Hashtags Studios uses cookies, local storage, and session storage to operate the platform. This page lists every cookie we set, what it does, and how long it stays. It should be read together with our Privacy Policy.
On your first visit a cookie banner asks for your consent. Strictly-necessary cookies are always set because the platform cannot function without them; all other categories (functional, analytics, marketing) are optional and are only set if you accept them. You can decline non-essential cookies at the banner, and you can change your choice at any time — see "Managing consent" below. Declining non-essential cookies will not block you from using the platform.
02
Strictly necessary
Cookie
Purpose
Lifetime
authjs.session-token
Authentication. Tied to your account; rotated when admins force-logout via a tokenVersion bump. Served as __Secure-authjs.session-token over HTTPS.
30 days
authjs.csrf-token
Cross-site request forgery protection on auth endpoints.
Session
NEXT_LOCALE
Stores your selected language (en / ar / fr / es / ...).
12 months
buyer-country
The country you are shopping from. Decides which listings can reach you and which currency is shown beside the AED price. Set when you pick a country in the header switcher.
12 months
hs_acting_as
Present only for a guardian who has switched into a managed child account. Names the child account being operated. Cleared when you switch back.
Session
cookie-consent
Records your granular cookie-consent choices (necessary / functional / analytics / marketing). Written by both the first-visit banner and the preferences panel below — one shared record.
12 months
These cannot be turned off — the platform will not function without them.
03
Stored on your device, not in a cookie
Two preferences are kept in your browser's own storage rather than sent to us with each request:
Item
Where
Purpose
Lifetime
theme
local storage
Light / dark / system appearance. Never leaves your device.
Until cleared
hs:recent
local storage
"Recently viewed" list on talent / job / event / listing pages. Written only if you accept the Functional category.
Until cleared
Your shopping cart is not a cookie. Cart contents are saved to your account in our database, so they follow you between devices while you are signed in.
04
Functional
hs:recent above is the functional category. Turning Functional off stops it being written and clears the existing value on your next page view, resetting "recently viewed" to empty.
Push notifications, when you enable them, use the browser's Push API rather than a cookie. Turning them on stores a push endpoint and its keys against your account so we can deliver the notification; turning them off in your settings or your browser deletes it.
05
Analytics
We collect anonymised, first-party page-view counts to understand which pages are used and improve the product. Events are written to our own database — nothing is sent to any third party, and no analytics runs at all unless you accept the Analytics category. Each event stores only the page path and an opaque random id (below); no account link, no IP, no fingerprint.
Cookie
Purpose
Lifetime
hs-analytics-id
Random opaque ID used to deduplicate visitors in aggregate counts. Set only while you have granted analytics consent, and deleted the moment you revoke it. Not linked to your account.
12 months
To opt out, turn Analytics off in the preferences panel below (or decline it at the banner). That deletes the id cookie and stops all collection immediately; the server also refuses to record anything without your consent.
06
Anti-abuse + rate limiting
Server-side rate limits are keyed by IP + account ID for sign-in, KYC submission, message send, and report submission. These rely on short-lived in-memory counters, not cookies.
07
What we do NOT use
Third-party advertising trackers (Google Ads, Meta Pixel, TikTok Pixel, etc.) — none are loaded by the platform.
Cross-site behavioural tracking cookies.
Fingerprinting libraries.
Cookie-based remarketing.
We do not sell cookie data to third parties.
08
Managing consent
Your granular choices (necessary / functional / analytics / marketing) are stored in a single cookie-consent cookie and can be changed at any time from the Manage cookies panel on this page. The first-visit banner writes the same record — "Accept all" turns every optional category on, "Essential only" turns them all off — so the banner and this panel always agree. Strictly-necessary cookies cannot be disabled. No third-party advertising or marketing scripts are loaded today — the marketing toggle only records your preference for any such feature we may add later.
To clear all cookies set by Hashtags: open your browser settings and remove cookies for the hashtagsstudios.com domain. You will be signed out and your preferences will reset. Clearing site data also removes the local-storage items listed above.
09
Third-party processors
When you make a payment, Stripe sets its own cookies on the Checkout page to fight fraud. When we send email via Resend, no cookies are involved. Google Translate runs server-side and does not touch your browser.
10
Changes + contact
Material changes will be announced in-app and via email. Questions: privacy@hashtagsstudios.com (or via /contacts).
This content can be updated live by an admin from /admin/settings (key: legal.cookie).
Preferences
Manage cookies
Strictly necessary cookies are always active so the platform works. The rest is your choice.
Strictly necessarySign-in, cart, security and your chosen language. These are always active.