Skip to content
← Home

Legal · Cookie Policy

Every cookie we set is listed on this page.

The short version

  • • Velur sets three cookies and one storage key, all strictly necessary.
  • • There are no advertising cookies and no cross-site tracking, anywhere.
  • • Our analytics set no cookie at all and store nothing in your browser.
  • • That is why there is no accept or reject banner. There is nothing to consent to.
  • • Add a non-essential cookie and we build consent controls first, not after.

Last updated: 23 September 2026

1. The short answer

Velur sets three cookies and one local storage key. All four are strictly necessary: they sign you in, remember which workspace you are looking at, finish a Shopify install, and remember that you have seen the cookie notice. None of them is used for advertising, and none of them follows you to another website.

That is the whole list. There is no advertising pixel, no tag manager, no embedded video, no chat widget and no social button anywhere on velur.io, so no other company can set a cookie through a page we serve.

2. Every cookie we set

Cookies and browser storage keys set by Velur, with their purpose and lifetime
NameTypeWhat it doesHow long
sb-<project>-auth-tokenFirst party cookieKeeps you signed in as you move between pages of the console. Set by Supabase Auth when you sign in, and removed when you sign out.Until you sign out
velur-tenantFirst party cookieRemembers which workspace you are looking at when your account belongs to more than one. Server side only, so no script on the page can read it.1 year
velur-shopify-claimFirst party cookieHeld only while you are installing Velur from the Shopify App Store, so the store you just authorised is attached to the account you then create. Deleted the moment the account exists.Minutes, then deleted
velur-cookie-ack-v1Local storageRemembers that you dismissed the cookie notice, so it is not shown to you on every page. Stays in your browser and is never sent to Velur.Until you clear site data

The first three are cookies. The fourth is a local storage key, which works like a cookie but is never attached to a request, so it stays in your browser and never reaches us.

3. Analytics, and why it sets nothing

The site uses Vercel Web Analytics to count page views and see which pages people read. It is worth being precise about what that does, because most analytics tools do something quite different.

Vercel Web Analytics sets no cookie and writes nothing to your browser storage. It does not assign you an identifier that persists between visits, and it cannot follow you to any other website. A page view is counted, the referring site and a coarse device type are recorded, and that is all. We never see who you are from it.

Because nothing is stored on or read from your device, this does not require consent under Article 22.2 LSSI. It is still processing of personal data under the GDPR, for which our lawful basis is legitimate interests: we need to know which pages are read in order to keep writing useful ones, and counting page views without identifying anyone is about as light an interference with your privacy as measurement gets.

4. Why there is no accept or reject banner

Article 5(3) of the ePrivacy Directive, which Spain transposes at Article 22.2 of Ley 34/2002 (LSSI), requires your consent before a site stores or reads anything on your device. It carves out one exception: storage that is strictly necessary to deliver a service you explicitly asked for.

Every key in the table above sits inside that exception, and the analytics store nothing at all. So there is nothing here for you to consent to, and a banner offering you an accept and a reject button would be theatre: both buttons would do exactly the same thing. We show a one line notice instead, which tells you what is set and links here, and it remembers that you dismissed it.

If we ever add a cookie that is not strictly necessary, an advertising pixel or a product analytics tool that fingerprints you, we will build real consent controls first and turn the cookie on second. Never the other way round.

5. How to control cookies yourself

You do not need our permission to remove any of this. Every browser lets you see the cookies a site has set, delete them, and block new ones, usually under Settings, then Privacy, then Cookies and site data. Deleting the cookies above signs you out of the console and makes the cookie notice appear again. Nothing else breaks.

Blocking the Supabase session cookie outright will stop you signing in, because that cookie is what signing in means. The marketing site reads perfectly well with every cookie blocked.

6. Changes, and who to ask

This page is part of our Privacy Notice, which explains everything else we do with data, and it changes when the inventory above changes, not on a schedule. Questions about any of it go to hello@velur.io, and the legal details of who is behind Velur are on the Imprint.