Back to Home

Cookie Policy

Last Updated: September 2026 • Mimesis Studios Ltd (Company No. 12768442, Registered in England & Wales)

Privacy-First Architecture & Zero Marketing Trackers

Mimesis Studios Ltd (Company No. 12768442) uses strictly necessary cookies for authentication and payment security, alongside optional functional and communication tools (such as our HubSpot customer support chat) which require your explicit opt-in consent before non-essential cookies are placed.

1. Introduction & Legal Framework

This Cookie Policy sets out how Mimesis Studios Ltd (Company No. 12768442, "we", "us", or "our") uses cookies and similar storage technologies on our website and web applications.

This policy is provided in accordance with the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR) and the UK General Data Protection Regulation (UK GDPR), enforced by the UK Information Commissioner's Office (ICO).

2. What Are Cookies and Local Storage?

Cookies are small data files stored on your computer, tablet, or smartphone when you visit web pages. They allow a web application to recognize your device, maintain authenticated login sessions across different pages, and protect against automated security vulnerabilities such as Cross-Site Request Forgery (CSRF).

In addition to standard cookies, modern web applications may use secure HTTP headers and local browser storage (such as session tokens) to maintain interface state during your active session.

3. Classification of Cookies & Consent Mechanism

Under UK PECR regulations and UK GDPR, cookies and trackers on our platform are categorized based on their purpose:

  • Strictly Necessary / Essential Cookies: Essential for the core operation of a service requested by the user (e.g. logging into a secure dashboard, maintaining security, CSRF protection, Stripe checkout fraud prevention). These do not require prior consent.
  • Customer Support & Interaction (Opt-In Consent): Powered by HubSpot for live customer chat and inquiry management. These cookies are loaded only after you explicitly click "Accept" on our HubSpot cookie consent banner.
  • Performance / Web Analytics (Cookie-less): We use Plausible Analytics, an open-source, privacy-first analytics tool. Plausible is 100% cookie-less, stores no persistent identifiers on your device, does not track across websites, and operates without tracking cookies.
  • Marketing & Profiling Cookies: Third-party advertising networks or behavioural tracking across unrelated websites. (Not used by Mimesis Indie).

You maintain full control over your cookie preferences. Non-essential cookies will never be dropped unless you provide active, affirmative consent through our consent banner.

4. Technical Inventory of Cookies & Storage Used

Cookie / Token IdentifierProvider / DomainCategory & PurposeSecurity & Lifespan
sb-*-auth-tokenSupabase / Mimesis IndieEssential Authentication: Encrypted JWT session token that authenticates your user identity, authorizes access to your projects and tickets, and guards server-side endpoints against unauthorized access.HttpOnly, Secure, SameSite=LaxSession / Up to 7 days (auto-refreshed)
__Host-* / Next.js Server TokensNext.js FrameworkEssential Security & Routing: Protects against Cross-Site Request Forgery (CSRF) and maintains deterministic routing state during server action mutations and form submissions.Secure, SameSite=LaxSession Duration
__stripe_mid / __stripe_sidStripe Inc. (.stripe.com)Payment Fraud Prevention: Placed by Stripe during payment checkouts to detect automated bot transactions, prevent payment fraud, and ensure secure processing of credit purchases.Secure, SameSite=None__stripe_sid: 30 mins / __stripe_mid: 1 year
messagesUtk / __hs_*HubSpot Inc. (.hs-scripts.com)Functional Live Chat Support: Maintains visitor conversation session continuity across page navigation when interacting with customer support. Does not perform cross-site advertising profiling.Secure, SameSite=LaxSession / Up to 6 months
Plausible AnalyticsPlausible (.plausible.io)Privacy-Preserving Aggregate Analytics: Lightweight script measurement with zero cookies, zero device fingerprinting, and zero personal data collection.Cookie-less / Zero Client StorageNo persistent cookies

5. Non-Use of Tracking & Advertising Technologies

Zero Third-Party Advertising: We do not host ad networks, banner trackers, or conversion pixels (e.g. Meta Pixel, TikTok Pixel, Google Ads).
Zero Behavioural Profiling: We do not track your activity across third-party websites, nor do we sell or license device identifiers to data brokers.
Zero Session Replay Tracking: We do not deploy intrusive third-party session recording scripts that record keystrokes or mouse movements.

6. How to Inspect, Manage and Clear Cookies

You have the right to control how cookies are stored on your computer or mobile device. Most web browsers allow you to view, manage, and delete stored cookies via their security and privacy settings.

Impact of Disabling Essential Cookies: Please note that if you configure your browser to block all cookies, you will be unable to log in, maintain your session, or access the Mimesis Indie dashboard.

7. Updates and Contact Inquiries

We may update this Cookie Policy from time to time to ensure ongoing legal compliance with UK regulations. Any modifications will be posted directly to this page with an updated "Last Updated" date.

Mimesis Studios Ltd

Email: support@mimesis-studios.com

Website: indie.mimesis-studios.com

Governing Law: England and Wales, United Kingdom