Cookie Policy
Last updated: July 2026
This policy explains the cookies and similar technologies Linebook uses across its marketing pages, studio console and studio booking flows. We aim to keep this footprint small and do not use advertising or cross-site tracking technologies for behavioural advertising.
01The technologies we use
The inventory below reflects our current understanding of the technologies used in production. Because some third-party providers determine exact browser behaviour at runtime, read it as a good-faith operational disclosure rather than a guarantee that no provider-controlled browser storage will ever vary. We update this policy when we materially change these technologies.
| Technology | Category | Purpose | Where it fires | Notes |
|---|---|---|---|---|
| Session / authentication cookie (epoch_session) | Necessary / security | Keeps you signed in and secures account access. | Studio console (signed-in) | httpOnly, ~12-hour lifetime. |
| Finances re-authentication (fin_unlock) | Necessary / security | Gates the Finances section behind a short-lived password re-auth. | Finances view in the console | Short-lived (~10 min). |
| Cloudflare Turnstile (anti-abuse) | Necessary / security | Distinguishes real booking activity from bots and abuse. | Public booking forms | Linebook code sets no cookie or browser storage for Turnstile; Cloudflare's own challenge may set its own browser storage. |
| Vercel Web Analytics / Speed Insights | Analytics / performance | Aggregate, privacy-preserving usage and performance measurement. | Site and app pages | Cookieless under Vercel's current default implementation, using a same-origin beacon and setting no cookies. |
Linebook does not use localStorage or sessionStorage, and there are no advertising, social or cross-site tracking pixels on our pages. Payments currently use a hosted Stripe Checkout redirect, with no Stripe.js loaded on Linebook pages. Our operator back office (a separate admin subdomain) is protected by Cloudflare Access, which sets the CF_Authorization authentication cookie there.
02Consent
Linebook treats authentication, re-authentication, OAuth CSRF protection and anti-abuse technologies as necessary to provide secure requested services, subject to applicable law and counsel review. Analytics or performance technologies may be treated differently depending on jurisdiction and configuration; ours are designed to be privacy-preserving and cookieless under Vercel's current default implementation. If we introduce a technology that requires consent before use, we will implement an appropriate consent mechanism before relying on it in those jurisdictions.
03Managing cookies
You can control or delete cookies through your browser settings; blocking necessary security or account cookies may stop parts of the console from working. Because studio booking pages may be visited by users in different jurisdictions, studios should also assess any local cookie or consent obligations that apply to their own use of those pages.
Questions? Contact us or hello@linebook.ink. See also our Privacy Policy and Subprocessors page.