2. Categories we use
TL;DR — Necessary (always on), Analytics + Product (after consent). No ad-tech, no fingerprinting.
Strictly necessary (always on — no consent required):
__Host-session— Clerk authentication for /admin/*. HTTP-only, Secure, SameSite=Lax. Expires: session.sf-consent— records your cookie-banner choice so we don't ask again. 12 months.cf_clearance,__cf_bm— Cloudflare bot protection. Cloudflare-managed, see their docs.
Analytics (only after you accept "Analytics"):
- Plausible sets no cookies — it fingerprints nothing, uses a rotating hash of IP+UA+domain that expires daily.
Product (only after you accept "Product analytics"):
- PostHog sets
ph_*cookies (distinct ID, feature-flags) for up to 12 months. Data region: EU.
3. How to manage your preferences
TL;DR — Use the cookie banner. Or the "Cookie settings" link in the footer. Or your browser's privacy controls.
The first time you visit surfient.com you'll see a cookie banner with three options: "Accept all," "Only necessary," and "Customise." Your choice is stored in sf-consent and respected on every page load.
To change later, click Cookie settings in the site footer. You can also clear cookies from your browser settings at any time — we'll simply ask again on your next visit.
4. Do Not Track & GPC
TL;DR — We honour Global Privacy Control (GPC) headers as an opt-out. DNT is treated identically.
If your browser sends the Global Privacy Control (GPC) signal or the legacy Do Not Track (DNT) header, we treat that as an opt-out from non-essential cookies — same as clicking "Only necessary" in the banner. You don't need to do anything else.
Cookie questions?
Email [email protected].