Legal
Cookie Policy
This page lists the cookies nextluk.com sets, what each one does, and how to remove them. The list is short because the site sets no advertising, analytics, or third-party tracking cookies.
Last updated September 21, 2026
What a cookie is
A cookie is a small file that a site asks your browser to store, and that the browser sends back on later requests to the same site. Cookies are used to keep a sign-in working or to remember a choice between visits. A similar entry kept in your browser without an expiry date is called local storage, and the same rules of transparency apply to it.
Cookies set by this site
Session cookie for staff sign-in. The administration area is protected by Auth.js, which issues the session cookie `authjs.session-token`, or `__Secure-authjs.session-token` when the site is served over HTTPS. It holds the signed session for a signed-in staff member, is marked HttpOnly so scripts on the page cannot read it, uses SameSite=Lax, and expires after eight hours or at sign-out. It is never set for an ordinary visitor reading the public site.
Companion CSRF cookie from the same sign-in system. Auth.js also sets a short-lived companion cookie that protects the sign-in form against cross-site request forgery. It exists only alongside a sign-in attempt and carries no information about your browsing.
Language preference cookie `NEXT_LOCALE`. When you choose English or French from the language selector, the site stores that choice in a `NEXT_LOCALE` cookie so a later visit to the bare domain opens in the language you picked. It is set by the page rather than by a tracking service, is readable by the page, uses SameSite=Lax, and expires after one year. Clearing it returns the site to the language your browser asks for, then to English.
Cookies the site does not set
There are no advertising cookies, no analytics or audience-measurement cookies, and no third-party tracking cookies on nextluk.com. No product analytics service is connected to the site.
Content photographs are loaded from images.unsplash.com. That host receives your IP address when such an image loads, because a browser has to request the file from it, but the request carries no cookie that identifies you to NextLuk.
Managing cookies
Every current browser lets you see the cookies a site has stored, remove them, and block them, usually under privacy or site-data settings. Blocking or removing the language cookie costs nothing beyond the language preference, and the language selector still works for the current visit.
Removing the staff session cookie signs that member of staff out immediately.
Questions about cookies
Write to contact@nextluk.com with any question about the cookies listed here, or if you believe the site has set something that is not described on this page. The answer comes by email.
Email: contact@nextluk.com
