The short version
One cookie keeps you signed in. One records which link brought you to a trainer’s page. There is no third one.
If you never create an account, the first never exists. Neither is used to build a profile of you, neither is shared with anybody, and neither follows you to another website — they cannot, because they are ours and are only ever sent back to us.
Every cookie we set
sb-…-auth-tokenYour sign-in session · strictly necessary · expires when the session does- Set by Supabase, our database and authentication provider, at the moment you sign in — and never before. It is what stops the site asking you to sign in again on every page. If you have never made an account, this cookie has never been set for you.
sthq_srcWhere you came from · functional · 30 days- Holds a single word — “directory”, “instagram”, “qr” — so a trainer can see which of their links is actually producing bookings. It is set only if you arrive on a link that carries a ?src= tag, only ever holds one of five fixed words, and is written once: if you come back later by a different route the original is kept, not replaced. It contains a label, not an identity, it is never sent anywhere but back to us, and it is read at one moment only — when a booking is created.
That is the complete list. If it ever grows, this page changes and the version at the top changes with it.
What is deliberately absent
Worth stating explicitly, because most sites this sentence appears on do have these:
- No analytics product — no Google Analytics, no Plausible, no Vercel Analytics, nothing running in your browser to watch what you do.
- We do keep our own counts, and they are not cookies. Our server tallies events like “a directory search happened” or “a payment completed”, so we can tell whether the product works. It sets nothing on your device, contacts no third party, and stores no name, email, IP address, device identifier or anything else that points at a person — so it cannot be turned off from here, because there is nothing about you in it. The full field list is in the privacy policy.
- No advertising pixels — no Meta, no TikTok, no Google Ads. There is no advertising on this platform and nothing to retarget you with.
- No session recording or heatmaps. Nobody is watching a replay of you filling in a booking form.
- No third-party fonts, embeds or widgets. Typefaces are served from our own domain. There is no chat widget, no social embed, no video player calling home.
- No fingerprinting and no attempt to identify a device across visits.
Ordinary server logs still exist — a web server records the requests it receives, including IP addresses — and that is described in the privacy policy.
Stripe’s checkout page
When you pay, you are on a page hosted by Stripe on Stripe’s own domain. Stripe sets its own cookies there, mainly for fraud prevention, under its own privacy policy. We have no access to them and no control over them. Your card details go to Stripe and never to us.
Turning them off
Every browser lets you block or delete cookies. Blocking ours has one consequence and it is not subtle: sb-…-auth-token is how being signed in works, so without it you cannot use a parent account or a trainer dashboard. Booking as a guest — which is how most people use this site — needs no cookie from us at all.
Because we do not track anyone, there is no “reject non-essential cookies” control here. There is no non-essential category to reject — and the event counts described above use no cookie at all, so blocking cookies would not change them either way.
Changes and contact
If we ever add anything that tracks you, this page will say so before it happens, and the choice will be a real one rather than a banner. The fuller description of what we collect and why is in the privacy policy; the cookie section of it is at privacy#cookies.
Questions: privacy@soccertrainerhq.com.
