1. What this policy covers
This Cookie Policy explains how Spatial Regal (SydGiG) uses cookies, local storage, pixels, SDKs, and similar technologies on sydgig.com and related apps. It should be read with the Privacy Policy. Last updated 1 September 2026.
A cookie is a small file stored on your device. Local storage and session storage are similar technologies used by browsers. Mobile apps may use equivalent identifiers. We treat them the same way for transparency and consent.
2. Consent and global rules
Where required (including the EU/EEA ePrivacy Directive, UK PECR, many EU member-state implementations, LGPD, and other consent-based cookie laws), we:
- Set strictly necessary cookies on the basis of necessity to provide a service you requested (login, security, load balancing, cookie-preference storage).
- Set preferences, analytics, and marketing cookies only after you opt in, unless a local law allows a different basis for a specific low-risk analytics cookie.
- Let you refuse non-essential cookies as easily as you can accept them.
- Honour a subsequent change of mind through the cookie banner or browser controls.
- Do not require cookie consent as a condition of creating an account, except for cookies that are strictly necessary to run that account.
In jurisdictions that use opt-out rather than opt-in for analytics (some US states), we honour Global Privacy Control (GPC) and similar universal opt-out signals where required, and the "Your privacy choices" request described in the Privacy Policy.
Essential cookies cannot be switched off in the product because the Platform would not function (you could not stay signed in or store your cookie choice). You can still block them in your browser, which may break sign-in.
3. Categories we use
| Category | Purpose | Consent |
|---|---|---|
| Strictly necessary | Authentication (Supabase session), security, load balancing, cookie-consent storage, CSRF-style protections | No (necessary) |
| Preferences | Language, currency, UI preferences you choose | Yes, where required |
| Analytics | Aggregated product usage to improve SydGiG (only if enabled) | Yes, where required |
| Marketing | Measuring or delivering promotional campaigns (only if enabled) | Yes |
Today, SydGiG's default production configuration uses strictly necessary cookies for authentication and security, and local storage for currency/language and cookie consent. We do not currently set third-party advertising cookies. If that changes, this table and the banner will be updated before those cookies are set.
4. Cookies and storage we currently use
| Name / key | Provider | Type | Typical lifetime | Purpose |
|---|---|---|---|---|
| sb-*-auth-token (and chunked variants) | SydGiG / Supabase | HTTP cookie | Session / up to ~400 days as configured by the auth library | Keep you signed in; restore session |
| sydgig-cookie-consent | SydGiG | Local storage | Until you clear it or 12 months | Remember your cookie choice |
| sydgig-currency / language (or equivalent UI keys) | SydGiG | Local storage | Until you change or clear it | Remember currency and locale you selected |
Exact cookie names may include a project prefix from our auth provider. Third-party processors (Supabase, Cloudflare) may set additional strictly necessary cookies or edge tokens to deliver the site securely. Cloudflare may set a security cookie to mitigate abusive traffic.
5. Third parties
Our hosting, CDN, authentication, and payment partners may process technical data (IP address, user agent) as described in Subprocessors. Payment checkout, if opened in a third-party hosted page, is governed by that provider's cookie policy (for example, Payaza). We do not control cookies on sites we link to.
6. How to control cookies
- Use the SydGiG cookie banner (Accept all, Essential only, or Customize).
- Browser settings: block or delete cookies. Guides are available from the major browser vendors.
- Mobile OS settings for tracking (iOS App Tracking Transparency, Android privacy controls) where an app build uses those identifiers.
- Global Privacy Control and similar legally recognised signals, where we are required to honour them.
- Opt out of marketing emails using the unsubscribe link; that is separate from cookies.
Do Not Track (DNT) is not a consistently implemented standard; we treat GPC and statutory opt-outs as the relevant signals.
7. Duration
Session cookies expire when you close the browser or after inactivity. Persistent cookies expire on the date in the table, or sooner if you delete them. Consent is re-requested at least every 12 months where a law requires refresh, or when we add a new non-essential category.
8. Changes
We will update this Policy when our cookie use changes. Material new non-essential cookies will not be set until we have a lawful basis, including fresh consent where required.
9. Contact
Questions: privacy@sydgig.com. You can also read the Privacy Policy.
