Last updated October 4, 2026
Cookie policy
Cookies are small files a website stores in your browser. SubmitStorm sets one kind without asking, because the site cannot work without it (the law calls these strictly necessary), and one kind only with your consent: Google Analytics. There are no advertising, social or cross-site tracking cookies. Apart from our network and security provider's security cookies (Section 1), no one else sets cookies on submitstorm.com.
1. Strictly necessary cookies
On a secure connection the names below carry a __Secure- prefix.
- better-auth.session_token (SubmitStorm): Keeps you signed in after you sign in. Lasts: 7 days, renewed while you use the site; gone when you sign out.
- better-auth.state, better-auth.pk_code_verifier (SubmitStorm): Protects the Google sign-in handshake against forged requests. Set only while you sign in with Google. Lasts: Minutes.
- better-auth.dont_remember (SubmitStorm): Remembers that you asked not to stay signed in on this device, if that option is used. Lasts: Until you close the browser.
Our network and security provider, which carries every connection to the site, may also set its own strictly necessary security cookies, for example after it checks that a visitor is a person. The sign-up form shows that provider's human check, which loads from the provider's own domain.
2. Analytics cookies, only with your consent
If you choose "Accept analytics" in the cookie banner, we load Google Analytics 4 and it sets the cookies below. We use it to count visitors and to see which pages and directory lists are read; IP addresses are shortened before storage, we do not use advertising features, and the data is not joined to your account. Nothing from Google loads before you say yes, wherever you are. If you choose "Only necessary", or withdraw later, the cookies below are deleted and Google Analytics is not loaded again.
- _ga (Google Analytics (Google Ireland Limited / Google LLC)): Tells returning visits from new ones with a random client id, so we can count visitors and see which pages help. Lasts: 2 years.
- _ga_<property id> (Google Analytics): Keeps the current visit together (session state). Lasts: 2 years.
3. Browser storage
One local storage item, cookie_consent: your answer in the banner, when you gave it, and the version of the question. It is how we remember not to ask again. No session storage. The admin pages we use to run the service register a service worker for push alerts to our own phones; it never runs for customers.
4. Other sites you may be sent to
- Payments happen on Stripe Checkout (checkout.stripe.com), on Stripe's own site under Stripe's cookie policy. We load no Stripe code on submitstorm.com.
- Google sign-in, if you choose it, happens on Google's site under Google's policies; we receive only the result.
- Badges and directory screenshots on our public pages are images served from our own domain. The badge component loads each badge image from its directory's own domain: in the preview on your order page, and on your own site when a visitor views your page. Those image requests set no cookies of ours.
5. How to change your choice
- Use Cookie settings in the footer of every page: the banner comes back and you can answer again.
- Your browser can show, delete or block cookies for submitstorm.com at any time. Blocking the session cookie means you cannot stay signed in.
6. Changes
We update this page whenever what we set changes, and ask for your consent again when a change affects what you agreed to. Questions: [email protected]. See also the privacy policy.