Cookie policy
We only set cookies we believe are necessary or that youâve explicitly consented to. You can change your choices any time via cookie preferences. Curate also writes a small number of keys to your browserâs local storage to remember preferences (theme, sidebar state, dismissed tips). Those are listed in the âLocal storageâ section below.
Whether you arrived on a curatewalls.com subdomain (e.g. acme.curatewalls.com) or on a merchantâs own vanity domain (e.g. curate.acme.com), the cookies described below are set, read, and decided on by Curate. On a curatewalls.com subdomain the cookies are scoped to curatewalls.com; on a custom domain theyâre scoped to that domain. In both cases Curate (Curate Walls Ltd, a company registered in England and Wales, company number 17412020) is the entity that controls them and the merchant has no access to their values. The merchant does not set cookies of their own through this product.
Strictly necessary
Required for the service to run. These don't need consent under UK GDPR.
| Name | Purpose | Retention | Party | Domain |
|---|---|---|---|---|
curate_analytics_consent | Stores your cookie consent choice, and the version of this notice it was made against, so we don't ask again. If this notice materially changes, the banner asks afresh. On curatewalls.com it is scoped to the parent domain so one choice covers the planner and merchant pages; on a merchant's own domain it stays scoped to that site. | 12 months | First-party | curatewalls.com |
sb-* (Supabase session) | Keeps you signed in to your Curate account. On curatewalls.com these are scoped to the parent domain (.curatewalls.com) and shared across tenant subdomains so a single sign-in carries over when you open a merchant planner. On a merchant's own custom domain they stay scoped to that host. | Session / 7 days | First-party | .curatewalls.com (custom domains: host-scoped) |
curate_tenant | Remembers which merchant tenant subdomain you arrived on so branding is consistent across pages. | 1 hour | First-party | curatewalls.com |
curate_device | Remembers your chosen device experience (mobile vs desktop) so we don't redirect you on every visit. | 12 months | First-party | curatewalls.com |
curate_anon | Anonymous session ID that lets you save and resume a wall without creating an account. Refreshed on activity, so it only expires after 90 days away; separately, walls left inactive for 60 days are purged from our servers by a daily job. | 90 days (sliding) | First-party | curatewalls.com |
__stripe_mid / __stripe_sid (Stripe) | Set by Stripe, our payment processor, when a payment form loads (paying for a Room Pass, a hanging kit, or a merchant subscription). Used by Stripe for fraud prevention on the payment you are making. These load only on payment surfaces, not on ordinary browsing. | __stripe_mid 1 year, __stripe_sid 30 minutes | Third-party (Stripe) | curatewalls.com (set by js.stripe.com) |
x-onboarding-done | Caches a merchant's onboarding-complete state for 5 minutes so we don't re-query the database on every page load. | 5 minutes | First-party | curatewalls.com |
curate_impersonator | Set only when a Curate admin is viewing a merchant account in read-only support mode. Marks the session as impersonated so write actions are blocked and a banner is shown. | 30 minutes | First-party | curatewalls.com |
Analytics
Help us understand how Curate is used so we can improve it. Only loaded if you opt in. When you opt in, PostHog persists its identifiers in both cookies and your browser's local storage (the ph_* entries listed in the Local storage section below). Your IP address is dropped on ingest. Session replay, which records an anonymised playback of your visit, is switched off by default; where it is switched on, replays mask all form inputs (passwords, email, phone) and your room photo is excluded from the recording entirely.
| Name | Purpose | Retention | Party | Domain |
|---|---|---|---|---|
ph_* (PostHog) | Product analytics: which features are used, error patterns, and conversion funnels. Also anonymised session replay where that is switched on, excluding your room photo. | 12 months | Third-party (EU region) | eu.posthog.com |
Marketing
Used to measure campaigns or personalise content. Curate sets none of these, so there is nothing here to switch off. Listed for transparency.
No cookies in this category at the moment.
Local storage
In addition to cookies, Curate stores a small set of preferences and dismissals in your browserâs local storage. Local storage is not transmitted to our servers in HTTP request headers; it stays on your device. You can clear it at any time via your browserâs site-data settings.
| Key | Purpose | Category |
|---|---|---|
curate_guest_id | Random ID we use when you share a wall as a guest, so the share link is stable across visits. | Guest identity |
curate_favourites | Your favourited artwork before you sign in. Merged into your account on first sign-in. | Preference |
curate_first_run_seen | Whether you've seen the design canvas first-run overlay. | Preference |
curate_walkthrough_seen | Whether you've seen the canvas walkthrough coach marks. | Preference |
curate-sidebar-expanded | Your preferred dashboard sidebar width (collapsed / expanded). | Preference |
curate_seen_clipper | Whether you've seen the Web Clipper bookmarklet promo. | Preference |
curate_room_catalogue_declined | Which rooms you have already seen the Room Pass offer for, so the print panel stays consistent on those rooms between visits. | Preference |
curate_seen_ar | Whether you've seen the AR feature promo. | Preference |
curate_ar_tier | Tracks fallback to the legacy WebXR AR engine when the native launcher isn't available. | Preference |
curate_clip_signal | Bridges product data from the Web Clipper bookmarklet into the Curate tab. Cleared after import. | Preference |
curate_uploads_tab_seen | Whether you've opened the âYour uploadsâ tab in the art panel. | Preference |
curate_art_banner_dismissed | Whether you dismissed the âImport your own artâ banner. | Preference |
curate_template_upload_hint_dismissed | Whether you dismissed the template-room upload hint. | Preference |
curate_branding_import_dismissed | Merchant-side: whether you dismissed the âImport branding from your websiteâ card on the Branding page. | Merchant preference |
curate_custom_layouts | Layouts you've saved on the canvas as personal favourites. | Preference |
curate_admin_feedback_lastseen | Admin-side: count of unanalysed feedback when you last visited the inbox. | Admin preference |
curate_actioned_suggestions | Admin-side: AI feedback themes you've marked as actioned. | Admin preference |
ph_* (PostHog) | Only present if you opt in to analytics. PostHog stores its anonymous distinct ID, feature-flag state, and session-replay buffer here. Cleared if you withdraw analytics consent. | Analytics |
Changing your mind
You can open cookie preferences any time to update your choices, or clear the curate_analytics_consentcookie in your browser to see the banner again. To clear the local-storage entries above, use your browserâs âClear site dataâ option for curatewalls.com.