← Legal Center
pre-launch draft for legal review · Updated 25 July 2026

Underground Platform — Cookie Policy

Status: pre-launch draft for legal review

Effective date: to be set before public beta

Last updated: 25 July 2026

This document is an operational draft. The final cookie inventory must be generated from the production applications before publication.

1. Scope

This policy explains how Underground Platform uses cookies, browser storage and similar technologies across its public website, Studio, Admin area and related services.

Privacy contact: privacy@undergroundplatform.com

General support: support@undergroundplatform.com

2. Categories

Strictly necessary

These technologies are required for authentication, session continuity, security, load balancing, fraud prevention and essential user-requested preferences. They cannot be disabled through a consent banner where they are technically necessary to provide the service.

Expected examples include:

  • the `underground_session` authentication/session cookie;
  • CSRF or equivalent request-integrity tokens where enabled;
  • security, rate-limit and abuse-prevention identifiers;
  • essential language, accessibility or interface preferences.

Functional

Functional storage remembers optional user choices that are not strictly necessary. It must be evaluated individually to determine whether consent is required.

Analytics

Non-essential analytics must remain disabled until the user gives valid consent. Underground's intended analytics model uses privacy-preserving daily aggregates and does not use cross-site tracking or user fingerprinting.

Advertising and profiling

Underground does not currently plan to deploy third-party behavioural advertising, cross-site profiling or tracking pixels. Any future introduction requires a policy update, prior consent and a fresh technical/legal assessment.

3. Consent rules

Before public beta, Underground must implement controls that:

  • keep non-essential technologies disabled before consent;
  • provide equally accessible accept and reject choices;
  • allow granular choices where required;
  • allow consent withdrawal as easily as consent was given;
  • store auditable consent evidence without unnecessary identifiers;
  • avoid manipulative interface patterns;
  • request renewed consent when purposes or vendors materially change.

Strictly necessary technologies are used on the basis that they are required to deliver or secure the service requested by the user. Other technologies will use consent or another valid legal basis only where permitted by law.

4. Current pre-launch inventory

The production inventory is not final. Before publication, each application must be scanned and this section replaced or supplemented with a table containing:

| Name | Provider | Scope/domain | Purpose | Category | Duration | First/third party | Consent required |

|---|---|---|---|---|---|---|---|

| `underground_session` | Underground Platform | production application domains | Authenticated session | Strictly necessary | 30 days | First party | No, where technically necessary |

The inventory must also cover `localStorage`, `sessionStorage`, IndexedDB, SDK identifiers, embedded players, CDNs, monitoring tools and any third-party content.

Third-party cookies (playback providers)

| Provider | Domain | Purpose | Duration | Category |

|----------|--------|---------|----------|----------|

| YouTube / Google | youtube.com, google.com | Playback delivery, player functionality, abuse prevention | Varies by cookie | Functional / Third-party |

YouTube cookies are set only when the user initiates playback of a YouTube-sourced recording. No YouTube SDK or cookies are loaded on pages without active playback.

5. Third-party services

External links do not by themselves place third-party cookies through Underground. Embedded services must use an appropriate consent mechanism where required by applicable law. The current YouTube playback integration loads on user-initiated playback only.

The final processor and data-location register is maintained separately in `PROCESSOR_AND_DATA_LOCATION_REGISTER.md`.

6. Browser controls

Users may also delete or block cookies through their browser settings. Blocking strictly necessary storage may prevent authentication or other core functionality from working.

Platform consent controls, once implemented, will be the primary mechanism for managing non-essential technologies used directly by Underground.

7. Retention

Cookie and local-storage durations must be limited to what is necessary for their purpose. Consent evidence and server-side session records follow the applicable periods in `RETENTION_POLICY.md`.

Playback Providers

Underground Platform integrates external playback providers to deliver audio and video content associated with releases and recordings.

Provider architecture

The Platform uses a provider-agnostic playback architecture. Different playback providers may be integrated at different times depending on the implementation available for a given release.

Current implementation

The public beta uses YouTube (operated by Google Ireland Limited) as the active playback provider.

When YouTube playback is initiated, the YouTube IFrame Player API is loaded. This may cause Google to:

  • set cookies on the `youtube.com` and `google.com` domains;
  • process the user's IP address;
  • collect technical information about the device and browser;
  • associate playback activity with a Google account if the user is logged in to Google services.

This processing is governed by Google's own Privacy Policy:

User control

Users may:

  • choose not to initiate playback (no provider SDK is loaded until playback is requested);
  • manage Google cookies through their browser settings;
  • manage their Google account activity at myactivity.google.com.

Future providers

The Platform may integrate additional or alternative playback providers in the future. Self-hosted audio delivery is architecturally supported and may become available. Each provider will be documented in this policy when activated.

8. Changes

This policy will be versioned and dated. The production cookie inventory must be reviewed whenever a new SDK, analytics service, embed, authentication mechanism, monitoring tool or advertising technology is introduced.

9. Contacts

Questions about cookies and privacy may be sent to privacy@undergroundplatform.com. Technical support requests may be sent to support@undergroundplatform.com.

Underground DiscoveryPress play and enter the catalog.