Contracting party#
| Contracting party | Imad Idrissi, trading as Brownbox (eenmanszaak) |
| Trading name | Brownbox |
| Website | https://usebrownbox.com |
| Registered office | Makreelstraat 24, 3192 AM Hoogvliet Rotterdam, the Netherlands |
| KvK | 84236361 |
| VAT / BTW | NL003931061B13 |
| Privacy | privacy@usebrownbox.com |
| Abuse | abuse@usebrownbox.com |
| Copyright / IP | copyright@usebrownbox.com |
| Legal | legal@usebrownbox.com |
| Security | security@usebrownbox.com |
| Support | support@usebrownbox.com |
This notice describes cookies and similar technologies (localStorage, sessionStorage, IndexedDB) used by the Brownbox web application.
Current posture: We use essential storage only for core Service functionality. Icon fonts (Material Symbols) are self-hosted on Brownbox origins — we do not load Google Fonts or other font CDNs on the marketing site or studio app. We do not use non-essential analytics or marketing cookies unless and until we implement a consent mechanism and update this notice. We do not pre-tick marketing or cookie consent, bundle cookie consent into Terms acceptance, or require non-essential tracking to create an Account.
Inventory — first-party essential storage#
| Name / key pattern | Technology | Purpose | Essential? |
|---|---|---|---|
Supabase Auth session keys (sb-*-auth-token style) | localStorage | Keep you signed in; refresh JWT | Yes |
brownbox.composer.settings.v2:* | localStorage | Composer prefs | Yes — UI continuity |
brownbox.brandKit.* | localStorage | Brand-kit setup continuity | Yes |
brownbox.security.loginAlerts | localStorage | Local UI preference | Yes |
brownbox:inflight-generation | sessionStorage | In-flight jobs across refresh | Yes |
brownbox:submit-idem:* | sessionStorage | Submit idempotency | Yes |
brownbox:shoots-mirror | sessionStorage | Fast paint mirror | Yes |
brownbox:shoots-v1 | IndexedDB | Instant reload cache | Yes |
| Soft-tips / error-boundary keys | sessionStorage | UX recovery | Yes |
No first-party HTTP advertising cookies in application code.
Conditional / third-party#
| Party | When | Classification |
|---|---|---|
| Stripe | Checkout / Customer Portal | Necessary for payment you request |
| Google OAuth (if enabled) | Necessary for that login method | |
| Sentry | Only if error monitoring is deliberately enabled in production | Non-essential — requires a consent mechanism or must remain disabled |
| Vercel | Hosting/CDN | Infrastructure; no Vercel Analytics package in the application |
| Supabase | Auth / API | Essential for backend |
| thum.io / screenshot helpers | Brand preview images | Functional preview |
| theSVG.org / brand icons | Connection brand icons | Locally hosted brand marks in the application (no live theSVG CDN request in current app UI) |
What we do not use (as of this version)#
- Marketing pixels / retargeting tags in the SPA
- Vercel Web Analytics npm integration
- Cookie consent bundling into signup Terms checkbox
- Selling device identifiers to data brokers
Managing storage#
Sign out; clear site data in your browser; use private browsing; prefer email/password without Google if you do not want Google’s OAuth cookies; complete Stripe flows only when purchasing.
If we later add non-essential analytics or advertising: we will ship a CMP with reject-all as easy as accept-all; update this inventory; keep non-essential tools off until consent.
Lawful basis summary#
| Category | Basis |
|---|---|
| Strictly necessary auth / security / payment | ePrivacy strict necessity + GDPR Art. 6(1)(b)/(f) as applicable |
| First-party functional UI prefs | Service feature continuity — not used for ads |
| Non-essential analytics / error monitoring | Consent via a consent mechanism — not currently claimed or enabled for marketing |
| Marketing cookies | Not used; would require consent |
Contact#
privacy@usebrownbox.com · Supervisory authority: Autoriteit Persoonsgegevens (NL).