Cookie Policy

Last updated: February 23, 2026 · Effective: February 23, 2026

1. What Are Cookies

Cookies are small text files placed on your device (computer, tablet, or mobile) when you visit a website. They are widely used to make websites work efficiently, provide analytics, and personalise your experience.

Cookies may be:

  • Session cookies: Temporary cookies deleted when you close your browser.
  • Persistent cookies: Stored on your device until they expire or are manually deleted.
  • First-party cookies: Set by fastbuilder.dev (the site you are visiting).
  • Third-party cookies: Set by external services embedded in our site (e.g., analytics, payment providers).

This policy also covers similar technologies such as web beacons, pixels, and local storage, which function in a comparable way.

2. How We Use Cookies

FastBuilder uses cookies for the following purposes:

  • Strictly necessary: Essential for authentication, session management, security protection, and core site functionality. These cannot be disabled without breaking the site.
  • Analytics & performance: Help us understand how visitors interact with our site, which pages are most popular, and where users encounter issues. Only set with your explicit consent.
  • Functional / preferences: Remember your settings such as theme preference, cookie consent choice, and language selection.
  • Security: Fraud detection, bot prevention, and abuse protection for forms and authentication endpoints.

We do not use cookies for advertising, behavioural tracking, or cross-site profiling.

3. Cookies We Use

The following tables detail all cookies used on fastbuilder.dev and app.fastbuilder.dev:

3.1 Strictly Necessary Cookies

CookieProviderDurationPurpose
cookie-consentFastBuilder1 yearStores your cookie consent preferences
sb-*-auth-tokenSupabaseSession / 7 daysAuthentication and session management for the client dashboard
sb-*-auth-token-code-verifierSupabaseSessionPKCE code verifier for secure OAuth flows
__Host-next-auth*Next.jsSessionCSRF protection and session state
__vercel_live_tokenVercelSessionPreview deployment authentication

3.2 Analytics & Performance Cookies

Only set with your explicit consent.

CookieProviderDurationPurpose
_gaGoogle Analytics2 yearsDistinguishes unique visitors using a randomly generated client ID
_ga_*Google Analytics2 yearsMaintains session state for GA4
_gidGoogle Analytics24 hoursDistinguishes unique visitors within a 24-hour period
_gatGoogle Analytics1 minuteThrottles request rate to limit data collection on high-traffic sites

3.3 Functional / Preference Cookies

CookieProviderDurationPurpose
themeFastBuilder1 yearStores your light/dark theme preference
localeFastBuilder1 yearStores your language/region preference

3.4 Third-Party Security Cookies

CookieProviderDurationPurpose
__stripe_midStripe1 yearFraud prevention and payment security
__stripe_sidStripe30 minutesPayment session identifier for fraud detection

4. Local Storage & Similar Technologies

In addition to cookies, we use the following browser storage mechanisms:

KeyTypePurpose
cookie-consentlocalStorageStores your detailed cookie preference settings (JSON)
sb-*-auth-tokenlocalStorageAuthentication token for the client dashboard

5. Managing Your Cookie Preferences

5.1 Via Our Consent Banner

When you first visit our site, a cookie consent banner allows you to:

  • Accept all: Enable all cookie categories including analytics.
  • Essential only: Permit only strictly necessary cookies.
  • Customise: Choose which optional categories to enable (analytics, functional).

You can change your preferences at any time by clicking “Cookie Preferences” in the footer of any page.

5.2 Via Browser Settings

Most browsers allow you to view, manage, block, and delete cookies through their settings. Common browsers:

Note: Blocking strictly necessary cookies may impair site functionality, including login and session management.

5.3 Opt-Out of Google Analytics

You can opt out of Google Analytics across all websites by installing the Google Analytics Opt-Out Browser Add-on.

6. Legal Basis for Using Cookies (GDPR)

  • Strictly necessary cookies: Permitted under GDPR Art. 6(1)(f) (legitimate interests) and exempt from consent requirements under the ePrivacy Directive Art. 5(3), as they are necessary for the service you have requested.
  • Analytics and functional cookies: Set only upon your explicit, informed, freely given, and specific consent (GDPR Art. 6(1)(a) and ePrivacy Directive Art. 5(3)).

Consent is obtained through our cookie banner, which complies with GDPR requirements for valid consent: it is granular (per-category), unambiguous (affirmative action required), and revocable at any time.

7. Your Rights (GDPR & CCPA)

Under the GDPR and CCPA, you have the right to:

  • Know what cookies and tracking technologies are being used and why.
  • Withdraw consent for non-essential cookies at any time without affecting the lawfulness of prior processing.
  • Request access to data collected via cookies.
  • Request deletion of data collected via cookies.
  • Opt out of analytics tracking.
  • Not be discriminated against for exercising your privacy rights.

For full details on your data protection rights, see our Privacy Policy.

8. Do Not Track & Global Privacy Control

We honour the Do Not Track (DNT) browser signal. When DNT is enabled, we do not set analytics cookies regardless of your consent banner selection. We also recognise the Global Privacy Control (GPC) signal as a valid opt-out under the CCPA.

9. Changes to This Policy

We may update this Cookie Policy to reflect changes in the cookies we use, our practices, or legal requirements. When we make changes:

  • The “Last updated” date at the top will be revised.
  • Material changes (e.g., adding new cookie categories) will trigger a new consent prompt.
  • We will not retroactively apply changes to cookies already stored on your device.

10. Contact

For questions about our use of cookies or this policy:

You may also manage your cookie preferences at any time by clicking “Cookie Preferences” in the footer.