Cookie Policy
Effective Date: August 18, 2026
1. What Are Cookies
Cookies are small text files placed on your device when you visit a website. They allow the site to remember your session, keep you logged in, and store your preferences. Similar technologies include browser local storage and session storage.
2. Our Approach to Cookies
TerryTrilla uses cookies in four categories: strictly necessary, functional preference, analytics and marketing attribution. The full list of every cookie we set, in every category, is in section 4 below — it is generated from the same registry that powers the cookie settings panel on the site, so the two cannot disagree.
Non-essential categories are managed through the cookie consent banner shown on your first visit. You can reopen those settings at any time from the cookie preferences link in the site footer.
3. Categories of Cookies We Use
| Category | Description | Consent Required |
|---|---|---|
| Strictly Necessary | Required for authentication, security, and core functionality. Cannot be disabled without breaking the Platform. | No — essential for service |
| Functional | Remember your preferences: language, theme, whether you asked for the full site instead of the mobile version. The Platform works without them, but will not remember your settings between visits. | Managed in cookie settings |
| Analytics | Measure which campaigns and pages bring people to the Platform. Not used to build advertising profiles. | Managed in cookie settings |
| Marketing attribution | Record which partner link brought you here, so that the partner's referral is credited. | Managed in cookie settings |
4. Detailed Cookie List
The tables below are generated from our cookie registry. If a cookie is not listed here, we do not set it.
4.1 Strictly Necessary
Set by our authentication and form-security systems; required to log in and use the Platform safely.
| Cookie Name | Provider | Purpose | Duration |
|---|---|---|---|
next-auth.session-token | NextAuth.js | Authenticated session management | 30 days |
__Secure-next-auth.session-token | NextAuth.js | Secure session (HTTPS only) | 30 days |
next-auth.csrf-token | NextAuth.js | CSRF protection | Session |
next-auth.callback-url | NextAuth.js | Post-login redirect URL | Session |
next-auth.pkce.code_verifier | NextAuth.js | OAuth PKCE security verification | Session |
next-auth.state | NextAuth.js | OAuth state parameter | Session |
next-auth.nonce | NextAuth.js | OIDC replay attack prevention | Session |
__stripe_mid | Stripe | Fraud prevention (payment security) | 1 year |
__stripe_sid | Stripe | Session fraud prevention | 30 minutes |
tt_ft_no | TerryTrilla | Stores your refusal of analytics cookies so it is respected on later visits | 2 years |
tt_form_csrf | TerryTrilla | Protects forms from being submitted from another site on your behalf | 1 hour |
4.2 Functional Preference
| Cookie Name | Provider | Purpose | Duration |
|---|---|---|---|
NEXT_LOCALE | next-intl | Language preference | 1 year |
theme | next-themes | Dark/light mode preference | 1 year |
tt_locale_choice | TerryTrilla | Marks that the language was chosen by you, so your device settings do not override it | 1 year |
tt_full_web | TerryTrilla | Remembers that you asked for the full site instead of the mobile version | 1 year |
4.3 Analytics
| Cookie Name | Provider | Purpose | Duration |
|---|---|---|---|
tt_ft | TerryTrilla | Remembers where you first came from, to measure which campaigns work | 90 days |
4.4 Marketing Attribution
| Cookie Name | Provider | Purpose | Duration |
|---|---|---|---|
tt_ref | TerryTrilla | Records which partner link brought you here, so their referral is credited | 60 days |
tt_ref_slug | TerryTrilla | Partner identifier, read at checkout if the main attribution cookie is unavailable | 60 days |
5. Third-Party Services
We use Stripe for payment processing. Stripe sets its own cookies for fraud prevention during checkout (listed in section 4.1 above). These are strictly necessary for secure payment processing and are governed by Stripe's own privacy policy:
- Stripe Privacy Policy: https://stripe.com/privacy
6. Managing Cookies
You can control cookies through your browser settings. Most browsers allow you to view, block, or delete cookies:
- Chrome: Settings → Privacy and Security → Cookies
- Firefox: Settings → Privacy & Security → Cookies and Site Data
- Safari: Preferences → Privacy → Manage Website Data
- Edge: Settings → Cookies and Site Permissions
Note: Blocking strictly necessary cookies (authentication and CSRF) will prevent you from logging in and using the Platform.
7. Cookie Settings on the Platform
A cookie consent banner is shown on your first visit, and your choice is stored for twelve months. You can change it at any time through the cookie preferences link in the site footer: each non-essential category can be turned on or off separately.
Refusing analytics is itself remembered (see tt_ft_no in section 4.1), so the choice survives later visits without asking again.
8. EU/EEA Users
Strictly necessary cookies are required to operate the Platform and cannot be switched off. Every other category — functional, analytics and marketing attribution — is managed through the consent settings described in section 7.
If you would like a copy of the data associated with these cookies, or its deletion, write to [email protected].
9. Changes to This Policy
We will update this Cookie Policy when our cookie usage changes. The "Last Updated" date at the top of this page will reflect any revisions. For material changes (e.g., introduction of analytics or marketing cookies), we will notify registered users by email.
10. Contact
For questions about our use of cookies: [email protected]