Skip to content

§ Legal · stads.cc

DEEN

Cookie PolicyCookie-Richtlinie

Last updated: 2026-06-18

§ 01

Who this policy is from

Please note: the German version of this Cookie Policy is the legally authoritative text. This English version is a convenience translation; in case of any discrepancy, the German wording prevails.

This Cookie Policy is issued by the operator of the website at stads.cc and the associated advertiser dashboard (together, the “Service”):

Postal addressFabian Bachfischer Software
c/o POSTFLEX PFX-504-917
Emsdettener Straße 10
48268 Greven
Deutschland (Germany)

The person responsible for content under § 18(2) MStV is Fabian Bachfischer. The operator is a small business (Kleinunternehmer) under § 19 UStG; there is no VAT ID and no commercial-register entry. Full provider details are in the Impressum.

For how we handle personal data more generally, see our Privacy Policy. This Cookie Policy explains the specific technologies we store on, or read from, your device.

§ 02

What cookies and similar technologies are

A “cookie” is a small text file that a website asks your browser to store and send back on later requests. Related technologies - such as localStorage, sessionStorage, and other forms of storing or reading information on your terminal equipment - are treated the same way under German and EU law for the purposes of this policy.

We distinguish two categories, because the legal basis is different for each:

  • Strictly necessary (essential). Required to deliver a service you have explicitly requested - for example, to keep you logged in. These do not require consent.
  • Non-essential. Anything not strictly necessary - analytics, advertising, personalisation, or cross-site tracking. These require your prior, informed, opt-in consent. We currently set none of these.
§ 03

Storage we use (strictly necessary)

The Service runs on a server-side data layer with a Supabase publishable key used for authentication only. The table below is the complete list of what we store on your device. There is exactly one cookie plus one localStorage entry for your banner choice - both are essential.

sb-access-tokenCookie · first-party · strictly necessary
purpose
Holds your signed-in session (the Supabase auth access token / JWT) so the server can recognise you on each request to the dashboard. Without it you would be logged out on every page load.
type
HTTP cookie · httpOnly · SameSite=Lax · Secure in production (HTTPS)
lifetime
Short-lived - the max-age is clamped to about 1 hour; the token is refreshed client-side while you stay active. Cleared when you log out.
lawful basis
Strictly necessary - no consent required (§ 25(2) TDDDG; Art. 6(1)(b) and (f) GDPR).
stads-consentlocalStorage · first-party · consent record
purpose
Stores your choice in the cookie notice (value “accepted” or “essential”) so the banner does not reappear on return visits. It governs only whether the banner is shown; it activates no further cookies, because no non-essential storage exists today.
type
localStorage entry (not a cookie - never sent to the server)
lifetime
Persists until you clear site storage for stads.cc in your browser.
lawful basis
Strictly necessary / records your decision - no consent required for the entry itself.

Note: this application sets no separate refresh cookie (e.g. sb-refresh-token) - token renewal is handled client-side by the Supabase browser client. There is also no dedicated CSRF cookie: cross-site request forgery is mitigated by the session cookie's SameSite=Lax attribute together with the Bearer/Authorization header on write APIs. We therefore list only the cookies we actually set.

§ 04

Cookies we do NOT set

stads is the ad company developers don't block. Consistent with that, the service serves a single labelled line of plain text - no images, no tracking pixels, and no code ever leaves the device. On this website and dashboard we therefore do not set:

  • advertising or ad-retargeting cookies;
  • cross-site or third-party tracking cookies;
  • analytics or measurement cookies that identify you (no Google Analytics, no fingerprinting, no tracking pixels);
  • social-media embed or “share” cookies; and
  • any cookie whose purpose is profiling or behavioural advertising.

If this ever changes, we will update this policy, present a consent banner before any such technology runs, and only set it after you opt in (see the consent section).

§ 07

Changes to this policy

We may update this Cookie Policy as the Service evolves or as the law changes. The “last updated” date at the top reflects the current version. If we add any cookie that requires consent, we will obtain that consent before the cookie is set and update this document accordingly.

Questions about cookies? privacy@soundworks-ai.com

Cookie Policy · Cookie-Richtlinie - stads · stads