Tracking Technologies
Cookie Notice
Version 1.0 · Effective September 19, 2026
This Cookie Notice explains how Aethos Solutions LLC (“Canvas UGC Marketplace”, “we”, “us”) uses cookies and similar technologies on canvasugcmp.com and any other site we control that links to this notice (the “Sites”). It is part of our Privacy Policy.
The Sites use only strictly necessary cookies: one that keeps you signed in, one used briefly during two-factor sign-in, and security cookies set by Cloudflare, plus short-lived cookies to protect a social-account connection or Google sign-in. We do not add analytics, advertising or session-replay trackers. Optional TikTok and Instagram players load when you open a video preview and may use their own cookies.
1.What Cookies Are
Cookies are small text files a website stores on your device so it can recognise your browser on later requests. Session cookies expire when you close your browser; persistent cookies last until a set date or until you delete them. First-party cookies are set by the site you are visiting; third-party cookies are set by another domain, for example a payment provider’s page embedded in or linked from ours.
2.Cookies We Set
| Cookie | Purpose | Type | Lifetime |
|---|---|---|---|
| canvas.oauth_state / canvas.state | Protects Google sign-in by tying its callback to the browser that started it. | Essential, first-party, HttpOnly, Secure (production carries the __Secure- prefix) | Short-lived; removed when the callback is processed |
| __Host-canvas-social / __Host-canvas-instagram | Binds the social-account authorization to your browser to prevent account mix-ups. | Essential, first-party, HttpOnly, Secure, SameSite=Lax | 10 minutes; removed when the callback is processed |
canvas.session_token | Identifies your signed-in session. Without it you cannot use your account. | Essential, first-party, HttpOnly, Secure, SameSite=Lax (production cookies carry the __Secure- prefix) | 7 days from your last daily activity; cleared on sign-out |
canvas.two_factor | Carries the pending sign-in while you enter a two-factor code. | Essential, first-party, HttpOnly, Secure | Minutes; removed once the code is verified |
__cf_bm | Cloudflare bot management. Distinguishes humans from automated traffic to protect the Sites. | Essential, set by Cloudflare on our domain | Up to 30 minutes |
cf_clearance | Records that you passed a Cloudflare security challenge, if one was shown. | Essential, set by Cloudflare on our domain | Up to a few hours |
3.Cookies Set by Others
- Google (accounts.google.com). Choosing Google sign-in opens Google’s sign-in page, which uses Google’s cookies to authenticate you under its own privacy policy. No Google sign-in iframe or tracking script loads on Canvas before you choose it.
- Cloudflare Turnstile (challenges.cloudflare.com). The human-verification widget on the sign-up page runs in a frame from Cloudflare and may set cookies on Cloudflare’s domain to complete the check. Cloudflare’s privacy policy is at cloudflare.com/privacypolicy.
- Stripe (checkout.stripe.com, connect.stripe.com). Brands paying for wallet top-ups and creators onboarding for payouts are sent to pages hosted by Stripe, which set Stripe’s cookies for fraud prevention and to operate its pages. Stripe’s cookie policy is at stripe.com/cookies-policy/legal.
TikTok and Instagram video previews load their official players only after you choose a preview. Those providers receive your IP address and browser information and may use cookies under their own policies. You can leave previews closed or follow the link to watch on the provider’s site. Fonts are served from our own domain.
4.What We Do Not Use
- No analytics cookies or scripts (no Google Analytics or similar).
- No advertising, retargeting or attribution cookies or pixels.
- Social account connection happens on the provider’s authorization page. Optional video players are described above.
- No session-replay or heat-map tools.
- No tracking pixels in the emails we send.
- No browser local storage, session storage or IndexedDB for tracking.
If we ever add any of these we will update this notice first and, where the law requires, ask for your consent before they run.
5.Other Technologies
Uploads of screenshots and rights files are made directly from your browser to a private storage bucket using a short-lived signed URL; this involves no cookies. We keep short-lived rate-limit counters on our servers, keyed by IP address or account, that are not stored on your device.
6.Your Choices
- Browser settings. Every major browser lets you view, block and delete cookies. If you block our session cookie you will not be able to sign in. Instructions: Chrome, Safari, Firefox and Edge each publish them in their help centres.
- Sign out. Signing out deletes your session cookie immediately.
- Do Not Track and Global Privacy Control. We set no cookies that these signals are designed to stop, so nothing changes when they are on. We treat a Global Privacy Control signal as an opt-out request wherever the law gives it that effect.
7.Changes
We may update this notice when the Sites change. The version and effective date are at the top of the page. See the Privacy Policy for how we handle personal information more generally.
8.Contact
- Email: support@canvasugcmp.com
- Mail: Aethos Solutions LLC, 3680 Wilshire Blvd, Ste P04-1212, Los Angeles, CA 90010, United States