Cookie Policy

Effective Date: 28 Nov 2025

1. Introduction

This Cookie Policy explains how Gender Journey Ltd operating as GenderJourney.xyz ("we," "us," or "our") uses cookies and similar technologies to recognise you when you visit our website. It explains what these technologies are, why we use them, and your rights to control our use of them.


Company Name: Gender Journey Ltd

Company Number: 16877382

ICO Registration Number: ZC049881

Registered Office: 128 City Road, London, United Kingdom, EC1V 2NX


This policy should be read in conjunction with our Privacy Policy and Terms of Service.


2. What Are Cookies?

Cookies are small text files that are placed on your device (computer, smartphone, or tablet) when you visit a website. They are widely used to make websites work more efficiently and provide information to website owners.


Types of cookies we use:

  1. Session Cookies: Temporary cookies that expire when you close your browser
  2. Persistent Cookies: Cookies that remain on your device until deleted or expired
  3. First-Party Cookies: Set by GenderJourney.xyz directly
  4. Third-Party Cookies: Set by external services we use (e.g., Stripe, Google OAuth)


3. Cookies We Use


3.1 Strictly Necessary Cookies (Essential)

These cookies are essential for the website to function and cannot be disabled. They are usually set in response to actions you take, such as logging in or filling in forms.


Cookie Name - Purpose - Duration

genderjourney_xyz_session - Maintains your login session and authentication state - Session (expires when browser closes)

XSRF-TOKEN- Security token to prevent (CSRF) attacks - Session (expires when browser closes)

laravel_token - Remembers your login for "Remember Me" functionality - 400 days (if "Remember Me" is checked)


Legal Basis: These cookies are necessary for the performance of our contract with you (providing the Service). Under UK PECR, consent is not required for strictly necessary cookies.


3.2 Functional Cookies (Optional)

These cookies enable enhanced functionality and personalization. They may be set by us or third-party providers. If you do not allow these cookies, some or all of these services may not function properly.


Cookie Name - Purpose - Duration

theme_preference - Remembers your dark/light mode preference - 1 year

pwa_prompt_dismissed - Tracks whether you dismissed the PWA install prompt - Session (expires when browser closes)


Legal Basis: Consent (you can disable these via cookie settings)


3.3 Third-Party Cookies

We use the following third-party services that may set cookies:


Stripe (Payment Processing)

  1. Purpose: Fraud detection and secure payment processing
  2. Cookies: __stripe_mid, __stripe_sid
  3. Privacy Policy: stripe.com/privacy
  4. Duration: 1 year (mid), 30 minutes (sid)


Google OAuth (Optional Social Login)

  1. Purpose: Authentication via Google account (only if you choose Google login)
  2. Cookies: SID, HSID, SSID, APISID, SAPISID
  3. Privacy Policy: policies.google.com/privacy
  4. Duration: 2 years


4. Similar Technologies


4.1 Local Storage

We use browser localStorage to store non-sensitive data locally on your device:

  1. Feature Flags: Developer mode settings (stored in sessionStorage, cleared when browser closes)
  2. UI Preferences: Dashboard widget settings, sidebar collapse state
  3. Draft Content: Unsaved post drafts (to prevent data loss)


Note: localStorage data never leaves your device and is not transmitted to our servers.


4.2 Service Worker and Cache Storage

Our Progressive Web App (PWA) uses a Service Worker to enable offline functionality:

  1. Purpose: Cache static assets (images, CSS, JavaScript) for faster loading and offline access
  2. Data Stored: App logo, icons, CSS files, JavaScript files
  3. Location: Browser cache storage (not cookies)
  4. Control: You can clear cache via browser settings


4.3 Push Notification Subscriptions

If you enable push notifications, your browser stores a push subscription containing:

  1. Push endpoint URL (provided by your browser vendor)
  2. Encryption keys for secure notifications


This is stored by your browser, not in cookies. You can revoke push permissions anytime via browser settings.


5. How We Use Cookies

We use cookies for the following purposes:


5.1 Authentication and Security

  1. Keep you logged in across page visits
  2. Protect against unauthorized access and CSRF attacks
  3. Manage active sessions and logout functionality


5.2 Functionality and Personalization

  1. Remember your theme preference (dark/light mode)
  2. Store your dashboard widget settings
  3. Track PWA installation status


5.3 Payment Processing

  1. Enable secure payment processing via Stripe
  2. Detect and prevent payment fraud


5.4 Social Login (Optional)

  1. Authenticate via Google OAuth (only if you choose this option)


6. What We Do NOT Use Cookies For

We do NOT use cookies for:

  1. Analytics or Tracking: We do not use Google Analytics, Facebook Pixel, or any tracking cookies
  2. Advertising: We do not serve ads or use advertising cookies
  3. Cross-Site Tracking: We do not track you across other websites
  4. Behavioral Profiling: We do not build profiles of your browsing behavior
  5. Marketing: We do not use cookies for marketing purposes


7. Your Cookie Choices


7.1 Cookie Consent Banner

When you first visit GenderJourney.xyz, you will see a cookie consent banner. You can:

  1. Accept All: Allow all cookies (strictly necessary + functional + third-party)
  2. Reject Non-Essential: Allow only strictly necessary cookies
  3. Customize: Choose which cookie categories to allow


For Registered Users:

If you have created an account, you provided explicit consent to our Cookie Policy during registration. You do not need to interact with the cookie banner again. If you wish to withdraw your cookie consent, you can do so by deleting your account via your profile settings, as strictly necessary cookies are required for the Service to function.


You can change your cookie preferences at any time via the "Cookie Settings" link in the footer.


7.2 Browser Settings

You can control cookies through your browser settings:

  1. Block All Cookies: Prevent all cookies from being set (may break website functionality)
  2. Delete Cookies: Remove existing cookies from your device
  3. Third-Party Cookies: Block only third-party cookies


How to manage cookies in popular browsers:

  1. Chrome: Settings → Privacy and security → Cookies and other site data
  2. Firefox: Settings → Privacy & Security → Cookies and Site Data
  3. Safari: Preferences → Privacy → Manage Website Data
  4. Edge: Settings → Cookies and site permissions → Manage and delete cookies


7.3 Opt-Out of Third-Party Cookies

  1. Stripe: Stripe cookies are necessary for payment processing. Blocking them will prevent you from making payments.
  2. Google OAuth: Only set if you choose Google login. You can use email/password login instead.


8. Data Retention

  1. Session Cookies: Deleted when you close your browser
  2. Persistent Cookies: Deleted after expiration (see table above) or when you clear browser data
  3. localStorage: Persists until you clear browser data or delete your account
  4. Service Worker Cache: Persists until you clear browser cache or we update the cache version


9. Updates to This Cookie Policy

We may update this Cookie Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of material changes by:

  1. Updating the "Last Updated" date at the top of this policy
  2. Displaying a notification on the website
  3. Sending an email notification (for significant changes)


10. Contact Us

If you have questions about our use of cookies, please contact us:

  1. Company Name: Gender Journey Ltd
  2. Company Number: 16877382
  3. Registered Office: 128 City Road, London, United Kingdom, EC1V 2NX
  4. Email: [email protected]
  5. Data Protection Officer: Isabella Jury, [email protected]


By continuing to use GenderJourney.xyz, you acknowledge that you have read and understood this Cookie Policy.