Cookie Policy
Every cookie this product can set, what sets it and how long it lasts, the cookieless analytics the site runs, and why there is no consent banner.
Contents
01·The short version#
If you are not signed in, Vinfirm sets no cookies at all. You can read the marketing pages, a public sale page, or a seller's profile without this site storing anything on your device. Page views are counted, but by a cookieless method described in section 02.
Signing in sets one session cookie, because there is no way to stay signed in without one. Opening a checkout page loads Stripe, which sets two of its own for fraud prevention. That is the complete list, and it is in the table in section 03.
02·Analytics#
Vinfirm uses Vercel Web Analytics to count page views across the site. It is cookieless: a repeat visit is recognised by a hash derived from the incoming request and a salt that rotates every day, and nothing is written to your device. It produces aggregate counts of pages, referrers, country and browser, and no profile of you.
Because the daily salt rotation discards the link between days, there is no way for it or for us to follow one person across visits, and nothing it collects can be joined to your Vinfirm account.
There is no advertising pixel, no session recording, no A/B testing tool, no cross-site tracker, and no third-party script that exists to build a profile of you. We do not sell or share anything about your browsing.
Public profile view counts are separate and simpler still: a single number incremented on the server, holding no viewer identity. No visitor list, IP address, location, device fingerprint or cookie is stored to produce them, and known crawlers are excluded so the number means something to the seller reading it.
03·Every cookie this product can set#
Each row below is a cookie this application or a service embedded in it may store, and the circumstances under which it appears. Nothing outside this table is set by Vinfirm.
| Cookie | Set by | Why | How long |
|---|---|---|---|
| sb-…-auth-token | Vinfirm (via Supabase) | Keeps you signed in and tells the app which account is making a request. Set only after you sign in. | Until you sign out or it expires |
| __stripe_mid | Stripe | Fraud prevention on card payments. Set only on a page where a payment form is loaded. | 1 year |
| __stripe_sid | Stripe | Fraud prevention within a single checkout session. | 30 minutes |
04·Why there is no cookie banner#
Consent rules for cookies are about storing or reading something on your device. Vinfirm stores nothing on your device that is not strictly necessary: the analytics in section 02 is cookieless and writes nothing at all, and the three cookies in section 03 each exist to deliver something you asked for: staying signed in, and not having your payment rejected as unverifiable.
Strictly necessary storage requires disclosure, not permission. That disclosure is this page, the cookies section of the Privacy Policy, and the FAQ. A consent dialog would ask you to decide a question that is not open: there is nothing non-essential here to switch off.
If that ever changes, whether through an advertising pixel, a third-party analytics script, session recording, or anything else that writes to your device, this page will say so, and it will sit behind a real choice made before the script loads, with refusing as easy as accepting and a way to change your mind afterwards.
05·Controlling cookies yourself#
Every browser can block or delete cookies for a site, and you can do that to Vinfirm at any time. Clearing the session cookie signs you out; blocking it means you cannot sign in, because the app has no other way to recognise you between requests. Blocking Stripe's means checkout may refuse the payment as unverifiable.
None of that affects reading a public sale page or a seller's profile, neither of which requires a cookie.
Vinfirm is operated by Vinfirm LLC, an Indiana limited liability company, which is the company responsible for what this page describes. Questions about any of it can go to help@vinfirm.com.