Underground Platform — Cookie Policy
Status: pre-launch draft for legal review
Effective date: to be set before public beta
Last updated: 25 July 2026
This document is an operational draft. The final cookie inventory must be generated from the production applications before publication.
1. Scope
This policy explains how Underground Platform uses cookies, browser storage and similar technologies across its public website, Studio, Admin area and related services.
Privacy contact: privacy@undergroundplatform.com
General support: support@undergroundplatform.com
2. Categories
Strictly necessary
These technologies are required for authentication, session continuity, security, load balancing, fraud prevention and essential user-requested preferences. They cannot be disabled through a consent banner where they are technically necessary to provide the service.
Expected examples include:
- the `underground_session` authentication/session cookie;
- CSRF or equivalent request-integrity tokens where enabled;
- security, rate-limit and abuse-prevention identifiers;
- essential language, accessibility or interface preferences.
Functional
Functional storage remembers optional user choices that are not strictly necessary. It must be evaluated individually to determine whether consent is required.
Analytics
Non-essential analytics must remain disabled until the user gives valid consent. Underground's intended analytics model uses privacy-preserving daily aggregates and does not use cross-site tracking or user fingerprinting.
Advertising and profiling
Underground does not currently plan to deploy third-party behavioural advertising, cross-site profiling or tracking pixels. Any future introduction requires a policy update, prior consent and a fresh technical/legal assessment.
3. Consent rules
Before public beta, Underground must implement controls that:
- keep non-essential technologies disabled before consent;
- provide equally accessible accept and reject choices;
- allow granular choices where required;
- allow consent withdrawal as easily as consent was given;
- store auditable consent evidence without unnecessary identifiers;
- avoid manipulative interface patterns;
- request renewed consent when purposes or vendors materially change.
Strictly necessary technologies are used on the basis that they are required to deliver or secure the service requested by the user. Other technologies will use consent or another valid legal basis only where permitted by law.
4. Current pre-launch inventory
The production inventory is not final. Before publication, each application must be scanned and this section replaced or supplemented with a table containing:
| Name | Provider | Scope/domain | Purpose | Category | Duration | First/third party | Consent required |
|---|---|---|---|---|---|---|---|
| `underground_session` | Underground Platform | production application domains | Authenticated session | Strictly necessary | 30 days | First party | No, where technically necessary |
The inventory must also cover `localStorage`, `sessionStorage`, IndexedDB, SDK identifiers, embedded players, CDNs, monitoring tools and any third-party content.
Third-party cookies (playback providers)
| Provider | Domain | Purpose | Duration | Category |
|----------|--------|---------|----------|----------|
| YouTube / Google | youtube.com, google.com | Playback delivery, player functionality, abuse prevention | Varies by cookie | Functional / Third-party |
YouTube cookies are set only when the user initiates playback of a YouTube-sourced recording. No YouTube SDK or cookies are loaded on pages without active playback.
5. Third-party services
External links do not by themselves place third-party cookies through Underground. Embedded services must use an appropriate consent mechanism where required by applicable law. The current YouTube playback integration loads on user-initiated playback only.
The final processor and data-location register is maintained separately in `PROCESSOR_AND_DATA_LOCATION_REGISTER.md`.
6. Browser controls
Users may also delete or block cookies through their browser settings. Blocking strictly necessary storage may prevent authentication or other core functionality from working.
Platform consent controls, once implemented, will be the primary mechanism for managing non-essential technologies used directly by Underground.
7. Retention
Cookie and local-storage durations must be limited to what is necessary for their purpose. Consent evidence and server-side session records follow the applicable periods in `RETENTION_POLICY.md`.
Playback Providers
Underground Platform integrates external playback providers to deliver audio and video content associated with releases and recordings.
Provider architecture
The Platform uses a provider-agnostic playback architecture. Different playback providers may be integrated at different times depending on the implementation available for a given release.
Current implementation
The public beta uses YouTube (operated by Google Ireland Limited) as the active playback provider.
When YouTube playback is initiated, the YouTube IFrame Player API is loaded. This may cause Google to:
- set cookies on the `youtube.com` and `google.com` domains;
- process the user's IP address;
- collect technical information about the device and browser;
- associate playback activity with a Google account if the user is logged in to Google services.
This processing is governed by Google's own Privacy Policy:
User control
Users may:
- choose not to initiate playback (no provider SDK is loaded until playback is requested);
- manage Google cookies through their browser settings;
- manage their Google account activity at myactivity.google.com.
Future providers
The Platform may integrate additional or alternative playback providers in the future. Self-hosted audio delivery is architecturally supported and may become available. Each provider will be documented in this policy when activated.
8. Changes
This policy will be versioned and dated. The production cookie inventory must be reviewed whenever a new SDK, analytics service, embed, authentication mechanism, monitoring tool or advertising technology is introduced.
9. Contacts
Questions about cookies and privacy may be sent to privacy@undergroundplatform.com. Technical support requests may be sent to support@undergroundplatform.com.