Lounge & MinglePre-publication draft technically reviewed: 14 August 2026
This policy explains how Lounge & Mingle uses cookies and similar browser storage. The service is currently in testing. We will re-audit the deployed build and obtain legal approval before assigning a production effective date.
Essential storage provides features you request, protects accounts, completes onboarding, and remembers your cookie choice. It cannot be switched off through the consent manager. Personalisation storage is optional and remains off unless you allow it.
You can accept optional storage, continue with essential storage only, or make a granular choice. Use the cookie button at the bottom of any page to change or withdraw your choice later. Withdrawing Personalisation clears the lm_vibe theme cookie.
We currently use seven first-party cookies. We do not use advertising, cross-site tracking or audience analytics cookies.
| Name | Category | What it does | Lasts |
|---|---|---|---|
__Host-next-auth.session-token | Essential | Keeps you signed in (development uses next-auth.session-token). | 7 days |
lm_otp_intent | Essential | Protects and completes an email one-time-code request. | 5 minutes |
onboarding-draft | Essential | Preserves encrypted onboarding answers between steps. | 24 hours |
onboarding-view-step | Essential | Remembers the current onboarding step. | 24 hours |
onboarding-selected-plan | Essential | Remembers the plan selected during onboarding. | 24 hours |
lm_notification_display_mode | Essential (requested preference) | Applies your selected notification view. | 180 days |
lm_vibe | Personalisation | Applies the visual theme you selected. | 1 year |
The production session cookie uses the __Host- prefix, which requires HTTPS, root-path scope and no subdomain scope. Its development name is next-auth.session-token.
onboarding-draft deserves a fuller explanation because it can hold answers entered during sign-up, including name, age, gender, location, education, job, income bracket, interests and sensitive profile information. It is encrypted before storage, HTTP-only, SameSite=Strict, scoped to/onboarding, secure in production, and expires after 24 hours.
Immediate deletion after successful onboarding is intended but is not implemented in the current pre-publication build. Until that is corrected, the cookie can remain until its 24-hour expiry unless you clear site data. Storage protection does not replace a lawful basis or the separate explicit consent required for special-category data.
We self-host the open-source Silktide Consent Manager files. Loading the banner does not contact Silktide. The manager stores your Essential and Personalisation choices, this policy version, and the time of your decision in this browser under keys beginning stcm.lounge-mingle-v1.
These records are treated as essential because they remember your storage choice in this browser. They are not copied into a server-side cookie-consent ledger. We ask again after 180 days or when the policy version changes. The implementation removes the upstream Silktide credit link, so normal use of the banner does not take you to Silktide.
We use per-tab session storage for one-time-code flow state and a cached map image. Session storage normally disappears when the tab closes. If you allow push notifications, your device issues a token that identifies the device for delivery; it is not a cookie and can be revoked in browser or device settings.
Notification realtime is handled by our server and does not add another browser cookie. The notification display preference in the table is the only dedicated notification cookie we set. We do not create our own persistent device fingerprint. Cloudflare Turnstile evaluates browser and device signals to distinguish people from abusive automation.
LinkedIn may set cookies when you choose LinkedIn sign-in. Stripe may set cookies on Stripe-hosted Checkout or the billing portal for payment security and fraud prevention. Their notices apply on their sites. Cloudflare Turnstile runs on protected authentication forms. The current implementation does not enable Turnstile pre-clearance or intentionally set a cf_clearance cookie; we will re-audit the deployed configuration.
We do not configure advertising, retargeting, conversion-tracking or audience-analytics storage. There is no Google Analytics, Google Tag Manager, Meta Pixel, PostHog, Mixpanel, Segment, Amplitude, Plausible, Hotjar or Microsoft Clarity integration in the reviewed build. We do not sell or share information for advertising.
You can reopen our cookie settings at any time or delete and block storage in your browser. Blocking essential authentication or request-protection storage prevents the corresponding requested feature from working. Cookies and storage that identify you involve personal data, so the rights in our Privacy Policy apply.
Cookies and similar storage are also governed by the Privacy and Electronic Communications Regulations 2003. Storage that is not strictly necessary requires the appropriate consent before it is used. The browser Do Not Track signal has no agreed implementation standard; we do not track you across websites in the first place.
We will update this inventory whenever storage changes. Non-essential storage will not be enabled before the required consent is available, and rejecting will remain as easy as accepting. Questions and privacy rights requests can be sent to privacy@loungeandmingle.com.
Lounge and Mingle Ltd, 5 Brayford Square, London, England, E1 0SG. Registered in England and Wales, company number 15163115.
← Back to Legal Centre