Transparency Report

Q2 2026 · Last verified 2026-05-07 · Cookie policy version 2026-05-v6

Overview

This page is the public counterpart to our internal privacy audit. We publish it quarterly so users, partners and the UK Information Commissioner’s Office can verify, without contacting us, that the information in our Cookie Policy matches reality.

The data on this page is rendered directly from src/lib/transparency.ts in our public source tree and reflects the state of the Service on 2026-05-07. A machine-readable JSON copy is available at /api/transparency for automated scanners and audit tooling.

1. Cookie counts at a glance

The Service may set up to 22 cookies or equivalent storage entries across a full user journey (no change vs. previous quarter). The total varies per session because Stripe and Google cookies only fire on the pages that need them.

CategoryCountLawful basisActive in this quarter?
Strictly Necessary9PECR reg. 6(4)Yes - always
Functional (opt-in)1GDPR consentYes - only after Accept
Marketing / Personalisation (opt-in)5GDPR consentYes - only after Accept (bundled with Functional toggle)
Analytics (opt-in)0GDPR consentNo - not currently used
Payment & fraud72026 Act Sch.4 (Recognised Legitimate Interests)Yes - only on checkout

2. Quarterly drift

We track total cookie count over time so any unexpected increase (a vendor adding new cookies in an SDK update, a new feature pulling in a tracker) is immediately visible. Each row is a manual quarterly review checkpoint signed off by the data protection lead.

QuarterTotal cookiesNote
Q4 202518Pre-Cookiebot - analytics line later removed (Vercel never installed).
Q1 202622Cookiebot CMP added. hCaptcha disclosed.
Q2 202622Maps SDK now consent-gated. Vercel-Analytics false claim removed.

3. Third-party recipients

Every external organisation that may set a cookie on thesbkdance.com, the country it operates from and the legal instrument under which we transfer data to it. Lifted verbatim from the ROPA in our Cookie Policy §9.

RecipientCountryTransfer instrumentCookies
Stripe Payments UK Ltd.United Kingdom & United StatesUK adequacy regulations + Stripe SCCs__stripe_mid, __stripe_sid, m, _mf, _ab, id, 1
Cloudflare Inc.United StatesUK International Data Transfer Addendum (IDTA)__cf_bm
Google LLCUnited StatesUK-US Data Bridge under s.17A UK Data (Use and Access) Act 2026NID, 1P_JAR, OGP / OGPC, CONSENT, SOCS
Cookiebot / Usercentrics A/SDenmarkEEA adequacy decisionCookieConsent, userlang
Supabase Inc.United States (DB hosted in EU-West)UK International Data Transfer Addendum (IDTA) + EU adequacy for DBsb-access-token, sb-refresh-token

4. Full inventory

Every cookie or equivalent storage entry the Service may set, mirroring the four tables in the Cookie Policy.

NameCategoryVendorDomainDuration
sb-access-tokenStrictly NecessaryThe SBK Dance / Supabasethesbkdance.com1 hour
sb-refresh-tokenStrictly NecessaryThe SBK Dance / Supabasethesbkdance.com1 year (rolling)
csrf-tokenStrictly NecessaryThe SBK Dancethesbkdance.comSession
sub-tierStrictly NecessaryThe SBK Dancethesbkdance.com24 hours
__cf_bmStrictly NecessaryCloudflare Inc.*.supabase.co30 minutes
CookieConsentStrictly NecessaryCookiebot / Usercentrics A/Sthesbkdance.com1 year
userlangStrictly NecessaryCookiebot / Usercentrics A/Sthesbkdance.comSession
cookie_consent (localStorage)Strictly NecessaryThe SBK Dancethesbkdance.com1 year
ems-auth-user-cache (localStorage)Strictly NecessaryThe SBK Dancethesbkdance.com24 hours
NIDMarketingGoogle LLCgoogle.com6 months
1P_JARMarketingGoogle LLCgoogle.com1 month
OGP / OGPCMarketingGoogle LLCgoogle.com1 month
CONSENTMarketingGoogle LLCgoogle.com2 years
SOCSMarketingGoogle LLCgoogle.com13 months
ems_ip_location (localStorage)FunctionalThe SBK Dancethesbkdance.com1 hour
__stripe_midPayment & fraudStripe Payments UK Ltd.js.stripe.com1 year
__stripe_sidPayment & fraudStripe Payments UK Ltd.js.stripe.com30 minutes
mPayment & fraudStripe Payments UK Ltd.m.stripe.com2 years
_mfPayment & fraudStripe Payments UK Ltd.m.stripe.network1 year
_abPayment & fraudStripe Payments UK Ltd.m.stripe.network1 year
idPayment & fraudStripe Payments UK Ltd.m.stripe.network1 year
1Payment & fraudStripe Payments UK Ltd.m.stripe.networkSession

5. Compliance posture

  • Cookie banner: three equally-prominent choices (Accept All / Reject All / Manage preferences), both default-off toggles in the Manage panel, no dark patterns. Verified by source review on 2026-05-07.
  • Consent withdrawal: available from every page via the “Cookie Settings” link in the footer and the in-line CTA on every map placeholder.
  • Data Protection Impact Assessment: internal DPIA last reviewed 2026-05-06. Redacted summary available on request to support@thesbkdance.com.
  • Records of Processing Activities: maintained per Article 30 UK GDPR; cookie-setting recipients reflected in section 3 above.
  • Information Security Management System: internal ISMS aligned with the ISO/IEC 27001:2022 framework; external certification not yet engaged. We will publish the certificate hash on this page once the audit is commissioned and the certificate issued.
  • Complaints Handling Duty (UK Data Act 2026, active June 2026): we acknowledge complaints within 5 working days and reply substantively within 30.

6. How to verify this report

  • Open browser DevTools → Application → Cookies on thesbkdance.com and reconcile against section 4 above.
  • Pull the machine-readable copy at /api/transparency for diffing across quarters.
  • Run an external scanner (Cookiebot, OneTrust, Termly). The numbers reported by the scanner should match section 1, allowing for vendor-side new cookies which we capture in the next quarterly review.

For corrections or to flag a cookie we’ve missed, email support@thesbkdance.com.