Cookie Policy
Version: 2.0.0
Last updated: September 8, 2026
1. Introduction
This Cookie Policy explains how Santa's Sack (https://santassack.app)
and Gifts (https://gifts.santassack.app) use cookies and similar
technologies. Cookies are small text files stored on your device.
Using the Service means you are informed of these essential cookies. You can delete cookies in your browser; doing so will sign you out or require you to unlock a shared list again. The in-app banner is informational, in line with GDPR transparency requirements.
2. What Cookies We Use
We use essential cookies only: authentication, security and (on Gifts) remembering that you already unlocked a shared list with the access phrase.
2.1. Shared session cookie
| Cookie name | Provider | Purpose | Duration | Type |
|---|---|---|---|---|
__Secure-santassack.session-token.v1 |
Santa's Sack (Auth.js) | Encrypted JWT session for the shared account. In production: Domain=santassack.app, Path=/, HttpOnly, Secure, SameSite=Lax. Signing in or out on either trusted product affects both. |
Up to 30 days, or until sign-out | Strictly necessary |
This is the only cookie shared across *.santassack.app. Preview and other
non-production hosts use a separate cookie name and must not receive the
production session.
2.2. Authentication transaction cookies (issuer host only)
Short-lived Auth.js cookies used during sign-in (CSRF, callback, PKCE/state)
stay host-only on the Santa's Sack issuer. They are not set on
gifts.santassack.app and are not scoped to the parent domain.
2.3. Gifts share-unlock cookie
| Cookie name | Provider | Purpose | Duration | Type |
|---|---|---|---|---|
__Secure-gifts.share-unlock.v2 |
Gifts | After a correct access phrase, remembers a scoped unlock for that share so you are not prompted on every click. Host-only on the Gifts origin (not the parent domain). HttpOnly, Secure. | Short-lived; expires with the unlock capability | Strictly necessary |
Revoking or rotating a share invalidates existing unlock capabilities. The cookie does not grant edit rights and does not replace sign-in for reserve, transfer or comment actions.
Non-production environments use a prefixed name such as
gifts.share-unlock.dev-v2 instead of the __Secure- production name.
2.4. Security and anti-spam cookies (Cloudflare Turnstile)
Used on Santa's Sack contact and support forms:
| Cookie name | Provider | Purpose | Duration | Type |
|---|---|---|---|---|
cf_clearance |
Cloudflare | Bot detection and security verification | 1 year | Strictly necessary |
__cf_bm |
Cloudflare | Bot management | 30 minutes | Strictly necessary |
Third party: Cloudflare, Inc. (USA).
More info: Cloudflare Privacy Policy
2.5. Local Storage (not cookies)
The Service may store in the browser's Local Storage:
- Cookie-banner acknowledgement
- Theme (Santa's Sack)
- Language preference where kept locally
Local Storage is not sent to the server with every request.
2.6. We don't use
The Service does not use:
- Analytical cookies (Google Analytics, Facebook Pixel, and similar)
- Marketing or advertising cookies
- Third-party tracking cookies (except Cloudflare for form security)
- Social-media cookies
3. Managing Cookies
There is no opt-out for essential cookies: without the session cookie you cannot stay signed in; without the Gifts unlock cookie you must re-enter the access phrase; without Cloudflare cookies you may be unable to submit contact forms.
__Secure-santassack.session-token.v1is cleared on sign-out or when the 30-day maximum age is reached.__Secure-gifts.share-unlock.v2expires with the unlock or when sharing is revoked.- You can delete cookies in the browser; that signs you out of both products and forgets Gifts unlocks.
4. Changes to this Cookie Policy
We may update this policy. We will notify you of changes via an in-app notice.
5. Contact
Questions: contact page.
Thank you for using Santa's Sack and Gifts.