COOKIES & STORAGE.
Version 2026-09-14-v6 · effective 14 September 2026.
What this page covers
This is the current inventory of cookies and browser-side storage used by UP FOR GRABS. It should be read with the Privacy Notice. We do not currently use advertising cookies, cross-site behavioural advertising or a third-party audience-measurement service.
Strictly necessary session cookie
ufg_session keeps the site secure and usable. It carries a random session identifier used for sign-in state, checkout continuity, CSRF protection, account controls, community submissions and short-lived interface notices. The cookie is HTTP-only, SameSite=Lax and secure when sent over HTTPS. A signed-in session can last for up to 14 days, with shorter inactivity and security rotation controls. Signing out clears it.
Referral attribution
If you follow a valid referral link, the referral identifier may be held in the necessary session only long enough to complete account creation and validate the referral. It is not used for cross-site advertising.
Browser storage and generated files
The site may use local browser storage for harmless interface state, such as the last open visual panel, and may create a temporary in-browser image when an owner downloads a claim card. This information stays on the device unless you clear it or share the generated file. Payment fields are supplied by Stripe; Stripe may set its own necessary fraud-prevention and payment cookies under its published privacy and cookie information.
Choices
Because the site currently sets only storage needed to provide, secure or remember the service, there is no cosmetic “accept all” banner. You can block or clear cookies in browser settings, but blocking the necessary session cookie will prevent sign-in, checkout, account controls and community participation. If non-essential analytics or advertising storage is introduced later, this page and the consent mechanism must be updated before it is enabled.