Lounge & Mingle

Cookie Policy

Pre-publication draft technically reviewed: 14 August 2026

This policy explains how Lounge & Mingle uses cookies and similar browser storage. The service is currently in testing. We will re-audit the deployed build and obtain legal approval before assigning a production effective date.

1. Your choices

Essential storage provides features you request, protects accounts, completes onboarding, and remembers your cookie choice. It cannot be switched off through the consent manager. Personalisation storage is optional and remains off unless you allow it.

You can accept optional storage, continue with essential storage only, or make a granular choice. Use the cookie button at the bottom of any page to change or withdraw your choice later. Withdrawing Personalisation clears the lm_vibe theme cookie.

2. Cookies used by the current test build

We currently use seven first-party cookies. We do not use advertising, cross-site tracking or audience analytics cookies.

NameCategoryWhat it doesLasts
__Host-next-auth.session-tokenEssentialKeeps you signed in (development uses next-auth.session-token).7 days
lm_otp_intentEssentialProtects and completes an email one-time-code request.5 minutes
onboarding-draftEssentialPreserves encrypted onboarding answers between steps.24 hours
onboarding-view-stepEssentialRemembers the current onboarding step.24 hours
onboarding-selected-planEssentialRemembers the plan selected during onboarding.24 hours
lm_notification_display_modeEssential (requested preference)Applies your selected notification view.180 days
lm_vibePersonalisationApplies the visual theme you selected.1 year

The production session cookie uses the __Host- prefix, which requires HTTPS, root-path scope and no subdomain scope. Its development name is next-auth.session-token.

3. The sign-up draft cookie

onboarding-draft deserves a fuller explanation because it can hold answers entered during sign-up, including name, age, gender, location, education, job, income bracket, interests and sensitive profile information. It is encrypted before storage, HTTP-only, SameSite=Strict, scoped to/onboarding, secure in production, and expires after 24 hours.

Immediate deletion after successful onboarding is intended but is not implemented in the current pre-publication build. Until that is corrected, the cookie can remain until its 24-hour expiry unless you clear site data. Storage protection does not replace a lawful basis or the separate explicit consent required for special-category data.

4. Consent records in local storage

We self-host the open-source Silktide Consent Manager files. Loading the banner does not contact Silktide. The manager stores your Essential and Personalisation choices, this policy version, and the time of your decision in this browser under keys beginning stcm.lounge-mingle-v1.

These records are treated as essential because they remember your storage choice in this browser. They are not copied into a server-side cookie-consent ledger. We ask again after 180 days or when the policy version changes. The implementation removes the upstream Silktide credit link, so normal use of the banner does not take you to Silktide.

5. Session storage and similar technologies

We use per-tab session storage for one-time-code flow state and a cached map image. Session storage normally disappears when the tab closes. If you allow push notifications, your device issues a token that identifies the device for delivery; it is not a cookie and can be revoked in browser or device settings.

Notification realtime is handled by our server and does not add another browser cookie. The notification display preference in the table is the only dedicated notification cookie we set. We do not create our own persistent device fingerprint. Cloudflare Turnstile evaluates browser and device signals to distinguish people from abusive automation.

6. Cookies set by other services

LinkedIn may set cookies when you choose LinkedIn sign-in. Stripe may set cookies on Stripe-hosted Checkout or the billing portal for payment security and fraud prevention. Their notices apply on their sites. Cloudflare Turnstile runs on protected authentication forms. The current implementation does not enable Turnstile pre-clearance or intentionally set a cf_clearance cookie; we will re-audit the deployed configuration.

7. What we do not use

We do not configure advertising, retargeting, conversion-tracking or audience-analytics storage. There is no Google Analytics, Google Tag Manager, Meta Pixel, PostHog, Mixpanel, Segment, Amplitude, Plausible, Hotjar or Microsoft Clarity integration in the reviewed build. We do not sell or share information for advertising.

8. Controlling storage and your rights

You can reopen our cookie settings at any time or delete and block storage in your browser. Blocking essential authentication or request-protection storage prevents the corresponding requested feature from working. Cookies and storage that identify you involve personal data, so the rights in our Privacy Policy apply.

Cookies and similar storage are also governed by the Privacy and Electronic Communications Regulations 2003. Storage that is not strictly necessary requires the appropriate consent before it is used. The browser Do Not Track signal has no agreed implementation standard; we do not track you across websites in the first place.

9. Changes and contact

We will update this inventory whenever storage changes. Non-essential storage will not be enabled before the required consent is available, and rejecting will remain as easy as accepting. Questions and privacy rights requests can be sent to privacy@loungeandmingle.com.

Lounge and Mingle Ltd, 5 Brayford Square, London, England, E1 0SG. Registered in England and Wales, company number 15163115.

← Back to Legal Centre