Cookie policy

The cookies and browser storage used to keep MyCakeShed secure and working.

Effective 11 August 2026

1. What this policy covers

This policy explains the cookies and similar browser storage used by MyCakeShed. Cookies are small text files stored by a browser. Local storage is a related technology that can remember information on a device without sending it with every request.

MyCakeShed currently uses only storage that is necessary to provide sign-in, security, basket and checkout functions. We do not currently place advertising or optional audience-measurement cookies on the MyCakeShed site.

MyCakeShed measures a small acquisition funnel without placing an analytics cookie or writing an analytics identifier to local browser storage. A random identifier exists only in page memory and is discarded when the page is reloaded or closed. The related data is described in the privacy policy.

2. MyCakeShed storage

The following items are used by the platform itself.

  • cs_session: an HTTP-only baker or platform session cookie used to keep an authorised user signed in. It expires after up to 30 days or when the user signs out.
  • Customer session cookie: an HTTP-only cookie used to keep a customer signed in and show their account and orders. It expires when the configured session period ends or the customer signs out.
  • cs_oauth_state and related sign-in state: short-lived HTTP-only cookies, normally lasting no more than 10 minutes, used to prevent cross-site request forgery during Google or Microsoft sign-in.
  • cakeshed.cart.[bakery]: local browser storage containing product identifiers and quantities for that bakery’s basket. It remains on the device until the basket is cleared or browser data is removed.

3. Third-party services

Cloudflare provides hosting and network security. If Cloudflare presents a security challenge, it may use strictly necessary cookies or similar identifiers to distinguish legitimate traffic. Amazon SES delivers email but does not place cookies on the MyCakeShed website.

If you choose Google or Microsoft sign-in, that provider may set its own cookies on its domain. If you continue to Stripe Checkout or a Stripe account-management page, Stripe may set cookies needed for payments, subscription billing, fraud prevention and security. Those cookies are controlled by the relevant provider and described in its own privacy and cookie information.

4. Your choices

Because MyCakeShed’s own cookies and local storage are currently necessary to provide features you request, they do not require an optional-cookie consent banner. You can block or delete them in your browser, but sign-in, baskets or checkout may stop working correctly.

If storage-based analytics, personalisation or advertising technology is introduced, this policy and the consent controls will be updated before that technology is enabled for UK users.

5. Contact and updates

Questions about browser storage can be sent to [email protected]. This inventory will be reviewed when providers or platform features change. The effective date at the top of this page shows when it was last updated.