Legal informationBrowser storage
Cookie Policy
The necessary storage and optional consent-gated Meta Pixel used by games.enterprises, with retention and controls.
Last updated:
1. What cookies and local storage are
A cookie is a small piece of data that a website stores in a browser and receives with later requests. localStorage and sessionStorage remain in the browser and are not sent automatically with every request. These technologies help maintain sign-in, language selection, and local game progress.
2. Strictly necessary cookies
We use our own strictly necessary cookies for authentication, language, free-play metering, and abuse prevention. They use appropriate SameSite and Secure settings in production and are not used for advertising. Stripe may set its own necessary technologies on hosted Checkout and the customer portal for payments, security, fraud prevention, and legal compliance.
- __Host-games_session (games_session in an insecure local environment): a random sign-in token. Maximum lifetime is approximately 30 days; it is deleted on sign-out. Only a hash of the token is stored on the server.
- games_locale: the interface language manually selected by a visitor. Maximum lifetime is one year, and a later manual selection replaces it. When a saved account preference applies, this cookie remains until expiry or manual clearing but does not determine the selected language.
- games_profile_locale: the language saved to the account and used to choose a localized route. Maximum lifetime is one year. Signing out alone does not delete it; it may remain until it expires, is manually cleared, or is later updated through locale synchronization.
- __Host-games_device (games_device in an insecure local environment): a random HttpOnly device token used with an HMAC-pseudonymized IP address to meter the anonymous 60-minute allowance and prevent repeated allowances or trials. Only an HMAC identifier is stored server-side. Maximum lifetime is one year. It is not used for advertising or device fingerprinting.
3. Game localStorage
Some games store a best score, unfinished state, daily or practice puzzle statistics, and tutorial completion on the device. Retention is controlled by the browser: the data remains until the game replaces it or the user clears site storage.
Local records work without an account, are not cookies, and ordinarily do not leave the device. In supported games, an individual score may be sent to the server only after a game action, as described in the Privacy Policy.
4. sessionStorage
The profile may temporarily record a technical indicator that a language preference was saved so that confirmation can be shown after navigation. It exists only in the current tab until used or until the tab is closed and is not used for profiling.
5. Optional Meta Pixel
With affirmative marketing consent, games.enterprises loads fbevents.js from connect.facebook.net and initializes Meta dataset/pixel 1064531599294316. We use it for advertising measurement and attribution, campaign optimization, and advertising audiences. It records PageView; ViewContent with a non-personal game slug; CompleteRegistration; and GameStart and GameOver where implemented. We do not send email addresses, account or user IDs, nicknames, scores, payment data, or comment text as event parameters, and no Conversions API token is present in browser code.
The browser request and Pixel can disclose the page URL and referrer, event time, IP address, user agent and other browser/device information, and Meta identifiers. The EEA recipient is Meta Platforms Ireland Limited, Merrion Road, Ballsbridge, Dublin 4, D04 X2K5, Ireland, which may associate this activity with Meta services under the Meta Business Tools Terms (https://www.facebook.com/legal/technology_terms) and Meta Privacy Policy (https://www.facebook.com/privacy/policy/). Meta may set first-party _fbp and, after a Meta click identifier is present, _fbc cookies; their ordinary maximum lifetime is approximately 90 days. Meta's retention of received event data follows its current policies and business-tool settings and may vary.
6. Whether consent is needed
Strictly necessary technologies are used for requested features and security without relying on marketing consent where the law permits. Meta Pixel, fbq, fbevents.js, and Meta advertising cookies are not created or loaded before an explicit button press that both confirms age 16+ and permits Meta Pixel, or before equivalent age and marketing selections in Cookie settings. A visitor under 16 can choose Necessary only without losing core functionality. Cookie settings remain available to change the choice; withdrawal sends a consent-revocation instruction, stops our later events, removes the Pixel script element, and attempts to delete accessible _fbp and _fbc cookies. Code already downloaded cannot be erased from browser memory, and Meta remains responsible for data already received.
The versioned games_privacy_consent localStorage record is strictly necessary to remember the choice. It stores only necessary=true, the marketing yes/no value, the 16+ confirmation as a separate value, consent version, decision time, and expiry; it expires after 180 days or earlier if replaced, invalidated, or cleared. Marketing and age values are reset on refusal or withdrawal. With active marketing consent, the optional games_meta_pending_registration sessionStorage record may hold up to eight random event IDs plus their creation and expiry times for up to 24 hours after confirmed signups, so each CompleteRegistration survives navigation until the loaded Pixel receives it. It is removed after hand-off, when tab storage ends, or on withdrawal, GPC, or expiry. A Global Privacy Control signal is treated as marketing refusal in that browser.
7. Stripe payment technologies
Hosted Stripe Checkout and the Stripe customer portal may use technologies strictly necessary to collect a payment method, authenticate a transaction, prevent fraud, remember the payment session, and comply with law. These technologies are controlled by Stripe on its domain and are subject to Stripe's notices and settings. Blocking them may prevent checkout or billing management from working.
8. How to manage storage
Before you make a choice, the consent banner lets you accept or refuse Meta Pixel. After making a choice, a signed-in user can reopen Cookie settings from the Profile; any visitor can also use Cookie settings on public non-game pages, including the Home page. These controls are not fixed over the game screen. You can also view and delete cookies and site data for games.enterprises or block them in your browser settings. Deleting the session cookie signs you out; deleting language cookies restores automatic language selection; clearing localStorage removes the saved consent choice, local scores, states, and tips. Deleting the free-play device cookie does not restore an allowance or trial and does not delete server-side eligibility, account, or subscription records.
Blocking necessary cookies may make free play, sign-in, preference saving, checkout, or the Stripe customer portal unavailable. Instructions vary by browser; use the privacy or site-data section of its settings.
9. Updates
We will update the list and display a new date when a technology is added, removed, or changed. Questions about browser storage may be sent to privacy@games.enterprises.