Legal
Cookie Policy
Still Bureau uses necessary security cookies, functional preference storage, and consent-controlled analytics on its own marketing pages. The analytics tag and attribution cookie do not load until you accept.
- Effective
- Last updated
01How we use cookies
A cookie is a small file a site stores in your browser. Still Bureau uses them for a narrow set of purposes: keeping you signed in, remembering that you unlocked a password-protected gallery or page, preserving security or workflow state, and remembering preferences. We also use local storage and session storage. Unlike cookies, those values are not attached automatically to every request; the application may read a stored value and send the information needed for an action you choose, such as checkout, proofing, or recording a banner view.
Authentication, security, and protected-content cookies are strictly necessary. Functional storage remembers choices such as theme, draft selections, and cart state. Optional analytics and its first-touch attribution cookie are created only after you accept on Still Bureau's own marketing pages.
This policy is part of the Privacy Policy.
02Strictly necessary cookies
Scroll horizontally to view all columns.
| Name | Purpose | Lifetime |
|---|---|---|
__Host-stillbureau_session | Signs you in to the dashboard. Signed, HTTP-only, and readable only by the server. | Until sign-out or up to 30 days; an account security policy can shorten it |
__Host-stillbureau_active_site | Stores the site identifier last selected in the dashboard. HTTP-only; authorization is checked separately on every request. | Up to one year, or until changed or cleared |
still_bureau_cognito_signup | Carries sign-up state between the registration form and the confirmation step. | Up to 24 hours — cleared once confirmed |
still_bureau_cognito_reset | Carries password-reset state between requesting a code and entering it. | Up to one hour — cleared once reset |
still_bureau_cognito_email | Carries pending email-change state while you confirm the new address. | Up to one hour — cleared once used |
__Host-still_bureau_google_auth_state | Validates a Google sign-in or sign-up callback and carries the selected authentication flow state. | Up to 10 minutes — cleared after the callback |
fh_gallery_<id> | Records that you unlocked a specific protected gallery, and which invited recipient you are. | Up to 30 days, or an earlier gallery-session expiry |
fh_gallery_download_<id> | Records that you entered the download PIN for a specific gallery. | Up to 30 days, or an earlier gallery-session expiry |
fh_site_<id> | Records that you entered the password for a protected photographer site. | Up to 30 days, tied to the current password |
fh_page_<id> | Records that you entered the password for a single protected page. | Up to 30 days, tied to the current password |
fh_project_<id> | Records that you unlocked a shared client project portal. | Up to 30 days, tied to the current password |
__Host-fh_ip_bypass_<siteId> | Records a successful emergency recovery-phrase check for a site's IP restriction. | Up to one hour |
03Functional and preference cookies
Scroll horizontally to view all columns.
| Name | Purpose | Lifetime |
|---|---|---|
sidebar_state | Remembers whether the dashboard sidebar is expanded or collapsed. | Up to seven days |
04Browser storage
These values stay in browser storage until the application or you clear them. The browser does not automatically attach them to requests. The application can use their contents when you perform the related action. Clearing site data removes them.
Scroll horizontally to view all columns.
| Key | Purpose |
|---|---|
stillbureau_platform_analytics_consent | Your accept-or-refuse choice for analytics on Still Bureau's own marketing pages. |
stillbureau_analytics_consent_<siteId> | Your accept-or-refuse choice for analytics on an individual photographer's site. |
theme | Whether you chose the light, dark, or system appearance. |
stillbureau-cart:<siteId> | The contents of your shopping cart on a photographer's store, so it survives a page reload. |
stillbureau-store-visited | Suppresses a repeat introduction the second time you open a store. |
stillbureau-picks-download-size | Remembers the download size you last chose in a gallery. |
stillbureau-picks:<siteId>:<galleryId> | Remembers local gallery selections when there is no active proofing session. |
stillbureau-product-draft:<productId>:<variantId> | Stores a product-design draft you explicitly save so it can be resumed. |
stillbureau-banner-view:<bannerId> | Uses session storage to avoid recording the same sales-banner view repeatedly in one browser session. |
05Optional analytics
On Still Bureau's own pages
Our public marketing pages offer Google Analytics 4. It loads only after you accept the privacy prompt. When it is enabled it measures page views, approximate geography, device and browser characteristics, and interactions such as scrolling and outbound-link clicks.
- Advertising storage, ad personalization, and Google Signals are disabled.
- IP addresses are truncated before storage.
- The tag never loads in accounts, dashboards, client galleries, checkout, or any other customer-specific area.
- Refusing removes the tag, known Google Analytics cookies, and the first-touch attribution cookie, then reloads the page so nothing further is collected. You can change your mind at any time using the privacy button on those pages.
Scroll horizontally to view all columns.
| Name | Purpose | Lifetime |
|---|---|---|
__Host-stillbureau_first_touch_v1 | Stores the first consented campaign, landing path, and referring host so a later signup can be attributed without sending account or customer data to Google. | Up to 90 days, or until analytics consent is withdrawn |
_ga and _ga_<id> | Google Analytics identifiers created only after analytics consent on Still Bureau's public product pages. | Set by Google Analytics; removed when consent is withdrawn where the browser permits |
Google explains how it processes information from sites that use its services on its partner-sites page.
On a photographer's site
Photographers on eligible plans may connect their own Google Analytics, Google Tag Manager, Meta Pixel, or Pinterest tag. Those tags belong to the photographer, not to us. They load only after the visitor accepts the consent banner on that site, and they are governed by that photographer's privacy notice and the tag vendor's terms. If you decline, no tag is loaded.
06Controlling cookies
- Use the privacy button on our marketing pages, or the consent banner on a photographer's site, to change an analytics choice.
- Every browser lets you view, block, and delete cookies and site data in its settings. Blocking strictly necessary cookies will sign you out and prevent protected galleries and pages from opening.
- On Still Bureau's own marketing pages, we honor Global Privacy Control as a request to refuse optional analytics. Photographer-operated site banners currently rely on the visitor's explicit choice.
Questions about anything on this page: hello@stillbureau.com.