Cookie Policy
Effective 2026-04-30
This page explains the cookies and similar technologies that Brightroom uses on https://bright-room.com and what they do. Together with our Privacy Policy, it describes how we process personal data set or read in your browser.
1. What are cookies?
Cookies are small text files that a website stores in your browser. Some are needed for the site to work (for example, to keep you signed in); others help us understand how the site is used or to deliver marketing. Similar technologies — local storage, session storage, pixels — work the same way for the purposes of this policy.
2. Categories we use
| Category | Purpose | Legal basis | Duration |
|---|---|---|---|
| Strictly necessary | Authenticate you (Supabase session cookie), remember your cookie-consent choices, prevent CSRF. | Legitimate interest / contract performance — these cookies are exempt from consent under Art. 5(3) ePrivacy. | Session — 12 months |
| Analytics | Aggregate usage statistics so we can fix bugs and improve flows. Not used for advertising. | Consent (you opt in via the banner). | Up to 13 months |
| Marketing | Measure ad performance and re-target visitors on other sites. Off by default. | Consent (you opt in via the banner). | Up to 13 months |
We do not currently use any cookies in the analytics or marketing categories. They are listed here so the policy reflects what would happen as we grow; if we add a new vendor, we will update this page and re-prompt you for consent.
3. Specific cookies and storage we set
| Name | Set by | Purpose | Duration |
|---|---|---|---|
sb-*-auth-token | Brightroom (Supabase) | Keeps you signed in. | Up to 1 year |
br-consent | Brightroom | Remembers your cookie-consent choices. | 180 days |
brightroom.register.v1 (sessionStorage) | Brightroom | Holds your registration draft so you don’t lose progress if you reload. | Until tab is closed |
4. Managing your preferences
When you first visit the Service we show a consent banner with three options: Accept all, Reject all, and Customise. You can change your choice at any time:
- By clicking the “Cookie preferences” link in the footer; or
- By clearing the
br-consentcookie in your browser, which will trigger the banner again.
Modern browsers (Chrome, Safari, Firefox, Edge) also let you block or delete cookies entirely; doing so for strictly necessary cookies will prevent you from signing in.
5. Do Not Track and Global Privacy Control
We honour the Global Privacy Control (GPC) signal as a valid opt-out of analytics and marketing categories. We do not respond to legacy Do-Not-Track headers, which have been deprecated.
6. Changes
If we add new cookies — for example when we wire up analytics or marketing — we will update this page and re-prompt you for consent before they load.