Contents
1. What Are Cookies?
Cookies are small text files that a website stores on your device when you visit. They are widely used to make websites work, operate more efficiently, and provide information to the site operator. Similar technologies include browser local storage, session storage, IndexedDB, pixels, and SDK identifiers. In this Policy we refer to all of these as “cookies”.
Cookies may be first-party (set by us) or third-party (set by a service provider acting on our behalf). They may be session cookies (deleted when you close your browser) or persistent cookies (stored for a defined period).
2. Categories We Use
We group cookies into four categories. The default state of each is shown below.
| Category | Default | Purpose |
|---|---|---|
| Strictly necessary | Always on | Required to operate the Service. Used for authentication, session management, load balancing, fraud prevention, and remembering your cookie-consent choice. These cannot be disabled. |
| Functional | Off until you opt in | Remember your preferences, language, saved filters, and UI state across sessions. |
| Analytics / Performance | Off until you opt in | Anonymous usage measurement and error tracking that help us understand how the Service is used and improve reliability and features. We do not sell this data. |
| Targeting / Advertising | Off (category disclosed for transparency) | We do not currently run advertising, profiling, or cross-context behavioral tracking pixels. This category is listed so our disclosure matches our cookie-consent UI and so the mechanism exists in case a future feature requires it. Your choice will be respected if and when that changes. |
3. Specific Cookies and Similar Technologies
The table below lists the primary cookies and storage keys used by the Service. Because our infrastructure evolves, this list may not be exhaustive at all times; it reflects the current set as of the effective date above.
| Name | Category | Type | Purpose | Retention |
|---|---|---|---|---|
axiom_session |
Strictly necessary | First-party cookie | Maintains your authenticated session. | Session / up to 30 days |
axiom_csrf |
Strictly necessary | First-party cookie | Cross-site request forgery protection on forms and API calls. | Session |
axiom.cookie.consent |
Strictly necessary | Local storage | Stores your cookie-consent choices so the banner does not reappear each visit. | Up to 12 months |
axiom.cookie.consent.log |
Strictly necessary | Local storage | Audit log of consent changes, retained to demonstrate lawful processing. | Up to 12 months |
axiom_prefs |
Functional | First-party cookie / local storage | Remembers UI preferences such as theme, league selection, and saved views. | Up to 12 months |
axiom_metrics |
Analytics | First-party cookie | Anonymous usage and performance measurement. | Up to 13 months |
__stripe_mid, __stripe_sid |
Strictly necessary | Third-party (Stripe) | Set by Stripe on checkout / billing pages to process payments securely and prevent fraud. | Session / up to 1 year |
4. Third-Party Cookies
The Service uses cookies set by the following third parties. Those cookies are governed by the third parties’ own privacy and cookie policies.
- Stripe, Inc. — payment processing and fraud prevention on checkout and billing pages.
- Content delivery and hosting providers — infrastructure cookies used for load balancing, traffic routing, and security.
We do not permit third parties to use cookies set on the Service for their own advertising or profiling purposes.
5. How to Manage Your Preferences
You can manage cookies in two ways:
- In-Service preferences. Use the Cookie Preferences link in the footer, or open the preferences panel directly via the button below. Your choices are saved per browser and per device.
- Browser settings. Most browsers let you block, limit, or delete cookies via their settings. Blocking strictly necessary cookies may prevent the Service from functioning.
6. Global Privacy Control and Do-Not-Track
Where required by applicable law, we honor Global Privacy Control (GPC) signals sent by compatible browsers as an opt-out of the sale or sharing of personal information, to the extent that “sale” or “sharing” occurs. As disclosed in our Privacy Policy, we do not currently sell personal information or share it for cross-context behavioral advertising. We treat GPC as an expression of preference for privacy-protective defaults.
Most browsers also support a “Do-Not-Track” (DNT) signal. Because there is no industry-standard interpretation of DNT, we do not currently respond to DNT signals, but we apply equivalent privacy defaults as described in this Policy.
7. Changes to This Policy
We may update this Cookie Policy from time to time. Material changes will be announced on the Service before taking effect. The “Effective date” at the top of this Policy indicates the latest revision.
8. Contact
This Cookie Policy is provided for review and should be finalized by qualified legal counsel licensed in your jurisdiction before customer-facing use.