Introduction and who we are
Controller: Kyxrelynsnyx.world, 143 Lake Road, Devonport, Auckland 0622, New Zealand. Email ask@kyxrelynsnyx.world. We operate the Lunira brand website located at https://kyxrelynsnyx.world/.
When this Policy references “you,” we mean the person whose browser stores the technologies described below. “We” or “us” refers to the controller and any processors that place tags on our behalf after receiving lawful instructions.
What cookies and siblings do
A cookie is a small text file placed on your device when a server responds to a request. Local storage, session storage, pixels, software development kits inside share buttons, and server-side logs with similar identifiers behave like cousins for legal purposes because they enable recognition across visits.
First-party technologies are set by our domain. Third-party technologies are set by analytics or advertising partners when you allow them. Session cookies vanish when the browser closes; persistent cookies remain until they expire or you erase them manually.
HTTP cookie
Classic key-value pair exchanged through Set-Cookie headers.
Pixel
One-by-one image loads that ping measurement endpoints.
SDK snippet
Optional embeds gated behind marketing consent.
Legal anchors
Under the ePrivacy Directive as transposed into member state law, storing or accessing information on a terminal generally requires informed consent except where strictly necessary to deliver a service explicitly requested by the subscriber. GDPR shapes how we document consent records and honour withdrawal.
In New Zealand, the Privacy Act 2020 principle of transparency obliges us to describe tracking plainly. United States state statutes may grant opt-out rights from “sales” or “sharing”; although we do not monetise lists, we honour browser opt-out signals where feasible.
Strictly necessary stack
The preference vault key lunira_cookie_consent_v1 captures whether analytics or marketing tags may fire. Security cookies help mitigate cross-site request forgery attempts during authenticated sessions if we introduce accounts in future. Load balancers may also inject short-lived routing tokens.
You cannot disable these items through our interface without breaking core navigation. Browser blanket blocking is possible, but the site may fail to persist your consents or complete forms securely.
Analytics and performance
When you opt in, we may activate privacy-oriented analytics that aggregate page views, scroll depth, and conversion funnels. Internet Protocol addresses are truncated before storage when vendors support masking. Heat-mapping trials, if any, strip out free-text fields so keystrokes stay private.
Retention windows typically range from two to twenty-six months depending on vendor defaults; we choose the shortest setting compatible with meaningful trend detection and reconfirm consent annually.
Marketing and personalisation
Marketing cookies remember creatives you clicked, frequency caps to avoid repetition, and whether you arrived from social platforms. They do not read credentials from other sites. Remarketing lists require explicit consent because they track across contexts.
Where we use paid advertising (for example Google Ads in New Zealand), conversion or attribution tags in the marketing category fire only after you opt in to marketing storage; necessary cookies may still be required for secure forms without profiling you for ads.
If you reject marketing storage, previously set identifiers should expire naturally within weeks, but you can manually clear site data for an immediate reset.
Local storage mirroring
Some experiments mirror consent strings into localStorage for faster hydration on single-page transitions. Keys mirror the cookie categories—necessary, analytics, marketing—and are deleted when you clear browser storage or press revoke-all flows we may expose in account dashboards later.
Typical lifetimes at a glance
- Consent metadata: twelve months or until the banner resets after a major release.
- Session security token: browser session only.
- Analytics identifier: thirteen months rolling.
- Marketing partner UUID: between thirty and ninety days unless you refresh interactions.
Managing preferences
Use our “Cookie settings” button to toggle categories. Browser vendors provide global settings to block third-party cookies, delete existing ones, or send “Do Not Track” hints. We interpret Global Privacy Control signals as an opt-out of targeted advertising where law demands that response.
Industry tools such as the Network Advertising Initiative or Digital Advertising Alliance also list partners with one-click opt-outs, though they may not capture every regional vendor we trial.
Third-party processors
Analytics and marketing processors operate under written agreements requiring confidentiality, subprocessors disclosure, and assistance with data subject rights. Their cookie policies, linked from their consoles, supplement ours with exact cookie names and default expiry tables.
Honouring browser signals
We log receipt of recognised opt-out headers and reconcile them with stored consent JSON. Conflicts are resolved conservatively: if any signal demands restriction, we suppress optional tags until you provide fresh consent.
Young audiences
We do not direct marketing at children. If analytics suggests disproportionate youth traffic, we will re-evaluate measurement practices and consider shutting down optional tags entirely for affected landing pages.
Changes to this Cookie Policy
We timestamp substantive edits, summarise them at the top of this page for thirty days, and may re-display the banner when new vendors appear. Your continued browsing after notice constitutes acknowledgement unless stricter law requires renewed clicking.
Questions
Reach ask@kyxrelynsnyx.world with subject lines that include “Cookie enquiry” so we route your ticket quickly. Postal correspondence should cite Lunira Cookie Compliance at the Devonport address on file.