How BeardStyles uses necessary storage and optional Analytics
2026/08/17
This policy explains how BeardStyles uses cookies and similar browser technologies such as localStorage. We use only two categories on BeardStyles pages: Necessary and Analytics. Analytics is optional and remains off unless you explicitly allow it. Your choice is not inferred from scrolling, closing a panel, or otherwise using the website.
For more about the data involved, providers, retention, and privacy requests, read the Privacy Policy.
Cookies are small values that a website or provider asks a browser to store and return with later requests. localStorage is first-party browser storage that stays on the device until it expires under our rules or is cleared. Some necessary settings can also be kept in browser memory for the current page.
The exact storage available can vary by browser, sign-in method, and feature. Browser privacy tools may shorten or block storage independently of BeardStyles.
Necessary technology supports only the functions needed to operate a feature you request:
These functions are not used for advertising or optional measurement. Necessary technology cannot be turned off through the BeardStyles preferences panel because doing so would prevent the related function from working. You can block it in your browser, but account, security, language, theme, or payment features may then fail.
Optional Analytics uses Google Analytics to understand aggregated page use and approved product interactions. It loads only after you choose to allow Analytics and only on non-sensitive routes. Before that choice, BeardStyles does not load the Google tag or send Google Analytics or Google Tag Manager requests. Rejecting Analytics does not prevent sign-in, photo upload, preview generation, saving, payment, or support.
When allowed, Google Analytics may use first-party _ga and _ga_* cookies to distinguish browser activity. BeardStyles configures Google Analytics cookies for an absolute maximum of 60 days from creation and disables rolling renewal on later visits. Ads consent, Google Signals, ad personalization, and User-ID are disabled. BeardStyles sends page origin and path without query or hash, a similarly reduced referrer, and approved product events rather than email, user ID, or raw image URLs.
The approved commerce events are sign_up for a successful registration, login for a successful sign-in, begin_checkout after a Stripe Checkout Session is created successfully, and purchase after BeardStyles' internal payment record is confirmed as paid. Depending on the event, the custom commerce-event properties BeardStyles adds are limited to the authentication method, stable product category and key, currency and value, one item, and a random receipt transaction ID for purchase. BeardStyles does not add email, name, any BeardStyles internal user, session, or payment ID, any Stripe ID, image URL, callback URL, query, or hash as custom commerce properties.
BeardStyles keeps a minimal local one-shot receipt to prevent duplicate events. It is a server-side record rather than a cookie or browser identifier. Every receipt is user-linked, so account deletion removes it. A purchase receipt can also be payment-linked; if that internal payment row is removed, its linked receipt is removed. A pending auth receipt can be claimed only within 30 minutes after the successful session starts. For resolved auth and purchase receipts, sensitive event-payload fields used to build the event are cleared. A session identifier can help match an auth receipt, but this does not mean deleting an individual session removes the dedupe row. Refusal or consent-read failure omits the current event without later replay. Stripe and internal payment records remain the revenue truth; Google Analytics is an incomplete consenting-user sample.
Google's standard aggregated reports may continue beyond the two-month user/event-level retention described in the Privacy Policy. Analytics remains an optional category even when its reports are aggregated.
Some external requests occur only when you actively use a feature and are not optional Analytics:
Rejecting Analytics does not block these user-initiated requests. Google, GitHub, Stripe, jsDelivr, and Google Storage control their own sites or delivery systems under their respective policies. These requests do not authorize BeardStyles to enable Analytics.
On first visit after initialization, BeardStyles offers Accept analytics, Reject optional, and Customize with comparable access. Customize shows Necessary as always on and Analytics off by default. You can later open Cookie Settings in the footer to review, allow, reject, or withdraw Analytics without leaving the page.
Withdrawal closes the BeardStyles event gate, disables future Google Analytics sending, updates consent to denied, and attempts to expire accessible _ga, _ga_*, and other specifically recognized GA-related cookies on the current domain. Code already loaded in the page cannot be physically unloaded, so the controls rely on the event gate, Google disable state, denied consent update, cookie cleanup, and network verification. Earlier lawful processing is not undone.
You can also clear or block cookies and site data through your browser. Clearing the choice may cause BeardStyles to ask again; blocking storage causes Analytics to stay off. JavaScript-disabled visits cannot record an opt-in, so Analytics remains off.
| Category | Technology | Maximum configured lifetime |
|---|---|---|
| Necessary | Authentication, security, locale, theme, payment-continuity, and feature-specific storage | Varies according to the requested function and security need. It is not repurposed for advertising or optional measurement. |
| Necessary | Analytics consent preference in first-party localStorage | 180 days for either allow or reject, unless a policy version change expires it earlier. |
| Analytics | Google Analytics _ga and _ga_* cookies | 60 days from creation, with rolling renewal disabled. Withdrawal attempts to expire accessible copies sooner. |
Third-party pages and resource hosts listed in Section 5 apply their own storage and retention rules.
We may update this policy when browser technology, providers, or our practices change. The date above identifies the current version. We will post material changes prominently and will ask for a new choice when a version change makes the stored preference expire.
For questions about cookies, similar storage, or Analytics choices, email support@beardstyles.org or use the Contact page.