Which cookies we use
| Cookie | Purpose | Set when | Duration |
|---|---|---|---|
cart_token | Identifies your shopping cart so items persist between visits. | You add something to the cart. | 30 days |
buylist_token | Identifies your buylist while you build it. | You add a card to your buylist. | 30 days |
NEXT_LOCALE | Remembers that you chose to read the site in English or Portuguese. | You use the EN / PT switcher. Not before. | Until you close the browser |
better-auth.session_token | Keeps a member of our staff signed in to the private administration area. | One of our staff signs in at /admin. Never set for shop visitors. | 7 days |
__stripe_mid, __stripe_sid | Set by Stripe, our payment provider, to detect and prevent fraud on the payment you are making. | You open the payment step of the checkout. Not before. | One year; 30 minutes |
None of our own cookies holds personal data: three are a random identifier, and NEXT_LOCALE is
the word en or pt. All four are sent only over an encrypted connection and are never sent
with requests coming from other websites. On the live site the staff cookie's name carries the
browser's __Secure- prefix, which is what enforces the encrypted-only rule for it.
The cart, buylist and staff session cookies are httpOnly, meaning scripts running in your
browser cannot read them. The language cookie is not, because the page itself has to read it.
We set no cookie at all until you do one of those things. Simply reading the site leaves nothing on your device, and the staff session cookie is only ever set for our own staff signing in to the administration area — never for a customer.
On the payment step, Stripe's payment form also sets its own fraud-prevention cookies, the two in the table on this site and others on Stripe's own domains, under Stripe's cookie policy. They exist to protect the payment you asked to make, which is why they need no consent either.
Why we do not ask for consent
Article 5(3) of Directive 2002/58/EC (ePrivacy), transposed by article 5 of Portuguese Law 41/2004, exempts cookies strictly necessary to deliver a service the user explicitly requested. A shopping cart is exactly that, and so is remembering a language you actively chose — which is why we only store that choice once you have made it, and never guess it from your browser. So is keeping someone signed in to an area only they can reach: an authentication cookie is the clearest case of all, because you cannot ask to sign in and then be surprised that you were. The fraud checks on a payment you are making are strictly necessary to that payment in the same way.
If we ever adopt marketing cookies, or any measurement that identifies you across visits or across websites, we will ask for your prior consent, and this page will be updated before we do.
Audience measurement
We count visits using Umami, an open-source analytics program that runs on our own server, in Europe. It is not a third-party service: the code is served from this website, your browser never contacts another company, and no data about you leaves our server.
It stores nothing on your device — no cookie, no local storage, nothing to delete. The only
things it reads there are your browser's Do Not Track setting, which we honour (if it is on,
nothing about your visit is sent at all), and a local opt-out flag named umami.disabled, which
you can set yourself in your browser's console to switch the counter off.
To tell one visit from another without identifying you, it combines the page's address, your IP address and your browser's user-agent string into a one-way hash, using a secret that is replaced at the start of every month. Your IP address is used in that calculation and to derive an approximate location; it is never stored. Because the secret changes every month, a visit in one month cannot be linked to a visit in the next, and a visit here cannot be linked to any other website. Within a month, visits from the same connection and browser count as one visitor.
What we record for each visit: the pages read, the site or search engine that sent you, and — derived, not asked — your country, region and city, your browser, operating system, kind of device, screen size and language. What we cannot see: who you are, what you do on any other website, or that two visits in different months were the same person.
We also count uses of the two buttons on the buylist page that hand a collection or a list of cards over to us. For each use we record which button it was, whether it opened WhatsApp or email and, for a collection, the size band the estimate falls in (for example 250 to 999 cards), never the figures you typed.
Why we do not ask for consent for it. Storing information on your device, or reading what is stored there, is what article 5 of Portuguese Law 41/2004 makes subject to consent, and this stores nothing. Reading the screen size and language through the page's own script, and using your IP address, is treated by European regulators as reaching your device too, so for that we rely on the exemption for audience measurement set out by the French data-protection authority (CNIL) — the most detailed guidance in the EU; the Portuguese authority has published none of its own — on conditions this meets in full: it serves only this website, it produces only statistics that do not identify you, it uses no identifier that follows you across sites or beyond a month, nothing is cross-referenced with anything or passed to a third party, and you can object at any time through Do Not Track, the opt-out flag, or by writing to us. If we ever stepped outside those conditions, we would ask first.
How to remove them
You can delete or block these cookies in your browser settings. The cart and the buylist will stop working if you do, and the site will pick a language from your browser's settings on each visit instead of remembering the one you chose.
Contact
Questions about this policy: support@misstepgames.com