Privacy
What we store
- Age cookie (
sb_age): one-shot assertion you are {18+}/{21+}. 365 days if "yes", 24 h if "no". First-party, HttpOnly, Secure, SameSite=Lax. Never used for advertising. - Geo cache cookie (
sb_geo): five-minute cache of your Cloudflare-detected country code to avoid redoing the compliance verdict on every navigation. - Market cookie (
sb_country): the ISO-3166-1 alpha-2 country you picked from the flag menu in the header (e.g.DK,GB). We use it to filter operator listings and CTAs to the jurisdiction you chose. 365 days, first-party, SameSite=Lax, Secure. You can clear it any time by clicking "Reset to auto-detect" in the flag menu or appending?country=autoto any URL. Never used for advertising. - Language cookie (
sb_lang): UI language you picked (en,da,sv,de,nl). 365 days, first-party, SameSite=Lax, Secure. - Compliance events: aggregated counts of geo verdicts, CTA renders, CTA suppressions, age-gate outcomes. No URLs, no query strings, no user IDs, and no IPs. We hash a truncated prefix (/24 for IPv4, /48 for IPv6) with a rotating salt only to detect abuse; that hash is never linked to the above cookies.
What we don't store
- Your full IP.
- Any third-party advertising or social identifiers - no Facebook SDK, no GA, no TikTok pixel, no Amplitude. The only third-party JS on the site is Cloudflare Turnstile on forms that exist (currently none public) and, outside the EU, Cloudflare Web Analytics (cookieless).
- Account data, because we do not offer accounts.
Regulated data from operators
When you click through an affiliate link, the operator's own pixels take over. Their privacy policy applies from that point. We do not receive any personally identifiable information back from the operator - only aggregate CPA reports (count of conversions, never identities).
Data subject rights
Because we hold neither your IP nor any account data, there is no per-person record to access, rectify or erase. Email privacy@spinbreaker.com if you disagree; we'll answer within 30 days per GDPR Art. 12.