This policy explains what cookies and similar storage technologies Suth Performance uses, why we use them, and how to opt out. We list every cookie we set, by category, in the tables below.
Suth Performance is operated by [REGISTERED COMPANY NAME TO BE CONFIRMED], a company registered in England and Wales, company number [COMPANIES HOUSE NUMBER TO BE CONFIRMED], registered office [REGISTERED OFFICE ADDRESS TO BE CONFIRMED].
What is a cookie?
A cookie is a small text file stored in your browser by a website you visit. We also use similar technologies (localStorage, sessionStorage, IndexedDB) which work the same way for the purposes of this policy. When we say “cookies” we mean all of these.
Cookies are how a website remembers things between page loads, like the fact that you accepted the cookie banner or that you started a quiz two days ago. Some cookies are essential; others power analytics or third-party features and only run with your consent.
Categories
- Strictly necessary. Always on. The site does not work without them.
- Analytics. Off by default. Loaded only after you accept Analytics in the cookie banner. Used to understand product usage in aggregate.
- Functionality (third party). Set by services we embed, like Stripe checkout or the optional live chat. Each only loads in context, not on every page.
- Marketing. None at the moment. If we add ad pixels in future, they will be opt-in via the banner and listed here before being switched on.
Strictly necessary cookies
Always on. Required for the site to function. No opt-out, because the site does not work without them.
These cookies keep you signed in across page loads, remember the choices you made in the onboarding quiz so a refresh does not throw away your progress, hold your shopping basket on the checkout page, and prevent cross-site request forgery on every form. Removing them would make the service unusable, not just inconvenient.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| suth:consent:v1 | Suth Performance (localStorage) | Remembers your cookie banner choices so we do not ask again every visit. | 12 months |
| suth:quiz:state | Suth Performance (localStorage) | Remembers your quiz progress so you can refresh or come back later. | 30 days |
| suth:customer:uuid | Suth Performance (localStorage) | Anonymous identifier for your quiz session. Linked to your account when you complete the email gate. | 12 months |
| __Host-next-auth.csrf-token | Suth Performance (session cookie) | CSRF protection on form submissions. | Session (cleared when you close the browser) |
| sb-access-token / sb-refresh-token | Supabase | Keeps you logged in across visits. | Access: 1 hour. Refresh: 30 days. |
Analytics cookies
Off by default. Loaded only after you accept Analytics in the cookie banner. Used to understand which pages perform, where the funnel breaks, which programmes interest people. Pseudonymous; we never match analytics events to your real name or email.
Analytics data is retained for 14 months and then aggregated into a rolling annual snapshot that contains no individual identifiers. We use it to decide which posts to write next, which programme pages need to be clearer, and where to invest engineering time. We do not sell analytics data to anyone, run remarketing against it, or use it for pricing decisions.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| ph_* | PostHog (EU) | Pseudonymous session and event tracking. Used to understand which pages perform and where the funnel breaks. Session replay masks all inputs. | 12 months (rolling) |
Third-party cookies
Set by services we embed. Each loads only in context:
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| __stripe_mid / __stripe_sid / m | Stripe | Fraud screening and session continuity during card payment. Set only during checkout. | Session to 12 months |
| crisp-client/* | Crisp (when live chat enabled) | Powers the in-page chat widget on /contact. Only set if you open the chat. | 6 months |
| Sanity Studio cookies | Sanity | Only set on /studio for editors. Public visitors never see these. | Session |
Stripe's cookie policy: stripe.com/cookies-policy/legal.
First-party vs third-party cookies
A first-party cookie is set by the domain you are visiting (suthperformance.com or its subdomains). A third-party cookie is set by a different domain embedded into the page (for example, an analytics script loaded from a vendor domain). First-party cookies are restricted to the original site; third-party cookies can in principle be read by the third party across any site that embeds them.
Most modern browsers (Safari, Firefox, Brave by default; Chrome gradually) restrict or block third-party cookies. We design the service to work without them: every analytics signal we use is either first-party or pseudonymous, and the checkout flow does not rely on third-party tracking. Blocking third-party cookies in your browser settings has no effect on your Suth Performance experience.
Consent management
Our cookie banner appears on your first visit and records your choice in a first-party cookie that lasts 12 months. You can re-open the banner at any time from the footer link "Cookie settings" and change your mind. There are no dark patterns: the accept and reject buttons are the same size and visual weight, and rejection takes effect immediately.
If you sign in across multiple devices, your consent preference is device-specific (because cookies are device-scoped). You can set the same preference on each device by visiting the banner once.
Cookie lifetimes
Session cookies are deleted when you close the browser. Persistent cookies have a defined expiry, listed in the tables above. The longest persistent cookie we set is 12 months (the consent record itself), so we can avoid showing the banner every time you visit. Everything else expires within 30 days. We do not extend any cookie's lifetime retroactively, and we do not refresh cookies on subsequent visits in order to keep them alive past their stated duration. When a cookie expires it is removed by the browser at the next visit; we do not attempt to reconstruct prior state from any other source.
Do Not Track
When your browser sends a Do Not Track signal, we treat it as a refusal of Analytics consent. The banner still appears (so you can flip the switch later), but analytics scripts will not load until you explicitly accept. This goes beyond what the law currently requires.
How to opt out
- In the Suth Performance banner. Reject all non-necessary on first visit, or re-open the banner from the footer at any time to change your mind.
- In your browser. Each major browser lets you clear, block, or restrict cookies:
- Safari (macOS / iOS): Settings → Safari → Privacy & Security → Block All Cookies.
- Chrome: Settings → Privacy and security → Cookies and other site data.
- Firefox:Settings → Privacy & Security → Cookies and Site Data.
- Edge: Settings → Cookies and site permissions → Manage and delete cookies and site data.
- Private / incognito mode. Most cookies do not persist past the session.
Blocking strictly necessary cookies will break parts of the site (the quiz, the checkout, staying logged in). Blocking analytics cookies has no effect on your experience.
Changes to this policy
We update this page whenever we add or remove a cookie. Material changes are also flagged in the cookie banner on your next visit so you can reconfirm your choices.
Contact
Questions about cookies: privacy@suthperformance.com.