Cookie Policy
Version 1.1-draft · Effective date: [EFFECTIVE DATE]
Template — not yet legally reviewed. The cookie and service tables below are generated from our internal registry; the surrounding text is a starting template and must be reviewed by a qualified legal professional before publication.
This Cookie Policy explains how [OPERATOR NAME] uses cookies and similar technologies on this website. Strictly necessary cookies are always active; all other categories load only after you consent. You can change or withdraw your choices at any time via “Cookie settings” in the footer.
1. Cookies we may use
| Name | Provider | Category | Purpose | Expiry | Party | Consent |
|---|
| sf_refresh | SkinFactory (this site) | necessary | Keeps you signed in by holding the rotating refresh token (httpOnly, not readable by scripts). | 14 days | First-party | Not required |
| sf_consent | SkinFactory (this site) | necessary | Stores your cookie choices and consent version so we do not ask again unnecessarily. | 12 months | First-party | Not required |
| sf_nav_open_groups (local storage) | SkinFactory (this site) | functional | Remembers which navigation sections you left open. | Until cleared | First-party | Required |
| sf_sound / UI preferences (local storage) | SkinFactory (this site) | functional | Remembers sound on/off and other interface preferences. | Until cleared | First-party | Required |
| [ad-network-dependent] | Advertising network (admin-configured) | marketing | Set by the third-party ad-network snippet for ad delivery, frequency capping and measurement. Specific cookie names cannot be enumerated until a concrete ad network is configured; none are set by default. | [ad-network-dependent] | Third-party | Required |
2. Services & processors
| Service | Provider | Category | Purpose | Location | Consent |
|---|
| ByMykel CSGO-API | ByMykel (open-source, MIT License) | necessary | Source of item names, images and metadata used to build the virtual catalog. Fetched server-side only. | GitHub-hosted static data, fetched by our server. | Not required |
| OpenAI API | OpenAI | necessary | Server-side text generation for admin content authoring (theme/name suggestions). Triggered by admins only. | United States (OpenAI) | Not required |
| Recraft | Recraft | necessary | Server-side image generation for admin-created content. Triggered by admins only. | United States (Recraft) | Not required |
| fal.ai | fal.ai | necessary | Server-side depth/ControlNet image generation for admin-created content. Triggered by admins only. | United States (fal.ai) | Not required |
| Stripe | Stripe, Inc. | necessary | Payment processing for real-money products: the VIP monthly recurring subscription and one-time XP Boost purchases. Also provides the Stripe-hosted Billing Portal (update card, view invoices, cancel). In-game balance and items are virtual with no cash value and are never handled by Stripe. | United States (Stripe, Inc.) | Not required |
| SMTP email provider (admin-configured) | [SMTP PROVIDER — admin-configured] | necessary | Delivery of transactional email only: account email verification and password-reset messages. When SMTP is not configured the link is logged server-side instead of sent (optional-degrade). No marketing or newsletter email is sent. | [PLACEHOLDER — depends on the SMTP host/relay the admin configures] | Not required |
| Advertising network (admin-configured) | [AD NETWORK — admin-configured] | marketing | Display advertising. Admin-authored ad-network HTML/JavaScript snippets are injected client-side into placement slots (sidebar / top banner / in-content) for non-VIP users when the ads flag is on. No ad network is wired by default (seeded slots are empty). | [PLACEHOLDER — depends on the ad network the admin configures] | Required |
3. Third-party cookies
When you grant marketing consent and the advertising feature is enabled, third-party advertising cookies may be set in your browser by the configured ad network. These cookies are placed and read by the ad network itself — not by us — typically for ad delivery, frequency capping and measurement, and they are only active for non-VIP users after marketing consent is given. No ad network is configured by default, so no such cookies are set until one is in place; the specific cookie names depend on the ad network and are listed as network-dependent in the table above.
We also use Stripe to process real-money payments (the VIP monthly subscription and one-time XP Boost purchases). Checkout is fully redirect-based: you are sent to Stripe’s own hosted payment page, so Stripe sets no cookies on this website’s origin. Any Stripe cookies (for example fraud-prevention and session cookies such as __stripe_mid and __stripe_sid) are set on Stripe’s own hosted-checkout domain and are governed by Stripe’s privacy and cookie policies.
4. Managing your choices
Use “Cookie settings” in the footer to allow or reject categories at any time. Rejecting a category stops the related scripts from loading and clears the related non-necessary storage. For more on how we handle personal data, see our Privacy Policy.