COOKIE POLICY

Last updated: 30 September 2026

1. What is a tracker?

A tracker is information stored on or read from your device when you visit a website: a cookie, data stored in the browser (localStorage, sessionStorage), a pixel or a third-party script. Some are essential for the site to work, others measure audience or measure an advertising campaign.

This page describes the trackers used on scoreshark.io, as found in the site's code on the date shown at the top of the page, and how to manage them.

2. Strictly necessary trackers

These trackers let the site work or answer a request you made. They do not require consent.

Name
sb-*-auth-token (cookie)
Issuer
ScoreShark, through Supabase Auth
Purpose
Keeps you signed in
Duration
Set by the authentication library (up to 400 days), removed when you sign out
Consent
Not required
Name
NEXT_LOCALE (cookie)
Issuer
ScoreShark
Purpose
Remembers the language you chose
Duration
The browsing session when the site's language library (next-intl) sets it: language selector, or a page opened in a language other than the one already remembered (or, without a cookie, other than your browser's language); 1 year when the site records it at sign-up, at sign-in or from your account preferences
Consent
Not required
Name
tz (cookie)
Issuer
ScoreShark
Purpose
Remembers your time zone to display match times
Duration
1 year
Consent
Not required
Name
cookie-consent-v3 (localStorage)
Issuer
ScoreShark
Purpose
Remembers your choices in the consent banner
Duration
Until you change or clear it
Consent
Not required
Name
ssk_dnt (cookie)
Issuer
ScoreShark
Purpose
Remembers your objection to audience measurement
Duration
13 months
Consent
Not required
Name
ssk_login_prefill_email, ss_promo_interstitial_shown, ss_sponsor_interstitial_shown (sessionStorage)
Issuer
ScoreShark
Purpose
Browsing comfort: e-mail pre-filled at login, promotional or sponsored message shown only once per session
Duration
While the tab is open
Consent
Not required
Name
ss_promo_interstitial_dismissed_at, ss_promo_interstitial_last, ss_pwa_banner_dismissed, compare_recent_players (localStorage)
Issuer
ScoreShark
Purpose
Not showing again a message you closed, remembering recently compared players
Duration
Until you clear it
Consent
Not required
Name
tiktok_oauth_state (cookie)
Issuer
ScoreShark
Purpose
Secures a TikTok sign-in from the admin area
Duration
10 minutes, administrators only
Consent
Not required

3. Audience measurement

ScoreShark measures its audience with an in-house tool, with no third-party analytics service. The basic measurement meets the conditions of the consent exemption defined by the French CNIL: short-lived session identifier, no IP address kept, no cross-site tracking, no link to your account. It therefore stays active if you click "Refuse all".

Name
ssk_sid (cookie)
Issuer
ScoreShark
Purpose
Session identifier for audience measurement: pages viewed, scroll depth, path
Duration
30 minutes, extended on each page view
Consent
Not required (CNIL exemption), objection available below
Name
ssk_attribution (sessionStorage)
Issuer
ScoreShark
Purpose
Source of the visit (source, medium, campaign and landing page of the first and last visit, their dates and a visit counter). With your consent to audience measurement, it is recorded with your account when you sign up to measure our acquisition channels; without that consent, your sign-up is only counted per channel, with no link to your account
Duration
While the tab is open
Consent
Required for recording with your account; not required for the per-channel count (CNIL exemption); objection available below

If you tick the "Audience measurement" box in the banner, your measurement events additionally carry a hashed technical fingerprint of the browser and, when you are signed in, your account identifier; when you sign up, the source of your visit (source, medium, campaign and landing page of the first and last visit, their dates and a visit counter) is recorded with your account. With this consent, the analyses you open and the subscriber-only content you come across are also used to tailor and trigger our welcome e-mails, if you receive them: the number of analyses opened during the week tailors the day-7 e-mail, and the day-14 e-mail is only sent if you came across subscriber-only content during the week. Without that acceptance, your browsing events are not linked to your account, and your sign-up is only counted per channel, with no link to your account. If you have objected to audience measurement, the source of your visit is neither recorded nor counted. Your sign-up, the start of a payment made without an existing account (the account being created at payment), subscriptions and cancellations are also recorded as events linked to your account, to manage the service.

You can object to audience measurement, including the exempted measurement, with the button below. The objection is recorded in the ssk_dnt cookie for 13 months. From that browser, the site then stops sending measurement events, no longer sets the ssk_sid session identifier, no longer captures the source of the visit (so it is neither recorded nor counted when you sign up) and no longer records your clicks on our short links posted on social networks.

4. Advertising and ad measurement

The Meta pixel (Facebook, Instagram) is loaded only if you accepted the "Advertising and ad measurement" box in the banner, and only on the public pages of the site. It measures our communication campaigns. It is never loaded before you accept.

Name
Meta pixel trackers
Issuer
Meta Platforms Ireland Ltd
Purpose
Measurement of ScoreShark campaigns run on Facebook and Instagram
Duration
Durations set by Meta: see Meta's cookie policy
Consent
Required

Withdrawing consent stops the sending of events from your next navigation. Trackers already set by Meta are not deleted by the site: you can remove them from your browser settings.

This banner category also mentions Google AdSense. No AdSense script is loaded on the site as of the date of this policy.

5. Push notifications (OneSignal)

The site loads the OneSignal script to manage the subscription to push notifications. Loading it triggers no notification. Your browser's permission request is shown only when you turn on push notifications in your account preferences, and you only receive notifications if you answered "Allow". Adding a player, a tournament or a match to your favorites does not trigger this request. The notifications sent are the following:

  • the announcement of the day's new analyses, sent to accounts that turned on push notifications;
  • the announcement that a tournament in your favorites is about to start, if the matching option is turned on in your preferences;
  • a confirmation when you add a match to your favorites.

The script is loaded regardless of your choices in the banner. OneSignal may store technical identifiers in your browser to manage this subscription. You can withdraw the permission at any time in your browser's notification settings or in your account preferences. Details: OneSignal's privacy policy.

6. Technical services

  • Sentry (error tracking): when a technical error occurs, a report is sent to Sentry through the site (path /monitoring). It contains technical information about the error and the browser, not your account data. Sentry's policy.
  • Vercel Speed Insights (performance): measures how fast pages display. Aggregated technical data, sent to the same domain as the site, with no cookie and no visitor identifier. Vercel's policy.
  • Cloudflare Turnstile (anti-bot): its script is preloaded on every page, meaning downloaded from Cloudflare's servers without being run, so that the sign-in window opens without delay. It only runs in the sign-in, sign-up and password reset window, on the Pricing page, where an invisible check protects subscribing, and on the admin sign-in page. Cloudflare then analyses technical signals from the browser to tell a human from a robot and may set a tracker for the duration of the check. Cloudflare's policy.
  • Stripe Checkout (payment): subscribing redirects you to checkout.stripe.com. Trackers set on that page fall under Stripe's policy. No Stripe script is loaded on scoreshark.io.

7. Managing your choices

  • The consent banner is shown on your first visit: you can accept all, refuse all or choose category by category.
  • The "Manage cookies" link, in the footer of every page, reopens this panel at any time to change or withdraw your choices.
  • The objection button in section 3 stops, from that browser, measurement events, the session identifier, the capture of the source of the visit and the recording of clicks on our short links, including for the measurement that requires no consent.
  • Your browser settings let you view, block or delete cookies and site data. Blocking necessary trackers may prevent you from signing in.

Your choices are kept in your browser (key cookie-consent-v3) until you change them or clear the site data. They are specific to each browser and each device. You are asked again if the list of trackers changes significantly.

8. Contact and complaints

For any question about trackers or your data: [email protected]. The processing of personal data is described in the Privacy policy.

You can lodge a complaint with the CNIL, the French data protection authority.