Cookie Policy
1. What this policy covers
This policy explains the cookies and similar technologies Yunoh uses, why, how long they last, and how you control them. It sits alongside the Privacy Policy. "Cookies" here covers any comparable technology that stores information on your device or reads it — local storage, session storage, pixels and similar identifiers; the consent rules are the same for all of them.
Yunoh runs no advertising cookies at launch. We operate no advertising, retargeting or attribution pixels, and share no data with advertising networks. If that changes, we will update this policy and ask for fresh consent before setting anything new.
2. The categories we use
Strictly necessary. These make the Platform work: signing in, holding a Session, buying Coins, moving between pages without being logged out. They do not track you across other sites and cannot be switched off in our preference centre. They rest on the strictly-necessary exemption in the ePrivacy rules, with Article 6(1)(b) and 6(1)(f) GDPR covering the processing.
Functional. These remember choices — language, subtitles, audio and video device preferences, dismissed notices. We ask for your consent first.
Analytics. These show us in aggregate how the Platform is used: pages visited, where signup drops off, whether a change helped. They are configured for pseudonymisation, IP truncation where supported, and no cross-site tracking. We ask for your consent first.
Security and anti-fraud. These distinguish humans from bots, mitigate denial-of-service attacks, detect account takeover and multi-accounting, and screen payment fraud. Most are strictly necessary and set without consent, because without them we could not meet our Article 32 GDPR security obligations. Where one goes beyond that — profiling behaviour beyond the immediate protection of the service — we treat it as non-essential and ask for consent.
3. The technologies we set
| Name | Set by | Category | Purpose | Duration |
|---|---|---|---|---|
| yunoh_session | Yunoh | Strictly necessary | Keeps you signed in | Session |
| yunoh_auth_refresh | Yunoh | Strictly necessary | Renews sign-in so you are not logged out mid-Session | 30 days |
| yunoh_csrf | Yunoh | Strictly necessary | Protects forms and payments against cross-site request forgery | Session |
| yunoh_age_gate | Yunoh | Strictly necessary | Records the 18+ entry declaration | 30 days |
| yunoh_consent | Yunoh | Strictly necessary | Stores your cookie choices, so we can honour and evidence them | 12 months |
| yunoh_lb | Yunoh | Strictly necessary | Routes you to the correct server, so a Session is not dropped | Session |
| yunoh_locale | Yunoh | Functional | Remembers language and region | 12 months |
| yunoh_media_prefs | Yunoh | Functional | Remembers camera, microphone and subtitle preferences | 6 months |
| yunoh_ui_state | Yunoh | Functional | Remembers dismissed notices and interface choices | 6 months |
| __cf_bm | Cloudflare | Strictly necessary (security) | Bot management | 30 minutes |
| cf_clearance | Cloudflare | Strictly necessary (security) | Records a passed security challenge | Up to 12 months |
| __cflb | Cloudflare | Strictly necessary | Load balancing and session affinity | Session or short-lived |
| yunoh_device_id | Yunoh | Security and anti-fraud | Detects multi-accounting, ban evasion and abuse of Guest free minutes | 12 months |
| yunoh_risk | Yunoh | Security and anti-fraud | Carries risk signals for payment fraud screening | Session |
| Payment processor cookies | a third-party PCI- DSS-compliant payment processor | Strictly necessary (payment) / anti-fraud | Completes checkout and prevents payment fraud; set on the processor's own frames | Per the processor's notice |
| Analytics identifier | Our analytics provider | Analytics | Aggregate usage measurement, pseudonymised | 13 months maximum |
Names and durations may change as we develop the Platform; the current, complete list is always in the preference centre.
Third-party technologies are also governed by the third party's own notice. A processor may only use the data for us; where a third party is an independent controller — as our payment processor is for parts of its own fraud and compliance processing — its notice applies to that use.
4. How we ask for consent
On your first visit from the EU, EEA, UK or any other market where consent is required, you see a consent banner before any non-essential technology is set. The banner:
explains in plain language what we want to set, and why; gives "Accept all" and "Reject all" as equally prominent choices, with no pre-ticked boxes and no design that nudges you towards accepting; offers "Manage preferences", where you can consent category by category rather than all or nothing; treats closing or ignoring the banner as no consent, so nothing non-essential is set; records your choice, the date, and the version of this policy you were shown, so we can evidence it.
We ask again after 12 months, or sooner if we add a materially different technology or a new purpose.
Strictly necessary technologies are set regardless of your choice, because the Platform cannot run without them. Where a market does not require prior consent, we still honour the choices you set in the preference centre.
5. Changing or withdrawing consent
Withdrawing consent is as easy as giving it.
- Preference centre. Open Cookie preferences in the site footer or your account settings. Change any category and save; the change takes effect immediately, and non-essential cookies already set are removed or expired.
- Browser controls. Every major browser lets you block or delete cookies. Deleting ours also deletes your consent record, so we will ask again on your next visit.
- Global Privacy Control. Where our consent platform detects a GPC signal, we treat it as withdrawal of consent for non-essential categories.
Withdrawal does not affect the lawfulness of anything done while consent was in force.
Refusing functional technologies means the Platform forgets your preferences; refusing analytics has no effect on you; blocking strictly necessary technologies means the Platform will not work. Refusing non-essential technologies never costs you access, features or a different price for Coins.
6. Changes to this policy
We update this policy when the technologies we use change; the "Last updated" date shows the current version. If we add a new non-essential technology or purpose, we will ask for your consent again before it is set.
Contact
Data protection, data rights and access requests: privacy@yunoh.com Account, billing, safety reports and complaints: support@yunoh.com General enquiries: info@yunoh.com
PXL NexQuantum Ltd Voukourestiou 25, Neptune House, 1st floor, Flat/Office 11, Zakaki, 3045 Limassol Republic of Cyprus Company registration number: HE 497211
You may complain to the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus, or to the supervisory authority where you live. Nothing in this policy removes or limits any right you have under mandatory local law.