Home/Cookie Policy
Legal

Cookie Policy

Last updated: July 2026

This policy explains the cookies and similar technologies Linebook uses across its marketing pages, studio console and studio booking flows. We aim to keep this footprint small and do not use advertising or cross-site tracking technologies for behavioural advertising.

01The technologies we use

The inventory below reflects our current understanding of the technologies used in production. Because some third-party providers determine exact browser behaviour at runtime, read it as a good-faith operational disclosure rather than a guarantee that no provider-controlled browser storage will ever vary. We update this policy when we materially change these technologies.

TechnologyCategoryPurposeWhere it firesNotes
Session / authentication cookie (epoch_session)Necessary / securityKeeps you signed in and secures account access.Studio console (signed-in)httpOnly, ~12-hour lifetime.
Finances re-authentication (fin_unlock)Necessary / securityGates the Finances section behind a short-lived password re-auth.Finances view in the consoleShort-lived (~10 min).
Cloudflare Turnstile (anti-abuse)Necessary / securityDistinguishes real booking activity from bots and abuse.Public booking formsLinebook code sets no cookie or browser storage for Turnstile; Cloudflare's own challenge may set its own browser storage.
Vercel Web Analytics / Speed InsightsAnalytics / performanceAggregate, privacy-preserving usage and performance measurement.Site and app pagesCookieless under Vercel's current default implementation, using a same-origin beacon and setting no cookies.

Linebook does not use localStorage or sessionStorage, and there are no advertising, social or cross-site tracking pixels on our pages. Payments currently use a hosted Stripe Checkout redirect, with no Stripe.js loaded on Linebook pages. Our operator back office (a separate admin subdomain) is protected by Cloudflare Access, which sets the CF_Authorization authentication cookie there.

02Consent

Linebook treats authentication, re-authentication, OAuth CSRF protection and anti-abuse technologies as necessary to provide secure requested services, subject to applicable law and counsel review. Analytics or performance technologies may be treated differently depending on jurisdiction and configuration; ours are designed to be privacy-preserving and cookieless under Vercel's current default implementation. If we introduce a technology that requires consent before use, we will implement an appropriate consent mechanism before relying on it in those jurisdictions.

03Managing cookies

You can control or delete cookies through your browser settings; blocking necessary security or account cookies may stop parts of the console from working. Because studio booking pages may be visited by users in different jurisdictions, studios should also assess any local cookie or consent obligations that apply to their own use of those pages.

Questions? Contact us or hello@linebook.ink. See also our Privacy Policy and Subprocessors page.