Cookie Policy
Short version: the site needs a handful of local values to work, and asks before loading anything that measures you.
Last updated: 30 August 2026
Your current choice
Analytics scripts are not loaded until you agree. If you choose “essential only”, Google Analytics and Microsoft Clarity are never inserted into the page at all — this is not a setting that merely tells them to behave.
Essential storage
These are needed for the site to function. They cannot be switched off, and they are not used to track you across other websites.
| Name | Kind | What it does | How long |
|---|---|---|---|
| NEXT_LOCALE | Cookie | Remembers the language you picked in the switcher | Up to a year |
| virar.consent.v1 | Local storage | Your answer to the cookie banner, so it stops asking | Until you clear it |
| virar_hints_enabled_v1 | Local storage | Whether you want the builder's hints shown | Until you clear it |
| virar_template_hints_dismissed_v1 | Local storage | Which hints you have already dismissed | Until you clear it |
| virar_color_usage_v1 | Local storage | The colours you recently used, so they stay to hand | Until you clear it |
None of these leave your browser. The local-storage entries are never sent to our servers.
Analytics cookies
Only set if you agreed. We use them to find out where the card builder confuses people — which step gets abandoned, which button never gets pressed.
| Name | Set by | What it does | How long |
|---|---|---|---|
| _ga, _ga_* | Google Analytics 4 | Distinguishes visitors and sessions for aggregate statistics | Up to 2 years |
| _clck, _clsk | Microsoft Clarity | Links a session to its recording, so we can watch how the interface was used | Up to a year |
Clarity records sessions — mouse movement, clicks, scrolling and the layout of the pages you saw. That is the honest reason it sits behind consent rather than in the essential list. It is used to fix the interface, not to identify you, and we do not try to match a recording to a person.
Payment cookies
On the payment step, Stripe sets its own cookies (such as __stripe_mid and __stripe_sid) to detect fraud and keep the payment form working. They are set by Stripe, not by us, and only on the page where you actually pay. Without them a payment cannot be taken safely, so they count as essential to that step — see Stripe's privacy policy.
Controlling cookies yourself
Beyond the controls at the top of this page, every browser lets you view, block and delete cookies and site data for a given site. Blocking everything will break parts of the builder that store your preferences locally, but it will not stop you from ordering a card.
What happens to the rest of your data is covered in the Privacy Policy.