Skip to content

Slick.cards policies

Cookie Policy

The cookies and browser storage identified in the current application.

Launch legal document | Draft pending production publication

Owner-approved launch terms. Effective date will be the actual approved production launch date; these documents are not yet effective. Attorney review has not been claimed.

Operator: onthemon.io LLC.

Scope

This launch policy describes cookies and browser storage identified in Slick.cards. It is not a guarantee about every browser extension or third-party page. Operator information and launch status appear above. Contact privacy@slick.cards with questions.

Authentication and session storage

Supabase authentication uses browser cookies through the Supabase SSR client. Session cookies support sign-in and authenticated requests and can be refreshed. Cookie names and lifetimes depend on Supabase configuration and session state. Do not assume all application storage is an authentication cookie.

Referral attribution

The application sets slick_cards_referral and slick_cards_referral_session cookies when processing a referral link. They support first-touch attribution and have a configured maximum age of 60 days. These cookies are HTTP-only, SameSite=Lax and Secure in production. The referral flow also reads legacy cardforge_referral and cardforge_referral_session names when present.

QR sessions

The slick_cards_qr_session cookie identifies a QR visitor session. Its configured maximum age is 365 days; it is HTTP-only, SameSite=Lax and Secure in production. QR resolution uses the identifier with device category and referring-page information.

Card analytics browser storage

Public cards use the local-storage key slick-cards-analytics-session for a random identifier associated with view and click events. The code does not set an automatic expiry for this local-storage value. It can remain until browser storage is cleared. This is local storage, not an HTTP cookie.

Preferences and other technologies

No separate general preference-cookie system or advertising SDK was identified in the reviewed code. That is not a claim that third-party embeds or hosted payment pages never track visitors. Browser and vendor behavior must be checked on the deployed service.

Payments and external content

Stripe Checkout and the customer portal run hosted payment flows and may use their own cookies or similar technologies. User-selected card embeds such as YouTube, Vimeo, Spotify, Calendly and Google Maps can contact those providers when loaded. Providers set their own policies and controls. The use of a YouTube privacy-enhanced URL does not establish that all embedded content is free of tracking.

Your choices

Browser settings let you view or clear cookies and site storage or restrict them. Clearing authentication storage can sign you out; blocking referral storage can affect attribution. Downloading a contact remains an explicit visitor action, separate from analytics or session storage.

Launch scope and consent

The initial launch is US-focused. No cookie-consent banner is included in this launch, and the application does not provide a universal consent choice for analytics, referral storage or external embeds. Browser settings are not a claim of a complete site-level consent mechanism.

Before intentionally targeting jurisdictions requiring opt-in consent for technologies actually used, Slick.cards will reevaluate purpose classification, prior consent, withdrawal or opt-out controls and delayed loading of embeds. This policy is not a substitute for any required technical control.