Legal

Cookie Policy

Which cookies suggar.me uses and why.

Your privacy matters to us. When you visit suggar.me, you will be asked for consent for optional cookies. Necessary cookies are always active — they are required for the platform to function. You can withdraw your consent at any time via Cookie settings in the footer.

What are cookies?

Cookies are small files that are stored in your browser when you visit a website. Similar technologies such as localStorage work in a comparable way. Under Section 25 TDDDG (German Telecommunications and Digital Services Data Protection Act) as well as Art. 6 GDPR, consent is required to store information on your device unless access is strictly technically necessary.

Managing consent

On your first visit, a banner appears with three options: Accept all, Necessary only, or Settings for granular control. Your choice is stored for 12 months and can be changed or withdrawn at any time via Cookie settings in the footer. Withdrawing consent is just as easy as giving it (Art. 7(3) GDPR).

Category 1 — Necessary cookies

Strictly required for the operation and security of the platform. These cannot be disabled. Legal basis: Art. 6(1)(b) GDPR, Section 25(2) No. 2 TDDDG.

accessToken Necessary
Duration: 15 minutes

JWT access token for the creator dashboard. HttpOnly flag — no JavaScript access possible.

refreshToken Necessary
Duration: 7 days

JWT refresh token used to extend the session. HttpOnly + Secure. Deleted immediately upon logout.

sgr_cookie_v1 (localStorage) Necessary
Duration: 12 months

Stores your cookie consent with a timestamp (record-keeping obligation under Art. 5(2) GDPR).

Category 2 — Statistics cookies (opt-in)

Only active with explicit consent. Legal basis: Art. 6(1)(a) GDPR, Section 25(1) TDDDG.

sgr_analytics Statistics
Duration: 12 months

Stores your statistics consent and passes it on to our server (value 0 or 1). Only when the value is 1 is an anonymous page view recorded internally — no cross-session tracking, no sharing with third parties.

Category 3 — Payment providers

Only loaded on creator profile pages when you open a payment form. Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

Stripe.js (third party) Payment processing

Stripe Inc., 510 Townsend St., San Francisco, CA 94103, USA. Stripe sets its own cookies for fraud prevention. Data is transferred to the USA on the basis of EU Standard Contractual Clauses (Art. 46 GDPR). Privacy policy: stripe.com/de/privacy

Marketing cookies

We currently do not use any marketing or advertising cookies. Should this change, separate consent will be obtained.

Disabling cookies in your browser

You can disable cookies via your browser settings. Please note: without necessary cookies, logging in to the creator dashboard is not possible.

Contact & supervisory authority

If you have any questions, please contact us (see Imprint). You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).

Last updated: September 2026