Cookie Policy
Last updated: August 23, 2026
1. Current position
Fullink currently uses essential authentication cookies when you sign in. It does not configure advertising cookies, preference cookies, or cookie-based site analytics. This policy describes the implementation verified on the date above; browser tools show the definitive cookies for your session.
2. Essential authentication cookies
Supabase authentication stores one or more cookies whose names can vary with the Supabase project and session format. They hold or refresh authenticated session state so Fullink can keep you signed in and authorize account requests. They expire according to the session attributes sent to your browser, or when you sign out or delete them.
Fullink checks the Origin or Referer header on authenticated state-changing requests. It does not currently set a cookie named csrf-token.
3. Cookieless measurements
Fullink uses Vercel Web Analytics for aggregate page-view measurement on public pages. Fullink excludes authentication, onboarding, dashboard, success, and API paths before collection and removes query strings and URL fragments. Vercel describes the service as using anonymized data without third-party cookies; see Vercel's Web Analytics privacy documentation.
Fullink also records a server-side event when someone activates a creator link. That event can include the creator and link identifiers, referrer, UTM source, and requesting IP address. This is not implemented with a browser cookie, but it is described in the Privacy Policy.
4. Payment and external services
Checkout and billing are hosted by Stripe. Stripe may use cookies and similar storage on its own pages for payment, security, and fraud-prevention purposes. See Stripe's Privacy Policy. Links on a public profile can take you to other sites with their own cookie practices.
5. Your controls
Your browser lets you inspect, block, or delete cookies and site storage. Blocking Fullink's essential authentication cookies will prevent sign-in and authenticated dashboard features from working. Public marketing and creator pages remain available without an authenticated session.
6. Changes and contact
Fullink will update this policy before intentionally enabling non-essential cookie categories and will request consent where required. Questions can be sent to privacy@fullink.io or support@fullink.io.