adapts a site to a user's preferences or improves its appearance or functionality, in each case provided that clear information is given and a free means of objection is offered. Paragraph 7 concerns geolocation in response to an emergency call.

3.3 In the European Economic Area, Article 5(3) of Directive 2002/58/EC, as amended by Directive 2009/136/EC and as implemented in each Member State, requires prior informed consent for any storage or access that is not strictly necessary to provide a service explicitly requested by the user or to transmit a communication. Consent is measured against Regulation (EU) 2016/679.

3.4 Where a cookie processes personal data, the UK GDPR and the EU GDPR apply in addition, and the Privacy Policy governs that processing.

3.5 In the United States, no general consent requirement applies to cookies. State privacy statutes instead confer rights in relation to the sale of personal information, to sharing for cross-context behavioural advertising, and to targeted advertising. Our position on those activities is stated in section 8.

4. Our Approach on First Visit

4.1 A consent banner is presented when the website is first visited from a device, and again where a previous choice has expired or where the technologies in use have materially changed.

4.2 Until a choice is made, no cookie is set other than those falling within paragraph 3 or paragraph 4 of Schedule A1, namely those strictly necessary to deliver the site and to keep it secure. Non-essential technologies remain inactive.

4.3 Accepting and refusing are offered with equal prominence at the same level of the banner. Refusal requires no greater effort than acceptance, and continuing to browse, scrolling, or closing the banner is not treated as consent.

4.4 The banner describes each category, states the purpose of the technologies within it, and allows each optional category to be accepted or refused separately.

4.5 The choice made is recorded, together with the date, the version of the banner presented, and the categories accepted, so that we can demonstrate the consent obtained. Any choice may be changed at any time by the means described in section 9.

4.6 Where a category permitted under paragraph 5 or paragraph 6 of Schedule A1 is operated on the objection model now available in the United Kingdom rather than on prior consent, that fact is disclosed in the banner, and the means of objecting is provided at the same point.

5. Categories We Use

5.1 Four categories are relevant to the website, and each is described below together with the consent position that applies to it.

5.2 Strictly necessary technologies authenticate a signed-in subscriber, maintain the session across pages, balance load, protect against cross-site request forgery, support fraud prevention during payment, and record the cookie choice itself. No consent is required for them, under paragraph 4 of Schedule A1 and Article 5(3) of Directive 2002/58/EC, and they cannot be switched off without disabling the service.

5.3 Functional and appearance technologies remember preferences such as language, display density, and units of measurement, and adapt the interface accordingly. Consent is requested for them in the European Economic Area. In the United Kingdom they are permitted under paragraph 6 of Schedule A1, subject to a free right to object.

5.4 Analytics and statistical technologies measure how the website is used, which pages are visited, and where errors occur, so that the service can be improved. They are first-party only, and they remain inactive until a choice has been made. Consent is requested for them in the European Economic Area, and in the United Kingdom they are permitted under paragraph 5 of Schedule A1, subject to a free right to object.

5.5 Advertising technologies are used only on our public blog. There we display advertising supplied by Google LLC through Google AdSense, which sets cookies in order to serve advertisements, to limit the number of times a given advertisement is shown, and to detect invalid activity, and which may, where the visitor consents, personalise the advertising displayed. These technologies are non-essential. They remain inactive until the advertising category is accepted through the banner; no advertising cookie is set before that point; and no advertising is shown, and no advertising cookie is set, anywhere within the signed-in application.

5.6 We do not use Google Analytics, the Meta pixel, or third-party email-marketing trackers. Apart from the Google AdSense advertising described in section 5.5, our analytics are first-party, are gated behind the choice described in section 4, and serve only to improve the service.

6. The Individual Technologies in Use

6.1 The technologies currently set follow from the platform components in use, namely Supabase authentication, Stripe payments, Vercel hosting, first-party analytics, and, on the public blog only, Google AdSense advertising. Each is described below with its provider, its purpose, and its lifetime; the advertising cookies set by Google are described in section 5.5 and are set only where the advertising category has been accepted.

6.2 A Supabase authentication token, named in the form sb-[project reference]-auth-token, is a first-party cookie that maintains the authenticated session of a signed-in subscriber and allows the account to be reached without repeated login. It is refreshed during the session and expires on logout.

6.3 A first-party consent record stores the categories accepted or refused through the banner, so that the choice is honoured on later visits and can be evidenced. Its lifetime is twelve months.

6.4 Stripe sets two third-party cookies during payment. The first, __stripe_mid, assigns a device identifier used for fraud detection and lasts twelve months. The second, __stripe_sid, identifies the browsing session within the payment flow for the same purpose and expires after thirty minutes.

6.5 A first-party analytics identifier distinguishes one visit from another so that aggregate usage can be measured. It is set only where the analytics category is active, and its lifetime is thirteen months.

6.6 Interface preferences such as language and units are held within browser local storage rather than in a cookie, and they persist until the user clears them.

6.7 A cookie set by Stripe is set by that company in its capacity as an independent controller for fraud prevention, and its own cookie notice governs that activity.

7. Durations and Renewal of Consent

7.1 The durations stated in section 6 are maximum lifetimes. A cookie may be deleted earlier by the user, and a session cookie expires when the browser is closed.

7.2 Consent is sought again no later than twelve months after it was given, in line with the guidance of the Information Commissioner's Office and of European supervisory authorities that consent should not be treated as valid indefinitely.

7.3 Consent is also sought again where a new category is introduced, where the purpose of an existing technology changes materially, or where a new provider is engaged.

8. Cookies, Sale of Personal Information, and Opt-Out Signals

8.1 Except for the advertising described in section 5.5, no cookie or comparable technology on the website is used to sell personal information or to support cross-context behavioural advertising or targeted advertising. Where advertising is shown on the blog, our position on any sale or sharing that may result, and the statutory definitions concerned, is set out in the Privacy Policy.

8.2 Apart from the information that Google receives in order to serve advertising on the blog, no personal information obtained through the website is disclosed to an advertising network or to a data broker. Where the advertising shown is personalised, this may amount to a sale or a sharing under certain United States state laws, and a means of opting out is provided as described in section 8.3 and in the Privacy Policy.

8.3 We honour an opt-out preference signal transmitted by a browser or extension, including Global Privacy Control, as a valid request to opt out of any sale or sharing for the jurisdictions whose law so requires. A visitor may also refuse or withdraw consent to the advertising category at any time through the cookie preferences control described in section 9, which prevents any advertising cookie from being set.

8.4 Browsers that transmit a Do Not Track header are not currently acted upon, because no uniform standard for responding to that header has been adopted. Our position is instead the one stated in section 8.1, namely that the activities the header seeks to prevent are not carried out at all.

9. Changing or Withdrawing a Choice

9.1 A choice may be reviewed and changed at any time through the cookie preferences control available in the footer of every page of the website. Reopening that control displays the categories currently active, together with the date on which the present choice was made.

9.2 Withdrawing consent is as straightforward as giving it, and no charge or detriment attaches to withdrawal. Following withdrawal, the technologies in the affected category cease to operate, and any information already collected is handled in accordance with the retention periods in the Privacy Policy.

9.3 Withdrawal does not affect the lawfulness of anything done while consent was in force.

9.4 Where the objection model described in section 4.6 applies, the same control operates as the means of objecting.

10. Controlling Cookies Through the Browser

10.1 Independently of the controls we provide, most browsers allow cookies to be blocked, restricted to first-party cookies, or deleted, and offer a private-browsing mode in which cookies are discarded at the end of the session. The relevant settings are found within the privacy or security section of the browser concerned, and the browser's own help function explains their operation.

10.2 Blocking strictly necessary cookies will prevent a subscriber from signing in and will stop parts of the service from working. Blocking functional cookies will cause preferences to be forgotten between visits.

10.3 Browser settings apply to the device and browser on which they are made. A choice made in one browser does not carry across to another browser or to another device.

10.4 Deleting cookies also deletes the record of the cookie choice, and the banner will therefore be presented again on the next visit.

11. Personal Data Obtained Through Cookies

11.1 Some of the technologies described collect information that constitutes personal data, including an online identifier and an IP address. The categories collected, the purposes, the legal bases, the recipients, the international transfers, and the retention periods are set out in the Privacy Policy.

11.2 The rights described in the Privacy Policy, including access, erasure, restriction, objection, and portability, extend to personal data obtained through cookies. Requests should be sent to dpo@stylory.io.

11.3 Failure to comply with the Privacy and Electronic Communications (EC Directive) Regulations 2003 may be penalised by the Information Commissioner. Since 5 February 2026, the maximum penalty under those Regulations has been aligned with the data-protection regime, at the higher of GBP 17.5 million and 4% of total worldwide annual turnover. We record the reference in order to make clear the seriousness with which the obligations in the Policy are treated.

12. Changes to the Policy

12.1 The Policy is reviewed whenever a technology is added, removed, or materially altered, and in any event periodically.

12.2 Each revision carries a new date at the head of the document. Where a change requires fresh consent, the banner is presented again before the new technology operates.

13. How to Contact Us

13.1 Cookie and privacy enquiries: dpo@stylory.io.

13.2 General enquiries: contact@stylory.io.

13.3 Postal address: STYLORY LTD, 67 Tradescant Road, London, Lambeth, England, SW8 1XJ, United Kingdom. Registered in England and Wales under company number 17152844.