Legal

Cookie Policy

This page explains the cookies and similar browser storage StaySorted uses so you can create an account, stay signed in and use the service.

Effective: 19 September 2026 · Last updated: 19 September 2026

Related documents: Privacy Policy and Terms of Service.

1. What this policy covers

This Cookie Policy describes cookies and similar technologies used on StaySorted, including the website at staysorted.ie and the signed-in application.

It should be read with the Privacy Policy and the Terms of Service. StaySorted is not cookie-free: authentication needs cookies or equivalent browser storage to keep you signed in.

2. What cookies are

Cookies are small text files that a website can store in your browser. They let the site recognise a later visit or keep information needed for a feature you asked for, such as remaining signed in.

  • Session cookies usually last only until you close the browser.
  • Persistent cookies stay until their expiry date or until you delete them.
  • First-party cookies are set for the StaySorted domain.
  • Third-party cookies are set by another service or domain, such as a payment page.

3. Similar technologies

Websites may also use local storage, session storage, authentication tokens, or pixels. StaySorted currently does not use advertising pixels or behavioural-tracking technologies.

Local storage and session storage are not technically cookies. They can still be treated similarly under privacy and ePrivacy rules where they store or access information on your device.

StaySorted uses first-party cookies for authentication and some first-party local storage for sign-in and interface preferences. No session storage was found in the current application.

4. Why StaySorted uses cookies

StaySorted currently uses cookies or equivalent storage only where necessary or functional, for purposes such as:

  • registering and authenticating users through Supabase;
  • keeping you securely signed in;
  • remembering an authenticated session;
  • protecting accounts and preventing misuse;
  • completing subscription checkout on Stripe;
  • remembering the “Remember me” sign-in choice;
  • remembering whether shopping or bills insights are shown on those pages.

StaySorted does not currently use cookies for analytics, advertising, profiling or cross-site tracking.

5. Strictly necessary cookies

Strictly necessary cookies are required for core functions of StaySorted. They cannot normally be switched off through a StaySorted consent control, and StaySorted does not currently show a cookie banner because it does not set optional analytics or advertising cookies.

Those functions include:

  • authentication and session management;
  • account security and request validation;
  • subscription checkout, when you choose to pay through Stripe.

Blocking these cookies in your browser may prevent signup, login, remaining signed in, secure account access or checkout. Strictly necessary cookies do not need optional consent where they are genuinely essential to provide a service you requested. StaySorted does not treat convenience, analytics or advertising cookies as strictly necessary.

6. Supabase authentication cookies

StaySorted uses Supabase Authentication, through @supabase/ssr, to register users and keep them signed in. The session is stored in first-party cookies so the browser and the server can read it.

The cookie name is generated from the Supabase project hostname and follows this pattern. Chunked cookies are pieces of the same session, not separate tracking tools.

Supabase authentication cookies
Name or patternProviderPurposeFirst- or third-partySession or persistentDurationCategory
sb-<project-reference>-auth-tokenStaySorted / SupabaseStores the signed-in session so you can use the accountFirst-partyPersistentConfigured max-age of 400 days in @supabase/ssr, unless you sign out or the cookie is deleted. The access token inside the session is refreshed while the cookie remains.Strictly necessary
sb-<project-reference>-auth-token.0 and further numbered chunks such as .1StaySorted / SupabaseHolds further parts of the same session when the value is too large for one cookieFirst-partyPersistentSame 400-day library max-age as the main session cookieStrictly necessary
sb-<project-reference>-auth-token-code-verifier and related PKCE keys such as -flow-<id>-code-verifier and -flows-code-verifierStaySorted / SupabaseCompletes secure sign-in flows, including Google sign-in and email confirmationFirst-partyTemporary for the sign-in flow; removed when the flow finishesWritten with the same library cookie options; intended to be cleared after the sign-in exchangeStrictly necessary

StaySorted does not publish the live project reference in this policy. The cookies are set for the StaySorted site, with path / and SameSite=Lax. The application does not set a custom cookie name or a shorter max-age.

7. Functional and preference storage

The application stores a small number of first-party preferences. These are not analytics or advertising tools.

Functional and preference storage
NameProviderPurposeStorage typeDurationConsent
homelyt-remember-meStaySortedRemembers whether you chose “Remember me” on sign-inLocal storageUntil you change the setting, sign out in a way that clears it, or clear site dataNot collected separately. Used because you chose a sign-in preference.
homelyt-session-onlyStaySortedMarks the browser session when “Remember me” is switched off, so StaySorted can sign you out after the browser is closedFirst-party cookie (Path=/; SameSite=Lax; no Max-Age)Session cookie: it is removed when the browser session ends. It is deleted immediately if you switch Remember me on.Not collected separately. Used to apply the sign-in preference you chose.
homelyt-shopping-insightsStaySortedRemembers whether spending insights are shown on ShoppingLocal storageUntil you change the toggle or clear site dataNot collected separately. First-party interface preference only.
homelyt-bills-insightsStaySortedRemembers whether spending insights are shown on BillsLocal storageUntil you change the toggle or clear site dataNot collected separately. First-party interface preference only.

“Remember me” does not change the 400-day max-age of the Supabase session cookie. If you leave Remember me on, the session cookie can persist. If you switch it off, StaySorted sets the session cookie above and signs you out after the browser is restarted.

8. Stripe cookies

If you subscribe to StaySorted Full or manage billing, you are sent to Stripe-controlled checkout or billing-portal pages. StaySorted does not embed Stripe’s payment form on staysorted.ie and does not set Stripe cookies on the StaySorted domain.

Stripe may set cookies or similar technologies for:

  • fraud prevention and security;
  • payment processing and checkout;
  • remembering payment-session information.

Cookies set on Stripe-controlled domains are governed by Stripe’s own policies, not by this inventory:

Stripe cookies are not StaySorted advertising cookies. StaySorted does not copy Stripe’s full cookie list here.

9. Vercel hosting cookies

StaySorted is hosted on Vercel. The application code does not set Vercel Analytics cookies, and Vercel Analytics is not installed.

Some Vercel preview or deployment-protection cookies may appear on protected preview deployments. Those are not expected for ordinary visitors to the public production site and are not listed as standard StaySorted production cookies.

10. Analytics and advertising

StaySorted currently does not use:

  • analytics cookies;
  • advertising cookies;
  • behavioural profiling or cross-site tracking;
  • Google Analytics or Vercel Analytics;
  • Hotjar, Microsoft Clarity, LogRocket, Sentry, Meta Pixel, TikTok Pixel or similar tools.

If analytics, advertising or other non-essential technologies are added later, this Cookie Policy will be updated, an appropriate consent tool will be put in place before those technologies are switched on, non-essential cookies will stay off until you give valid consent, and you will be able to withdraw consent as easily as you gave it.

StaySorted does not show an “Accept all” or “Reject all” banner while there are no non-essential cookies to control.

  • Strictly necessary cookies are used because they are required to provide a service you requested or to secure that service.
  • StaySorted does not ask for optional consent for those genuinely necessary cookies.
  • Consent will be requested before any future analytics, advertising or other non-essential cookies are used.
  • Consent must be freely given, specific, informed and unambiguous.
  • Rejecting optional cookies must not block the Basic service unless the cookie is genuinely required for a feature you asked for.
  • Withdrawal of consent must be as easy as giving it.

StaySorted does not treat continued browsing, a pre-ticked box or silence as consent.

12. Managing cookies

You can view, delete or block cookies, clear site data, or use private browsing in your browser settings. Browser menus change over time, so use the publisher’s current help pages:

Blocking strictly necessary cookies may prevent:

  • account creation;
  • login;
  • remaining signed in;
  • secure account access;
  • subscription checkout;
  • other essential functions.

13. Retention

How long a cookie or storage item lasts depends on its purpose. The durations above are the ones configured or observed in the current StaySorted code and in @supabase/ssr.

The Supabase session cookie is not session-only. The library sets a persistent max-age of 400 days. How long you actually stay signed in also depends on Supabase Auth session and refresh-token settings in the project, and on whether you use Remember me.

Preference items in local storage stay until you change them or clear site data. The Remember me session cookie lasts only for the browser session.

14. Cookie inventory

14.1 Strictly necessary cookies

Strictly necessary cookies
Name or patternProviderPurposeCategoryStorage typeDurationFirst- or third-party
sb-<project-reference>-auth-token and numbered chunksStaySorted / SupabaseKeep you signed inStrictly necessaryCookie400-day configured max-age, or until sign-out or deletionFirst-party
sb-<project-reference>-auth-token-code-verifier and related PKCE keysStaySorted / SupabaseComplete a secure sign-in exchangeStrictly necessaryCookieRemoved after the sign-in flow; written with the same library cookie optionsFirst-party

14.2 Functional or preference cookies

Functional or preference cookies
NameProviderPurposeCategoryStorage typeDurationFirst- or third-party
homelyt-session-onlyStaySortedApply a session-only sign-in when Remember me is offFunctionalCookieBrowser session, or deleted if Remember me is switched onFirst-party

14.3 Third-party payment cookies

StaySorted does not set payment cookies on staysorted.ie. If you open Stripe checkout or the billing portal, Stripe may set cookies on Stripe-controlled domains under Stripe’s own Cookie Policy.

14.4 Analytics cookies

StaySorted does not currently use cookies in this category.

14.5 Advertising cookies

StaySorted does not currently use cookies in this category.

14.6 Other browser storage

Other browser storage
NameProviderPurposeCategoryStorage typeDurationFirst- or third-party
homelyt-remember-meStaySortedStore the Remember me choiceFunctionalLocal storageUntil changed or clearedFirst-party
homelyt-shopping-insightsStaySortedStore the Shopping insights toggleFunctionalLocal storageUntil changed or clearedFirst-party
homelyt-bills-insightsStaySortedStore the Bills insights toggleFunctionalLocal storageUntil changed or clearedFirst-party

15. Updates to this policy

This Cookie Policy may be updated if technologies, providers, legal requirements or cookie use change. The “Last updated” date will be revised when that happens.

If a material change involves non-essential cookies, consent controls will be updated and fresh consent will be obtained where required.

16. Contact

For questions about cookies or this policy, contact:

Brian Ó Ciardha, trading as StaySorted
[Business address, Cork, Ireland]
Email: info@staysorted.ie
Website: staysorted.ie

You can also read the Privacy Policy and the Terms of Service.