Cookie Policy
Last updated: September 2026
This policy explains what Velvet stores on your device when you visit velvet.fans, why, and what you can switch off. It covers cookies and the equivalent browser storage — localStorage and sessionStorage — because the rules are the same for all of them.
What This Covers
A cookie is a small file a site stores in your browser. Browsers also offer localStorage and sessionStorage, which do the same job by a different mechanism. European law treats them identically, so this policy lists everything Velvet stores, whichever mechanism it uses.
Strictly Necessary
These are required for the site to work at all. They are not optional and cannot be switched off, because without them you could not sign in, could not pass the age check, and could not complete a purchase.
- Session cookie (velvet_access_token). Keeps you signed in as you move between pages. Cleared when you sign out.
- Age-gate session (velvet_age_gate). Records that you passed the 18+ check. Signed by our server and set for the period your country requires — 60 minutes in France, 45 in Italy.
- Adult confirmation (velvet_age_verified). Remembers on this device that you confirmed you are an adult, so you are not asked repeatedly.
- Payment provider cookie. Set by our payment provider during checkout to verify and process your payment. It is not used to track you across other websites.
Preferences
These remember choices you made yourself. They are set only because you asked for the thing they remember, so they do not require separate consent, but you should know they are there.
- Language (NEXT_LOCALE). The interface language you selected.
- Theme (velvet-theme). Whether you chose light or dark mode.
- Cookie choice (velvet.cookie_consent). Your decision on this page, so we do not ask again. Refusing still has to be remembered somewhere.
- Region (velvet.consent_region). Which privacy rules apply to you, resolved from your IP address and kept only for the current browser session.
Audience Measurement — your choice
We use Umami, an analytics tool we host ourselves on our own infrastructure. It sets no cookies, assigns you no cross-site identifier, and shares nothing with any third party; it records the page, the referrer, the browser, the operating system, the device type and the country. We still ask, because it is your device.
- Umami. Off unless you allow it. Aggregated counts only — never sold, never shared for advertising.
Advertising — your choice
When we are running a paid campaign, we use Google Ads conversion tracking to learn whether an advert led to a signup. This is the only technology on Velvet that hands anything to a third party for advertising purposes, and it is off by default.
- Google Ads (gtag.js). Loaded only after you allow advertising, and never at all when no campaign is configured. It stores a Google advertising identifier on your device and reports conversions back to Google. We do not sell your data, and we do not build advertising profiles from what you do on other websites.
Attribution
Two items record where a visit came from so that a referral is credited to the right person. They are written on arrival and are not currently behind the choices above; we are reviewing that, and this section will be updated when it changes.
- Affiliate code (velvet_aff_code). Stored when you arrive through a link containing an ?aff= code, so the referrer is credited if you later subscribe or buy.
- Campaign (velvet.landing_campaign). The utm_source, utm_medium and utm_campaign values from the link you arrived on, kept for the current browser session only.
Third Parties That Receive Data
Loading a page necessarily tells whoever serves its parts that your browser asked for them, including your IP address. For completeness:
- Payment provider. Processes your payment during checkout. Card details are handled entirely by them and never stored by Velvet.
- Google Fonts and Fontshare. Serve the typefaces the site is set in. Your IP address reaches them as part of that request.
- Firebase Authentication. Used for sign-in. Handles your credentials during authentication only.
- Age verification provider. Runs the 18+ check when you choose to verify. Only used when you start that flow.
Your Choices
If you are in the EEA, the UK or Switzerland, we ask before anything optional is stored, and refusing is one click, exactly like accepting. Elsewhere, optional storage is permitted until you turn it off — which you can do here, at any time, with the same effect. Your decision is remembered on this device; changing browser or clearing your data will bring the question back.
Managing Storage In Your Browser
Your browser can also view, delete and block this storage directly. Because the strictly necessary items are required for the site to function, blocking them may stop you signing in or using parts of Velvet.
Where to find the controls:
- Chrome: Settings > Privacy and security > Cookies and other site data
- Firefox: Settings > Privacy & Security > Cookies and Site Data
- Safari: Preferences > Privacy > Manage Website Data
- Edge: Settings > Cookies and site permissions > Manage and delete cookies and site data
Changes To This Policy
We will update this page when what we store changes, with a new last-updated date. If a change adds anything that needs your consent, we will ask you again rather than relying on a choice you made about something else.
Contact
Velvet
Velvet — postal address available upon written request
Email: support@velvet.fans