Cookie policy
This cookie policy describes the cookies and equivalent storage that Flagside.football uses, and how you can control them. It supplements our Privacy policy.
What is a cookie?
A cookie is a small text file a website asks your browser to store, so it can recognise your browser on a return visit or keep track of state during a session. "Equivalent storage" is the same idea — localStorage, sessionStorage, IndexedDB — used for the same purposes. Wherever this policy refers to "cookies" it also covers those equivalents.
Cookies Flagside sets
We use the smallest set of cookies that lets the site work.
Strictly necessary
These cannot be turned off — the site would not function without them.
- `NEXT_LOCALE` — remembers which market edition you are reading (UK, NL, DE, FR, …) so we don't redirect you back to the geoIP default on every visit. Set when you choose a market, or by the middleware after locale detection. One year.
- `next-auth.session-token` — keeps editorial-team members signed in to the /admin dashboard. Set only when an admin logs in. Two weeks.
- `fs_geo_suggest` — remembers that you have seen or dismissed the soft-suggest banner ("Visiting from Germany?"). 30 days.
- `fs_cookie_consent` — remembers whether you have accepted or declined the analytics category in our cookie banner. One year. Stored in localStorage, not as a cookie.
Reader accounts (only if you create one)
Reading Flagside needs no account. Nothing in this section exists for a reader who has not made one, and there is no cookie to delete if you have not.
If you do register, we set one cookie so that you stay signed in between pages:
- `__Secure-better-auth.session_token` — keeps you signed in to your reader account. Set when you sign in, removed when you sign out. Marked `HttpOnly` and `SameSite=Lax`, so it is not readable by scripts on the page and is not sent when another site links to us.
- `__Secure-better-auth.session_data` — a signed copy of your username and sign-in state, so that showing your name in the header does not need a database query on every page. Refreshed every five minutes. It holds no more than the session cookie already implies.
On a development build the same two appear without the `__Secure-` prefix, because that prefix requires HTTPS.
This is a different cookie from the `next-auth.session-token` above, which is for our own editorial team. Reader accounts and staff accounts share no cookie, no password and no database table.
These are strictly necessary in the specific sense that they exist only to do the thing you asked for. We do not read them for analytics, we do not use them to build a profile of what you read, and they are never shared with anyone.
What signing up stores on our servers — your email address, your username, and anything you post — is not a cookie question, and it is covered by the Privacy policy rather than here.
Video preferences (optional)
None of these exists until you create it, and each is absent for every reader who has not. They were listed as "strictly necessary" in an earlier revision of this policy, which was wrong: nothing about the site stops working without them.
- `fs_embed_consent` — remembers that you asked us to stop showing the notice before an embedded video elsewhere on the site. Absent unless you tick that box. It does not control the Reels feed, where video now plays automatically for everyone. Stored in localStorage, not as a cookie.
- `fs_video_sound` — remembers, for the current browser tab only, that you MUTED the video. A comfort setting rather than a permission, and cleared when you close the tab. Stored in sessionStorage.
`fs_video_autoplay` was listed here in an earlier revision. It no longer exists: automatic playback is now the behaviour for every reader rather than something you switch on, so there is nothing for the entry to record. We clear any copy left in your browser the next time you visit.
Analytics (optional, consent-based)
A pseudonymous identifier set by our analytics provider for de-duplicating pageviews. We use a cookieless analytics product wherever possible; the identifier is set only when you accept the analytics category in our cookie banner. 13 months.
You can revoke consent at any time. We will treat the revocation as a request to delete previously collected data going forward.
Video from YouTube
Some pages, including Reels, carry football video published by clubs and competitions on their own YouTube channels.
Video plays automatically, and you do not have to press anything for it to start. As soon as a video card reaches your screen we load the player from YouTube and it begins playing, muted. This is the behaviour for every reader. There is no setting that turns it off, and an earlier version of this page said the opposite — it said nothing from YouTube loaded until you pressed play. That was true when it was written and it is not true now.
Because there is no press, there is no moment at which you are asked first. We would rather state that plainly than describe it as a choice you made.
Each time a video loads:
- We use `youtube-nocookie.com`, which we have measured as setting no cookies, rather than the standard player, which sets six before you interact with it at all — including one that lasts about 180 days.
- The player nevertheless writes to your browser's local storage, contacts Google servers, and discloses your IP address and the address of the page you are on to Google. Google's own description of the no-cookie player promises that playback is not used to personalise advertising. It does not promise that nothing is stored or received, and we are not going to imply that it does.
- This happens once per video, as that video reaches your screen. Only one player exists at a time: when you scroll on, the previous player is removed from the page entirely rather than paused, which is also why the sound stops.
- Automatic playback always starts muted, and every video does — not just the first. Your browser refuses to start an embedded video with sound on its own, and on a phone it refuses however much you have already tapped, so a video that started by itself is always a silent one. To hear a video, use the Sound control on the card. That turns the sound on for that video; the choice to Mute is remembered for the current browser tab only — the `fs_video_sound` entry above.
- Nothing loads before the first video reaches your screen. Cards you have not scrolled to show a still image served from our own servers, and Google is not contacted for those.
What Google does with that data is governed by Google's own privacy policy, not ours.
Cookies we do NOT set
- No advertising cookies.
- No social-media tracking pixels.
- No fingerprinting beacons.
- No cross-site identifiers shared between Flagside and any other property.
- No third-party content anywhere except the YouTube player described above, and nothing at all outside the video cards. We are not going to list "loads only when you ask" here any more, because for video that is no longer true.
How to control cookies
- The cookie banner at the bottom of the screen lets you accept or decline the analytics category. Your choice is remembered for 12 months; you can revisit the banner at any time by clearing `fs_cookie_consent`.
- There is currently no in-page control that stops video loading. The honest answer is that if you do not want the Reels feed contacting Google, do not open the Reels feed; the rest of the site carries no automatic video. Blocking third-party frames in your browser or an extension also works, and we would rather tell you that than pretend we offer a switch we do not.
- The analytics choice and the video behaviour are separate permissions and neither affects the other: declining analytics does not stop the player loading, and it never did.
- If you have asked us to stop showing the notice on embedded video elsewhere on the site and want it back, clear `fs_embed_consent` — withdrawing is meant to be exactly as easy as granting.
- To turn a video's sound on, or to mute it again, use the Sound control on the card. A mute holds for the tab: `fs_video_sound` never outlives it, and closing the tab resets it.
- If you have a reader account, signing out deletes its cookies. There is no separate setting to hunt for and no need to clear anything by hand. Deleting the account itself, from your account page, removes what we hold on our servers as well.
- Your browser also lets you delete cookies or block them globally. Blocking strictly-necessary cookies will sign you out of your reader account and of the admin dashboard, and reset your market preference on every visit.
Updates
We may update this policy when we add or remove a service that sets cookies. The "Last updated" date below reflects the most recent revision. Material changes are also surfaced via a banner on the site.
Contact
Cookie questions: privacy@flagside.football.
Last updated: 2026-08-13