Legal

Cookie Policy

Last updated: 1 June 2026 · Version 1.0

In short: GhostCoach uses only the cookies and browser storage that are strictly necessary to sign you in, process your payments, and let the site work. We do not use analytics, advertising, or tracking cookies. Because of this, we do not need to ask for your consent to set these — but we want you to know exactly what they do.

This page explains what we store in your browser and why. It sits alongside our Privacy Policy, which covers how we handle your personal data more broadly.


1. What cookies and similar technologies are

“Cookies” are small text files a website stores in your browser. Websites also use related technologies — localStorage and sessionStorage — which work similarly but live in your browser's storage rather than as classic cookies. Throughout this policy, “cookies” refers to all of these unless we say otherwise.

Some are strictly necessary: the site cannot function without them. Others are optional and require your consent before they are set — for example analytics or advertising. GhostCoach currently uses only strictly necessary ones.


2. What we use them for

We do not use cookies to track your behaviour, build a profile of you, measure analytics, or serve advertising.


3. Cookies and storage we use

Every item below is strictly necessary to provide the service you have requested. None requires consent under the ePrivacy Directive or the Dutch Telecommunications Act.

NameTypeDurationCategoryPurpose
sb-…-auth-tokenlocalStorageUntil logoutStrictly necessaryKeeps you signed in across pages (Supabase authentication).
__stripe_midCookie1 yearStrictly necessaryStripe fraud prevention. Set only on payment pages.
__stripe_sidCookie30 minutesStrictly necessaryStripe fraud prevention (short-lived). Payment pages only.
gc_cookie_consentlocalStorageUntil clearedStrictly necessaryRemembers your cookie-notice choice so we don't re-ask.
gc_signupsessionStorageUntil tab closesStrictly necessaryCarries signup form data between steps.
gc_onboarding_partialsessionStorageUntil tab closesStrictly necessaryPreserves onboarding input if you navigate away.
gc_api_keysessionStorageUntil tab closesStrictly necessaryHolds your Anthropic API key during a chat session (Phase 1).

Note on Stripe cookies: __stripe_mid and __stripe_sid are set by Stripe.js but appear as first-party cookies on getghostcoach.com. They are used solely for payment security and fraud prevention, and only on our payment pages.


4. Third-party services and integrations

Some features rely on third parties. Where these involve your browser, we describe them here.

Stripe (payments)

Handles card payments and fraud prevention. Sets the two strictly-necessary cookies listed above, only on payment pages. See Stripe's own cookie and privacy policies for details.

Google Fonts (typography)

Our fonts (DM Sans and Playfair Display) are served directly from getghostcoach.com. They are not loaded from Google's servers, so no data about you is shared with Google to display them.

Sign in with Google (optional)

If you choose to sign in using Google, you are redirected to that provider, which sets its own cookies on its own domains under its own policies. These are not GhostCoach cookies and we do not control them. You only encounter them if you actively choose that sign-in method. See Google's privacy policy for details.

Supabase, Anthropic, n8n, Beehiiv

These power authentication, AI responses, automation, and email. They process data on our servers or via secure API calls — they do not set cookies in your browser. How they handle your personal data is described in our Privacy Policy.

Beehiiv currently runs no tracking on this site. If we ever add email open/click tracking or analytics, we will update this policy and, where the law requires it, ask for your consent first.


5. International data transfers

Some of our providers process data in the United States. Where that involves your personal data, those transfers are governed by the safeguards described in our Privacy Policy (such as Standard Contractual Clauses or the EU–US Data Privacy Framework). See the Privacy Policy for the full picture.


6. Managing cookies

Because every cookie we use is strictly necessary, there is nothing optional to switch off — disabling them would stop core features like login and payment from working. You can still control cookies through your browser settings, including blocking or deleting them, though this may break parts of the site.

If we add optional cookies in future (for example analytics), we will show a consent control that lets you accept or reject them, and you will be able to change your choice at any time.


7. Children

GhostCoach is intended for adults running their own businesses. It is not directed at children and we do not knowingly collect data from anyone under the age of 16.


8. Changes to this policy

We may update this policy when our technology or practices change — for example if we add analytics. We will revise the “Last updated” date and, for significant changes affecting optional cookies, ask for your consent where required.


9. Contact

Questions about this policy or your data? Contact the data controller:

[Founder name], GhostCoach
[Street address], Amsterdam, Netherlands
Contact us via our contact form →

You also have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).