Legal
Cookie Policy
Last updated September 7, 2026
How Toplodr uses cookies
Toplodr sets a small number of first-party cookies so the product works: sign-in, social sign-in, and catalog language. The session cookie is named tcg_session on this deployment (the default name is toplodr_session). We do not set advertising cookies, and we do not load Google Analytics, ads, or other third-party tracking scripts.
Strictly necessary cookies run when you use the matching feature (for example, signing in). We do not wait for a banner before creating a session. Optional analytics or marketing cookies are not used, so there is nothing extra to opt into today. The notice on the site explains this and links here. See also the Privacy Policy.
Cookies we set
| Name | Type | Purpose | Duration | Need |
|---|---|---|---|---|
| tcg_session | First-party cookie, httpOnly | Keeps you signed in. The token is looked up in our database; the cookie is not readable by page scripts. | About 30 days of activity | Strictly necessary to stay logged in |
| toplodr_oauth_state | First-party cookie, httpOnly | Protects Google and Discord sign-in (CSRF / return-path) and is cleared after the callback. | 10 minutes | Strictly necessary for social sign-in |
| toplodr_lang | First-party cookie | Remembers the catalog language you selected (English, Japanese, Traditional or Simplified Chinese). | 1 year | Functional — set when you choose a language |
| toplodr_cookie_ack | First-party cookie | Remembers that you dismissed the cookie notice so it does not appear on every visit. | 1 year | Functional — set only after you acknowledge the notice |
Similar storage in this browser
These are not cookies. They stay on your device so guest binders, recent searches, and list preferences survive a refresh. Signed-in collection and watchlist are stored on our servers and mirrored locally while you use the site.
| Key | Purpose |
|---|---|
| toplodr-collection | Guest collection quantities in this browser until you sign in and sync. |
| toplodr-watchlist | Guest watchlist card ids in this browser until you sign in and sync. |
| toplodr-search-history | Recent searches for the sidebar. |
| toplodr-card-list-prefs | Sort, language filter, and layout for card lists. |
| toplodr-admin-sets-filters | Admin catalog filter preferences (staff only). |
| toplodr-cookie-notice | Same acknowledgment as the cookie notice, stored locally so the banner does not flash on reload. |
Cookies we do not set
Page scripts do not load analytics, advertising, or social pixels. Fonts are self-hosted by the app. Choosing Google or Discord sign-in sends you to those providers; they may set their own cookies on their domains. That is their processing, not a Toplodr tracking pixel.
If toplodr.com is served through a CDN or bot-protection layer, that provider may set its own strictly necessary cookies (for example Cloudflare security cookies). Those are not set by Toplodr application code.
How to control cookies
You can delete cookies and site data in your browser settings. Doing that signs you out, forgets catalog language, and removes guest collection data that has not been synced. Blocking all cookies will prevent sign-in from working.
If we later add analytics or advertising, we will update this page and use a real consent tool before those optional cookies run.