Cookies
What we set, why, and how to control them.
Last updated: 9 June 2026
What cookies are (and what they aren’t)
Cookies are small text files your browser stores on your device when you visit a website. Some are essential for a service to work (eg. keeping you signed in). Others are analytics or marketing — these are only set if you’ve agreed to them.
Get Set Gig also uses local storage on your device (similar to cookies, but with a different mechanism) for a couple of small preferences. We’ve listed those at the bottom for transparency. Under UK GDPR and the Privacy and Electronic Communications Regulations (PECR), local storage gets the same consent treatment as cookies.
Essential cookies
Always on, required to provide the service you signed up for. No consent needed under PECR Regulation 6(4) (the “strictly necessary” exemption).
| Name | Purpose | Retention |
|---|---|---|
sb-<project-ref>-auth-token |
Supabase authentication. Keeps you signed in across visits. | Up to 60 days, sliding (refreshed on each visit) |
sb-<project-ref>-auth-token-code-verifier |
Short-lived PKCE verifier used by the magic-link / OAuth sign-in flow. | Cleared when sign-in completes |
gsg-active-band |
Remembers which band you’re currently viewing, if you’re in more than one. | 1 year |
gsg-analytics-consent |
Records your analytics choice so we don’t ask again. | 1 year |
Analytics cookies
Only set if you’ve chosen “Allow analytics” in the consent banner or on the Account page. Can be turned off at any time from the Account page; turning them off removes them from your browser too.
| Name | Purpose | Retention |
|---|---|---|
ph_* (PostHog) |
Anonymised product analytics — which features are used, what fails. Stored in PostHog’s EU region. | Up to 1 year |
Local storage we use
Small preferences stored on your device for the convenience of the app. None of this leaves your browser.
| Key | Purpose | Retention |
|---|---|---|
gsg:stage:reading-mode |
Whether you prefer Lyrics or Chart on the on-stage view. | Until you clear browser data |
gsg:install-prompt:dismissed-at |
Timestamp of the last time you dismissed the “install this app” prompt, so we don’t nag you for a week. | Until you clear browser data |
How to control cookies and storage
- In the app — turn analytics on or off any time on the Account page. Refusing analytics doesn’t affect your access to anything.
- In your browser — every browser lets you block or clear cookies and local storage. Blocking the essential cookies above will sign you out and break sign-in.
Third-party services and cookies
We don’t run any third-party advertising, social-media, or cross-site tracking pixels.
When you choose to sign in with Google or Microsoft, those providers will set their own cookies on their own domains during the sign-in handshake. Those cookies are covered by their respective privacy policies, not ours.
Google Maps calls (used for drive-time and venue lookup) are server-side from our application — Google doesn’t set cookies in your browser as a result.
Changes
If we add new cookies or change how existing ones are used, we’ll update this page and the “Last updated” date at the top. Where the change introduces a non-essential cookie, we’ll ask for fresh consent.
Contact
Cookie questions — rob.wilson@getsetgig.com.