Legal

Cookie Policy

ICONIC Human Design Education PMA — Last updated: April 12, 2026

Contents

  1. What Are Cookies?
  2. How We Use Cookies
  3. Cookie Categories
  4. Specific Cookies We Use
  5. Third-Party Cookies
  6. Managing Your Cookie Preferences
  7. Do Not Track
  8. Changes to This Policy

1. What Are Cookies?

Cookies are small text files that are placed on your device (computer, tablet, or mobile phone) when you visit a website. They are widely used to make websites work efficiently, remember your preferences, and provide information to site owners about how their site is being used.

In addition to cookies, we use similar technologies such as localStorage and sessionStorage — browser-based storage mechanisms that serve similar functions. This policy covers all such technologies collectively referred to as "cookies."

We keep our cookie use minimal. We do not use advertising cookies or cross-site trackers. Our cookies are limited to what is necessary to operate the Service and understand how it's being used.

2. How We Use Cookies

We use cookies to:

  • Keep you signed in during your session and across visits (authentication)
  • Remember your settings and preferences (theme, language, layout choices)
  • Understand how visitors use our site so we can improve it (analytics)
  • Ensure the Service functions correctly (functional/session cookies)
  • Prevent abuse and protect security (security cookies)

We do not use cookies for:

  • Targeted or behavioral advertising
  • Cross-site tracking or profiling
  • Selling or sharing your browsing activity with advertisers or data brokers

3. Cookie Categories

🔒

Strictly Necessary Cookies

Always Active

These cookies are essential for the Service to function. They enable core features like secure login, session management, and access to protected content. You cannot opt out of these cookies without affecting Service functionality. No personal data is shared with third parties via these cookies.

⚙️

Preference Cookies

Optional

Preference cookies remember your settings and choices to personalize your experience — for example, your selected display theme (light or dark mode), UI layout preferences, and dismissed notifications. Without these cookies, some personalization features will reset each session.

📊

Analytics Cookies

Optional

Analytics cookies help us understand how visitors interact with the Service — which pages are most visited, where users drop off, and how features are used. This data is aggregated and anonymized; it is not used to identify individual users. We use this information solely to improve the Service.

🛡️

Security Cookies

Always Active

Security cookies protect users and the Service from fraud, abuse, and unauthorized access. They support CSRF protection for OAuth flows, rate limiting, and session integrity verification. These cookies contain no personally identifiable information.

4. Specific Cookies We Use

4.1 Authentication & Session

Cookie / Key Type Purpose Duration
iconic_token localStorage Stores your JWT authentication token to keep you signed in 7 days or until logout
session HTTP cookie Server-side session identifier for authenticated requests Session (browser close)
iconic_session HTTP cookie (httpOnly) Secure session cookie for authenticated page views 7 days

4.2 Preferences

Cookie / Key Type Purpose Duration
iconic-theme localStorage Stores your selected display theme (light or dark mode) Persistent (until cleared)
pwa-dismissed localStorage Records whether you dismissed the app install prompt Persistent (until cleared)
cookie-consent localStorage Records your cookie consent choice 1 year
announcement-dismissed sessionStorage Tracks whether you dismissed the announcement bar this session Session (browser close)

4.3 Analytics

Cookie / Key Type Purpose Duration
Server-side logs Server log (no client cookie) Aggregated page view and feature usage analytics (IP anonymized) 12 months (server-side)

We do not currently use third-party analytics platforms (e.g., Google Analytics). Usage analytics are processed server-side from anonymized log data.

4.4 Security

Cookie / Key Type Purpose Duration
oauth_state In-memory (server-side) CSRF state token for OAuth authorization flows 15 minutes
x-request-id HTTP header Request tracing for security auditing Session

5. Third-Party Cookies

5.1 Stripe (Payment Processing)

When you complete a purchase, Stripe may set cookies to facilitate secure payment processing and fraud prevention. These cookies are governed by Stripe's Privacy Policy. We do not control Stripe's cookies.

5.2 Embedded Content

Some pages may include embedded content from YouTube, SoundCloud, or other platforms (e.g., course videos, audio samples). These third-party services may set their own cookies when you interact with embedded content. We recommend reviewing their privacy policies directly.

We minimize the use of third-party embeds and, where possible, use privacy-preserving embed modes (e.g., YouTube's no-cookie domain).

5.3 No Advertising Networks

We do not use cookies from advertising networks, social media pixels (Facebook Pixel, TikTok Pixel, etc.), or any behavioral targeting services. We have no third-party trackers for advertising purposes on this site.

6. Managing Your Cookie Preferences

6.1 Browser Settings

You can control and manage cookies through your browser settings. Most browsers allow you to:

  • View what cookies are stored and delete them individually or in bulk
  • Block all cookies or specific types of cookies
  • Be notified when a new cookie is set

Instructions for managing cookies in popular browsers:

  • Google Chrome
  • Mozilla Firefox
  • Safari (iOS & macOS)
  • Microsoft Edge

Note: Blocking strictly necessary cookies (session and authentication cookies) will prevent you from accessing your account and using protected features of the Service.

6.2 Clearing localStorage

Some of our preference and session data is stored in your browser's localStorage rather than as cookies. To clear this data, use your browser's developer tools or clear all site data for thehumandesignsystem.com in your browser settings.

6.3 Opting Out of Analytics

Our analytics are server-side and based on anonymized log data, not client-side cookies. There is no browser-based opt-out mechanism required. If you are in the EU/EEA, analytics processing is based on our legitimate interest in improving the Service; you may object to this processing by contacting us via the contact form.

7. Do Not Track

Some browsers offer a "Do Not Track" (DNT) setting. Because we do not engage in cross-site tracking for advertising purposes, our responses to DNT signals are consistent regardless of DNT status: we do not track you across third-party websites.

We note that there is currently no universally accepted standard for how websites should respond to DNT signals; as such, we do not alter our data practices based on browser DNT settings.

8. Changes to This Policy

We may update this Cookie Policy from time to time as we add or remove technologies or as legal requirements change. We will post any changes on this page with a revised "Last updated" date. For material changes, we will also provide notice via email or a banner on the site.

Questions About Cookies?

If you have questions about how we use cookies or want to exercise data rights related to cookie data, contact us via the web form.

Contact Us

Related: Terms of Service  ·  Privacy Policy