How StatsBin uses browser storage, consent tools, and advertising technology.
StatsBin uses browser storage for user-requested preferences and functions such as theme, app-install prompts, service-worker state, and consent choices. The LUNC Burn Ads advertiser workspace saves campaign IDs and one-time management keys locally so that browser can reopen the campaign. Clearing site data removes that advertiser access and StatsBin cannot recover the key.
Publisher accounts use a separate strictly necessary session cookie after a successful wallet signature. Affiliate accounts use a separate opaque session cookie after password login. Both are unavailable to page JavaScript, sent only over HTTPS to StatsBin, blocked from cross-site requests, revocable and limited to 12 hours. Publisher wallet signatures and raw session tokens are not stored in local storage.
A valid affiliate link sets a signed, first-party, HTTP-only referral cookie for the configured attribution period (30 days by default). It stores only the referral code, landing path, first-touch time and expiry so a new publisher registration can be attributed. It is not sent to publisher websites and is not a third-party or cross-site advertising identifier.
The progressive web app and your browser may cache public assets and pages for speed and resilience. StatsBin does not place its own analytics identifier in your browser.
The embeddable LUNC Burn Ads script does not set cookies or use local storage. It requests a rotating creative and reports a view only after at least half the advert remains visible for one second.
Third-party advertising is limited to fallback mobile placements. Provider consent tools may ask for permission before optional advertising storage or personalised processing is used in regions where consent is required.
Publisher login challenges expire after five minutes; publisher and affiliate sessions expire after 12 hours; affiliate password-reset links expire after one hour. Referral cookies expire after the configured attribution period. Revoked and expired server records may remain for a limited security-audit period, but cannot authenticate another request. Preference, advertiser-workspace and consent records remain until they expire, are replaced, or you clear site data. Provider retention periods are described in their own policies.
This policy will be updated when storage or advertising behaviour materially changes. Last updated: 22 August 2026.