Version 2026-08-v1
Cookie Policy
Controller: Werhner Lab
Website: werhnerlab.com
Language: English (this is the binding version)
This Policy explains which cookies and similar technologies Werhner Lab uses, why, and how you can control them.
1. What cookies are
Cookies are small files stored on your device. We also use similar tools (local storage, session storage, security tokens) needed for login and checkout.
2. Who sets them
Werhner Lab sets first-party cookies on werhnerlab.com. Some third parties may set cookies if you use their service (payment gateway, Cloudflare security, optional analytics if enabled).
3. Categories we use
3.1 Strictly necessary (always on)
These are required for the site to work. They do not need consent under EU rules.
| Purpose | Examples |
|---|---|
| Login / session | Supabase Auth session, refresh token |
| Account security | CSRF / anti-abuse tokens |
| Cart and checkout | Cart contents, checkout step |
| Cookie choice | Stores your banner decision |
| Load / attack protection | Cloudflare or similar WAF cookies |
Without these cookies you cannot sign in, keep a session, or complete an order.
3.2 Analytics (only with consent)
If enabled, we may use privacy-respecting analytics (for example EU-hosted or cookieless metrics) to see which pages are used. Not set until you accept. You can refuse and still buy.
3.3 Marketing (off by default)
We do not currently use advertising cookies. If that changes, they will appear in the banner and will require opt-in.
4. How long they last
Session cookies: deleted when you close the browser or when the login expires. Persistent cookies: kept only as long as needed (login "remember me", cookie preference, security). Typical range: hours to 12 months.
Exact names and lifetimes can change when we update Auth or hosting. The categories stay the same.
5. Legal basis
Necessary cookies: Art. 6(1)(b) GDPR (contract / requested service) and ePrivacy necessity. Analytics / marketing: Art. 6(1)(a) GDPR (consent). You may withdraw at any time.
6. How to control cookies
The cookie banner on first visit (and via "Cookie settings" in the footer). Your browser settings (block or delete cookies). Email [email protected] for questions.
If you block necessary cookies, login and checkout will fail.
7. Third parties
- Supabase Auth — session cookies / tokens for email login and magic link.
- Payment provider (CoinGate, Bitnovo Pay, or the provider shown at checkout) — may set cookies on their payment page. Their policy applies there.
- Cloudflare (or similar) — security cookies to filter bots and attacks.
We do not sell cookie data.
8. Changes
We may update this Policy when tools change. The published version on this page applies.
Contact: [email protected]