Cookie Policy

Effective Date: March 21, 2026 Last Updated: March 21, 2026

1. What Are Cookies?

Cookies are small text files placed on your device (computer, tablet, or mobile) when you visit a website. They are widely used to make websites function correctly, work more efficiently, and to provide analytics information to site operators.

Cookies set by the website operator (in this case, Smart Money API) are called "first-party cookies." Cookies set by parties other than the website operator are called "third-party cookies." Third-party cookies enable third-party features or functionality (such as payment processing and authentication) to be used on or through the website.

Cookies may be "session cookies," which expire when you close your browser, or "persistent cookies," which remain on your device for a set period or until you delete them.

2. How We Use Cookies

Smart Money API uses cookies and similar technologies (such as localStorage and sessionStorage) to:

  • Keep you logged in to your account across page visits
  • Remember your preferences and settings (such as theme choice)
  • Maintain the security of your session and API access
  • Understand how visitors use our website to improve the experience
  • Enable payment processing and subscription management via Stripe
  • Support Firebase Authentication for Google Sign-In
  • Store your cookie consent preferences

We do not use cookies for advertising, retargeting, or to track you across unrelated third-party websites.

3. Essential Cookies

These cookies are strictly necessary for the Service to function. They cannot be disabled without breaking core functionality such as authentication and security. No consent is required to set these cookies under GDPR, as they are necessary for contract performance.

Cookie NamePurposeDuration
__sessionFirebase Authentication session token — keeps you logged inSession / 14 days
firebase:authUserFirebase local auth state stored in localStoragePersistent
sma_themeYour selected UI theme preference (dark/light)1 year
sma_cookie_consentStores your cookie consent choice (essential/all/declined)1 year
CSRF tokenCross-site request forgery protection for form submissionsSession

4. Analytics Cookies

These cookies help us understand how visitors interact with our website. All analytics data is aggregated and anonymised — we cannot identify individual users from analytics data alone. These cookies are only set if you accept analytics cookies via our consent banner.

Cookie / Storage KeyPurposeDuration
sma_session_idAnonymous session identifier for page flow analyticsSession
sma_first_visitRecords first visit date for cohort analysis (anonymised)1 year
sma_refRecords referral source to understand traffic origin (anonymised)30 days

We do not use Google Analytics or other third-party analytics services that track users across websites. Our analytics are self-hosted and privacy-preserving.

5. Third-Party Cookies

Some pages of our Service involve third-party providers that may set their own cookies. We have limited control over these cookies; please refer to each provider's privacy and cookie policy for details.

5.1 Firebase / Google Authentication

When you sign in using Google, Firebase Authentication sets cookies and uses localStorage to manage your session. These are essential for the authentication flow. Google's cookie information: policies.google.com/technologies/cookies.

5.2 Stripe

When you access billing or subscription pages, Stripe may set cookies to prevent fraud and ensure secure payment processing. These cookies are essential to Stripe's fraud detection systems. Stripe's cookie policy: stripe.com/cookie-settings.

CookieProviderPurpose
__stripe_midStripeFraud prevention, device fingerprinting for payment security
__stripe_sidStripeSession-level fraud prevention during checkout

5.3 Cloudflare

Cloudflare, our CDN and security provider, may set cookies for bot detection and DDoS mitigation. These are security-essential and cannot be disabled. Cloudflare's cookie policy: cloudflare.com/cookie-policy.

CookiePurposeDuration
__cf_bmBot management — distinguishes humans from automated traffic30 minutes
cf_clearanceRecords passing of a Cloudflare security challenge1 day

6. Managing and Disabling Cookies

6.1 Cookie Consent Banner

When you first visit Smart Money API, a cookie consent banner allows you to accept all cookies or essential cookies only. You can change your preference at any time by clicking "Cookie Settings" in the website footer.

6.2 Browser Settings

You can also control cookies through your browser settings. Most browsers allow you to:

  • View cookies currently stored on your device
  • Delete all or specific cookies
  • Block cookies from specific sites or all sites
  • Enable "Do Not Track" signals

Instructions for common browsers:

Note: Disabling essential cookies will prevent you from logging in and accessing paid features of the Service.

6.3 localStorage and sessionStorage

Some preferences are stored using browser localStorage rather than cookies. You can clear this data through your browser's developer tools or by clearing site data. This will log you out and reset preferences.

7. Your GDPR Rights Regarding Cookies

Under GDPR, you have the right to:

  • Withdraw consent for non-essential cookies at any time, without affecting the lawfulness of prior processing
  • Object to processing based on legitimate interests for analytics cookies
  • Access information about what cookie data we hold about you
  • Request deletion of cookie-derived personal data we hold

To exercise these rights, contact us at privacy@smartmoneyapi.com or use our contact form.

8. Changes to This Cookie Policy

We may update this Cookie Policy as we add or change features, or as laws evolve. Updates will be reflected with a new "Last Updated" date. Material changes will be communicated via the cookie consent banner on your next visit.

9. Contact Us

Questions about our use of cookies? Contact us: