Skip to main content
Santa's Sack

Cookie Policy

Version: 2.0.0
Last updated: September 8, 2026

1. Introduction

This Cookie Policy explains how Santa's Sack (https://santassack.app) and Gifts (https://gifts.santassack.app) use cookies and similar technologies. Cookies are small text files stored on your device.

Using the Service means you are informed of these essential cookies. You can delete cookies in your browser; doing so will sign you out or require you to unlock a shared list again. The in-app banner is informational, in line with GDPR transparency requirements.

2. What Cookies We Use

We use essential cookies only: authentication, security and (on Gifts) remembering that you already unlocked a shared list with the access phrase.

2.1. Shared session cookie

Cookie name Provider Purpose Duration Type
__Secure-santassack.session-token.v1 Santa's Sack (Auth.js) Encrypted JWT session for the shared account. In production: Domain=santassack.app, Path=/, HttpOnly, Secure, SameSite=Lax. Signing in or out on either trusted product affects both. Up to 30 days, or until sign-out Strictly necessary

This is the only cookie shared across *.santassack.app. Preview and other non-production hosts use a separate cookie name and must not receive the production session.

2.2. Authentication transaction cookies (issuer host only)

Short-lived Auth.js cookies used during sign-in (CSRF, callback, PKCE/state) stay host-only on the Santa's Sack issuer. They are not set on gifts.santassack.app and are not scoped to the parent domain.

2.3. Gifts share-unlock cookie

Cookie name Provider Purpose Duration Type
__Secure-gifts.share-unlock.v2 Gifts After a correct access phrase, remembers a scoped unlock for that share so you are not prompted on every click. Host-only on the Gifts origin (not the parent domain). HttpOnly, Secure. Short-lived; expires with the unlock capability Strictly necessary

Revoking or rotating a share invalidates existing unlock capabilities. The cookie does not grant edit rights and does not replace sign-in for reserve, transfer or comment actions.

Non-production environments use a prefixed name such as gifts.share-unlock.dev-v2 instead of the __Secure- production name.

2.4. Security and anti-spam cookies (Cloudflare Turnstile)

Used on Santa's Sack contact and support forms:

Cookie name Provider Purpose Duration Type
cf_clearance Cloudflare Bot detection and security verification 1 year Strictly necessary
__cf_bm Cloudflare Bot management 30 minutes Strictly necessary

Third party: Cloudflare, Inc. (USA).
More info: Cloudflare Privacy Policy

2.5. Local Storage (not cookies)

The Service may store in the browser's Local Storage:

  • Cookie-banner acknowledgement
  • Theme (Santa's Sack)
  • Language preference where kept locally

Local Storage is not sent to the server with every request.

2.6. We don't use

The Service does not use:

  • Analytical cookies (Google Analytics, Facebook Pixel, and similar)
  • Marketing or advertising cookies
  • Third-party tracking cookies (except Cloudflare for form security)
  • Social-media cookies

3. Managing Cookies

There is no opt-out for essential cookies: without the session cookie you cannot stay signed in; without the Gifts unlock cookie you must re-enter the access phrase; without Cloudflare cookies you may be unable to submit contact forms.

  • __Secure-santassack.session-token.v1 is cleared on sign-out or when the 30-day maximum age is reached.
  • __Secure-gifts.share-unlock.v2 expires with the unlock or when sharing is revoked.
  • You can delete cookies in the browser; that signs you out of both products and forgets Gifts unlocks.

4. Changes to this Cookie Policy

We may update this policy. We will notify you of changes via an in-app notice.

5. Contact

Questions: contact page.

Thank you for using Santa's Sack and Gifts.