Cookie policy
The cookies Mill & Merchant uses, why, and how to manage them. Plain-English, no dark patterns.
Last updated: May 2026
What cookies are
Cookies are small pieces of text stored by your browser when you visit a site. Some are essential for the site to work (signing you in, remembering preferences). Others are optional and only set if you agree to them.
I treat consent seriously: nothing non-essential fires until you've made a choice, and you can change your mind any time using .
Cookies in use
The table below covers the cookies currently set on millandmerchant.co.uk. Third-party cookies are only set after you opt in.
| Cookie | Category | Purpose | Retention | Provider |
|---|---|---|---|---|
| authjs.session-token / __Secure-authjs.session-token | Essential | Keeps you signed in to your account or merchant portal. | Session / up to 30 days | Mill & Merchant (Auth.js) |
| authjs.csrf-token / __Host-authjs.csrf-token | Essential | Prevents cross-site request forgery on sign-in forms. | Session | Mill & Merchant (Auth.js) |
| authjs.callback-url | Essential | Remembers where to return you after signing in. | Session | Mill & Merchant (Auth.js) |
| mm_cookie_consent | Essential | Stores your cookie preferences so we don't ask again on every page. | 1 year | Mill & Merchant |
| _vercel_* / Vercel Analytics & Speed Insights | Analytics | Privacy-respecting aggregate traffic and performance measurement. No cross-site tracking, no advertising identifiers. | Up to 1 year | Vercel Inc. |
Marketing cookies are reserved for future use and are not active today.
How I categorise them
- Essential— strictly necessary for authentication, security, and basic site functions. These don't require consent under UK GDPR / PECR, and they can't be switched off.
- Analytics — Vercel Analytics and Speed Insights, used to understand aggregate traffic and performance. No advertising identifiers, no cross-site tracking. Off by default; only set if you opt in.
- Marketing — reserved for future use (e.g. measuring the effect of campaigns). Not currently set. Off by default.
Managing your preferences
Open at any time to change which categories you allow. Your choice is stored in a first-party cookie called mm_cookie_consent for one year — clearing site data resets it.
You can also block or delete cookies from your browser settings. Doing so may sign you out or break parts of the site that depend on essential cookies.
Withdrawing consent
Withdrawing consent is just as easy as giving it — use the link above. Withdrawal doesn't affect anything that already happened while consent was in place.
Questions
For anything about cookies or data on this site, email hello@millandmerchant.co.uk. The privacy policy covers the wider picture.
Not legal advice — if you need a bespoke policy for your own business, speak to a solicitor.