Last updated: 24 September 2026
This policy explains the cookies and similar technologies used on https://verbier.dev and its subdomains, including clerk.verbier.dev, which runs our sign-in service. It is provided by Fortis Ventures Ltd ("we", "us" or "Verbier"). Our Privacy Policy at /privacy explains how we handle personal data more generally.
1. What cookies and similar technologies are
1.1 A cookie is a small text file that a website stores in your browser. Your browser sends it back to that website on later requests, so the site can recognise your browser, for example to keep you signed in.
1.2 Similar technologies work in a comparable way. They include local storage and session storage, which let a website keep data in your browser, and techniques that read information from your device. In this policy, "cookies" includes these technologies unless we say otherwise.
1.3 Cookies can be:
(a) first-party, set by the site you are visiting, or third-party, set by another domain;
(b) session cookies, deleted when you close your browser; or
(c) persistent cookies, which stay until they expire or you delete them.
2. The law, and why we do not ask for consent
2.1 The Privacy and Electronic Communications (EC Directive) Regulations 2003 ("PECR") control the use of cookies. Under regulation 6(1) of PECR, a website may not store or access information on your device unless an exception in Schedule A1 to PECR applies.
2.2 Paragraph 4 of Schedule A1 contains the "strictly necessary" exception. It applies where storage or access is strictly necessary to provide an online service you have asked for, including where it is strictly necessary:
(a) to ensure the security of your device or of the service;
(b) to prevent or detect fraud; or
(c) to authenticate you automatically.
Before 5 February 2026, this exception was in regulation 6(4) of PECR.
2.3 Every cookie and similar technology we use falls within that exception (section 3). We do not use analytics, advertising, social media or other tracking cookies. So we do not need your consent, and we do not show a cookie consent banner. We still explain here what each cookie does.
3. Cookies we use
3.1 The table below lists every cookie used on our website. All of them are strictly necessary.
| Name | Provider | Set on | Purpose | Duration | Category |
|---|---|---|---|---|---|
__session and __session_<suffix> |
Clerk | .verbier.dev | Holds a short-lived signed token showing that you are signed in, so that the dashboard and our servers can confirm who you are on each request. Set only while you are signed in. The version with a suffix does the same job for our particular Clerk instance | About 60 seconds; renewed automatically while you are signed in | Strictly necessary (authentication) |
__client |
Clerk | .clerk.verbier.dev | Identifies your browser's sign-in "client" to Clerk, which uses it to issue the short-lived __session token. Scripts cannot read it (HttpOnly) |
400 days | Strictly necessary (authentication) |
__client_uat and __client_uat_<suffix> (for example __client_uat_-fpc9KDX) |
Clerk | .verbier.dev | Records when your browser last signed in or out ("uat" means "updated at"), so that Clerk can check whether your session is still valid. It is set even when you are not signed in. The version with a suffix does the same job for our particular Clerk instance | 400 days | Strictly necessary (authentication) |
__cf_bm |
Cloudflare, on behalf of Clerk | .clerk.verbier.dev | Bot management: helps tell people apart from automated bots on our sign-in service | Expires after 30 minutes of inactivity | Strictly necessary (security) |
_cfuvid |
Cloudflare, on behalf of Clerk | .clerk.verbier.dev | Rate limiting: lets Cloudflare tell apart different visitors who share the same IP address | Session (deleted when you close your browser) | Strictly necessary (security) |
__stripe_mid |
Stripe | verbier.dev, on the checkout page only | Fraud prevention: helps Stripe assess the risk of an attempted payment | 1 year | Strictly necessary (fraud prevention) |
__stripe_sid |
Stripe | verbier.dev, on the checkout page only | Fraud prevention: helps Stripe assess the risk of an attempted payment | 30 minutes | Strictly necessary (fraud prevention) |
3.2 Clerk provides our sign-in, account and billing service. Cloudflare protects Clerk's service. Stripe processes card payments. We checked the cookies our website sets for signed-out visitors on 24 September 2026. The __session cookies are set only while you are signed in, and the Stripe cookies only on the checkout page. Their details come from Clerk's and Stripe's documentation.
3.3 The durations for __client, __client_uat and _cfuvid are those we observed; your browser may shorten them. During sign-in, Clerk may also set short-lived internal cookies (such as __clerk_handshake) for the same authentication purpose, which are deleted within minutes.
4. Local storage and other similar technologies
4.1 We use one local storage item:
| Name | Provider | Purpose | Duration | Category |
|---|---|---|---|---|
__clerk_environment |
Clerk | Holds a copy of our sign-in configuration, so that Clerk's sign-in and account components can load it without fetching it every time | Stays until Clerk replaces it or you clear your browser's data for our site | Strictly necessary |
4.2 On the checkout page, Stripe's payment form also gathers information about your device and browser, and may use storage in its own frame (on Stripe's domains), to detect and prevent payment fraud. This falls within the fraud-prevention part of the strictly necessary exception. Apart from that and the items described above, we do not use tracking pixels or any other similar technology.
5. Third-party content on our documentation page
5.1 Our API reference at /docs uses a documentation viewer:
(a) jsDelivr (operated by Volentio JSD Limited) serves the viewer's script from cdn.jsdelivr.net; and
(b) Scalar (API Documentation Inc.) serves the viewer's fonts from fonts.scalar.com.
5.2 When you open /docs, your browser fetches these files directly from those providers, and they receive your IP address and standard browser information. Neither of them set any cookies in our check, and jsDelivr's privacy policy says its services do not use cookies. For how they handle your data, see section 7.4 of our Privacy Policy at /privacy.
5.3 No other page on our website loads content from third parties apart from Clerk's sign-in service and Stripe's checkout form, described above.
6. How to control cookies
6.1 You can use your browser's settings to see, block and delete cookies and local storage, for all sites or just for ours. Your browser's help pages explain how.
6.2 Because all the cookies we use are strictly necessary, blocking them will stop parts of the Service working:
(a) if you block Clerk's cookies, or Cloudflare's cookies on clerk.verbier.dev, you will not be able to sign up, sign in or use the dashboard, including creating API keys and managing your plan; and
(b) if you block Stripe's cookies, checkout may not work, and you may not be able to buy or change a paid plan.
6.3 Blocking cookies should not stop you reading our website or documentation. The API does not use cookies: it authenticates requests with your API key.
7. Changes to this policy
7.1 We will update this policy if we change the cookies or similar technologies we use, and publish the new version at /cookies with a new "Last updated" date.
7.2 If we ever want to use cookies that are not strictly necessary, such as analytics cookies, we will update this policy first. We will also ask for your consent where the law requires it.
8. Contact
Questions about this policy: hello@verbier.dev. Fortis Ventures Ltd, C/O Aardvark Accounting, 1 Cedar Office Park, Cobham Road, Wimborne, BH21 7SB, United Kingdom.