What we use
authjs.session-tokenCookie · strictly necessaryKeeps park owners signed in to their dashboard.
Duration: Up to 30 days, or until you sign out
authjs.csrf-tokenCookie · strictly necessarySecurity: protects the sign-in form against forged requests.
Duration: Session
authjs.callback-urlCookie · strictly necessaryRemembers which page to return to after signing in.
Duration: Session
flatsite.rigLocal storage · functionalOn booking pages, remembers the RV type and length you entered so you don't have to type it again. Stays in your browser; never sent to us.
Duration: Until you clear it (tap “Clear” in the RV filter or clear your browser data)
On secure connections the cookie names may start with __Secure- or __Host-. Guests who only browse or book on a park's page don't get any cookie from us.
Why there's no consent banner
Cookies that are strictly necessary to provide a service you asked for (like staying signed in) don't require consent under EU and UK rules (ePrivacy Directive art. 5(3), Spanish LSSI art. 22.2) or US state laws. We don't use analytics, advertising or social media cookies, and our fonts are served from our own servers, so your browser doesn't connect to Google or other third parties when you visit FlatSite. If that ever changes, we'll ask for your consent first and update this page.
Payments
When you pay, you're taken to a secure Stripe page. Stripe sets its own cookies there to process the payment and prevent fraud, under Stripe's cookie policy.
Managing cookies
You can delete or block cookies in your browser settings at any time. If you block the ones above, you won't be able to sign in to the dashboard. Questions? email us at support*@flatsitehq.com.