L HAZARD LTD / L HAZARD STORE
Effective & updated: 21 September 2026 · Version 2026-09-21
Cookies are small browser records sent with requests. Local storage is information kept by your browser for a particular website. This policy applies to both when used by L Hazard Store. It does not cover the separate hosting administration panel or external websites you choose to visit.
When you sign in, our self-hosted Supabase authentication client stores the session locally under a key in the form sb-<project-ref>-auth-token. The project reference is derived from the configured API hostname. The stored session supports keeping you signed in and refreshing access while your session remains valid.
This storage is used for the account service you request and is not an advertising identifier. Local storage has no browser-enforced expiry: the entry may remain until sign-out, session invalidation cleanup or you clear site data. Individual access tokens expire and must be refreshed. Signing out of this browser removes its local session; clearing storage on one device does not necessarily revoke other devices’ sessions.
Saved-product selections are stored in your private account in our database so that they remain available after reload; they are not an advertising cookie. Temporary interface and data-fetching state is held in memory while the application is running. Infrastructure may process request and security metadata as described in the Privacy Notice.
The public Store currently has no optional tracking preference to accept. If non-essential analytics, advertising or other consent-dependent technology is introduced, it must be held back until the required choice is made, with a way to withdraw consent. A required sign-in operation is not permission for unrelated tracking.
You can sign out through your workspace and use your browser’s site-data settings to inspect or remove local storage and cookies. Blocking all site storage can prevent sign-in from working. Public information and policy pages can be read without signing in.
Use a private device for an owner or staff account. Do not share session tokens. Contact → Privacy & data rights if you have a question about storage or need help closing an account.