Every cookie roplush.com sets, what each one is for, how long it lasts, and why none of them needs a consent banner.
Last updated 18 September 2026
This policy lists every cookie roplush.com sets, what each one is for, and how long it lasts. It is the detail behind the cookies section of the privacy policy.
A cookie is a small piece of text a site asks your browser to store and send back on your next visit. A session cookie is deleted when you close your browser. A persistent cookie stays until it expires or you delete it. The table below says which each one is.
We run no analytics, no advertising and no tracking. Every cookie below is strictly necessary — it exists to do something you asked for, such as keeping your basket or keeping you signed in — and strictly necessary cookies do not require consent under the ePrivacy Directive or the GDPR.
Reading the site sets nothing. Cookies are set when you put a plush in your basket, when you sign in, and when the payment fields load at checkout.
| Cookie | Set by | Set when | Purpose | Expires |
|---|---|---|---|---|
rp_cart | RoPlush | You add a plush to your basket | Keeps your basket between page loads and visits | 14 days |
sb-…-auth-token | RoPlush | You sign in | Holds the tokens that prove this browser is signed in | End of the session; signing out deletes it |
__stripe_mid | Stripe | The payment fields load at checkout | Fraud prevention on the payment | 1 year |
__stripe_sid | Stripe | The payment fields load at checkout | Fraud prevention on the payment | 30 minutes |
There is no other cookie, and no local storage, session storage or fingerprint used in place of one.
rp_cart is httpOnly, so no script on the page can read it. It holds which
campaigns you have chosen and how many of each, and nothing else — not your
name, not your address, not a price, not anything about your payment. There is
no copy of an un-checked-out basket on our servers.
The sign-in cookies are set when you sign in and not before. They are httpOnly
too, and they are refreshed as you browse so that you are not signed out halfway
through an order. Signing in with Google or Discord sets one more, for the few
seconds the sign-in takes, and it is deleted when the sign-in completes.
They do not hold your name, your role, or anything about your orders. What they identify is your account; everything about it is looked up on our servers, every time.
If you never sign in, none of them is set.
Stripe is our payment processor. When you reach checkout, the card fields are served by Stripe inside their own frame, and loading them sets Stripe's two cookies on this domain. Stripe uses them to tell one device from another and block fraudulent payments.
They are set at checkout and nowhere else. Stripe's own cookie policy (opens in a new tab) covers what it does with them, and the privacy policy covers what Stripe processes for us.
Every browser can block or delete cookies, usually under Settings → Privacy:
Blocking them breaks the things they do: your basket empties on every page load, you cannot stay signed in, and checkout will not accept a payment. Nothing else on the site is affected — you can read every campaign page with cookies blocked.
If we ever set a cookie that is not strictly necessary, this page changes first and asks for your consent before setting it. Write to support@roplush.com with anything about this page.