Cookie Policy

Last updated: 3 April 2026

The short version

CanIShip uses only strictly necessary cookies. We do not use tracking cookies, advertising cookies, or any third-party analytics cookies. Our analytics tool (Plausible) is deliberately cookie-free and GDPR-compliant by design.

1. What are cookies?

Cookies are small text files stored on your device by your browser when you visit a website. They allow websites to remember information about your visit — such as whether you are logged in.

2. Cookies we use

Strictly NecessaryAuthentication (Supabase)

When you sign in, Supabase sets a session cookie so you stay logged in across page loads. Without this cookie, you would be logged out every time you navigate to a new page.

NamePurposeDuration
sb-*-auth-tokenStores your encrypted session tokenSession / 7 days
sb-*-auth-token-code-verifierPKCE flow security tokenSession
Strictly NecessaryPayments (Stripe)

When you initiate a payment, Stripe sets cookies to secure the transaction and prevent fraud. These are set only when you interact with the Stripe checkout flow.

NamePurposeDuration
__stripe_midFraud prevention and machine identification1 year
__stripe_sidSecure payment session30 minutes
Cookie-freeAnalytics (Plausible)

We use Plausible Analytics to understand traffic patterns. Plausible is intentionally built without cookies — it does not store any information on your device and is fully GDPR, CCPA, and PECR compliant. No consent is required for Plausible because it collects no personal data.

3. Cookies we do NOT use

  • Advertising or retargeting cookies
  • Social media tracking cookies
  • Third-party analytics cookies (Google Analytics, Facebook Pixel, etc.)
  • Profiling or behavioural tracking cookies

4. Your choices

Because all cookies we use are strictly necessary for the service to function, they cannot be disabled without breaking core features (you would not be able to stay logged in or complete a payment).

You can always clear cookies from your browser settings. Doing so will log you out of CanIShip. Most browsers also offer a private/incognito mode where cookies are deleted when you close the window.

5. Legal basis (GDPR)

Under GDPR Article 6(1)(b) — performance of a contract — we may process strictly necessary cookies without obtaining consent because they are essential to deliver the service you have requested. No consent banner is legally required for strictly necessary cookies, but we display one for transparency.

6. Contact

Questions about this policy? reachout@actvli.com