Cookies Policy
Last updated 16 June 2026
- Advertising cookies
- None set by the Studio
- Cross-site tracking
- Not used
- Analytics
- Privacy-friendly aggregate counts only, where enabled
- Strictly necessary
- Authentication session, security challenge, currency preference
- Third-party storage
- Only the regulated card payment fields when checkout is open
- Manage
- Clear or block at any time via your browser settings
This Cookies Policy describes the cookies and similar browser storage technologies used by Xylora Studios in connection with the operation of xylorastudios.com, the categories into which such technologies fall, the lawful bases on which they are deployed and the means by which they may be managed by the User.
The Studio does not employ advertising cookies, cross-site tracking pixels or third-party profiling technologies.
Scope and interpretation
- 1.1
This Cookies Policy (the “Policy”) is published by Xylora Studios (“the Studio”) in accordance with the Privacy and Electronic Communications (EC Directive) Regulations 2003 (as amended) and the relevant provisions of the United Kingdom General Data Protection Regulation. It describes the cookies, local-storage entries, session-storage entries and similar browser storage technologies (collectively, “Storage”) which may be set when a user (“the User”) accesses xylorastudios.com (the “Site”).
- 1.2
This Policy is to be read in conjunction with the Studio’s Privacy Policy and Terms of Service.
The Studio's approach to Storage
- 2.1
The Studio does not employ advertising cookies, cross-site tracking pixels or third-party profiling technologies. Storage is used solely for the operation, security, payment processing, account access and limited functional preference of the Site.
- 2.2
Where consent is required by applicable law, no non-essential Storage shall be set until such consent has been obtained. The categories of Storage currently in use are set out in the tables below.
Strictly necessary Storage
- 3.1
The following items of Storage are strictly necessary for the operation of the Site within the meaning of regulation 6(4) of the Privacy and Electronic Communications Regulations and may be set without the User’s consent.
- 3.2
Identifier Category Purpose Duration sb-* Strictly necessary Maintains the User's authenticated session and enables safe refresh of access tokens following sign-in. Until sign-out, expiry or removal by the User. edge-security-clearance Strictly necessary Permits the edge security layer to confirm that requests originate from a legitimate session and reduces repeated security challenges. Short-term; controlled by the edge security provider. human-verification-token Strictly necessary Stores the response to a one-time challenge in connection with the submission of public forms. Single submission or short expiry.
Functional preference Storage
- 4.1
The following items of Storage record functional preferences expressed by the User and are retained solely on the User’s device. They may be deleted at any time through the User’s browser settings.
- 4.2
Identifier Category Purpose Duration xy-currency Functional preference Records the User's chosen display currency when reviewing package prices and line-item totals. Persistent until amended or cleared by the User. browser-locale-signal Functional preference Permits the Site to suggest an initial currency on the basis of the browser locale where the User has expressed no preference. Read from the browser; not separately set by the Studio.
Third-party Storage set on the Site
- 5.1
The edge security provider may set short-lived Storage in the User’s browser for the purpose of evaluating whether the User’s session is interacting with the Site in the expected manner.
- 5.2
The regulated payment service provider may set Storage within its hosted payment fields when the embedded checkout is mounted, for the purposes of fraud prevention, payment authentication and receipt handling. Such Storage is subject to the cookie notice published by that provider. The Studio does not receive the contents of the User’s messages, account profile or browsing history through such third-party Storage.
Lawful bases
- 6.1
Strictly necessary Storage is set on the basis of the Studio’s legitimate interest in operating a secure and functional Site, and does not require consent under the Privacy and Electronic Communications Regulations.
- 6.2
Functional preference Storage is set in consequence of the User’s express selection of a preference and is retained solely on the User’s device.
- 6.3
Security signals — including human-verification challenges and rate-limiting tokens — are set on the basis of the Studio’s legitimate interest in protecting the Site against fraud and abuse.
- 6.4
Non-essential Storage is not currently in use. Should the Studio introduce any such Storage, consent shall be obtained before it is set and this Policy shall be updated accordingly.
Retention periods
- 7.1
Storage is retained for the periods specified in the tables above, save that:
- 7.2
(a) authentication sessions ordinarily persist for up to seven (7) days, refreshed on activity and cleared on sign-out; (b) checkout-intent Storage is cleared on success, failure or after one (1) hour of inactivity; (c) human-verification tokens have a lifetime measured in minutes and are reissued per challenge; and (d) functional preferences persist until amended or cleared by the User.
User controls
- 8.1
The User may, at any time, manage Storage through the privacy or developer tools of his or her browser, including by clearing all Storage in respect of xylorastudios.com, by using private browsing, by signing out of any customer account, or by configuring the browser to reject specified categories of Storage.
- 8.2
The Studio does not currently honour global automated signals other than as expressly stated. Where Global Privacy Control is enabled by the User’s browser, it shall not affect strictly necessary Storage but shall be honoured in respect of any non-essential Storage subsequently introduced.
Consequences of blocking Storage
- 9.1
Blocking strictly necessary Storage may result in the User being signed out, the failure of protected account actions, the interruption of human-verification checks, the interruption of checkout, or the failure of form submissions. Blocking functional preference Storage shall not prevent the Site from loading, but may require the User to re-select preferences (such as display currency) on each visit.
Server-side records
- 10.1
Server logs, internal event records, payment records and abuse-prevention counters are maintained on the Studio’s systems and do not constitute Storage within the meaning of this Policy. The processing of such records is described in the Studio’s Privacy Policy.
Amendments
- 11.1
The Studio may amend this Policy from time to time. The version in force from time to time shall be the version published on the Site, together with the date of last revision shown above. New entries shall be added to the relevant table before the corresponding Storage is set.
