Cookie Policy
Lux Edge, a Cozens Corp Company, an Indiana corporation
Effective date: [DATE] Last updated: [DATE]
1. About this policy
This Cookie Policy explains how Lux uses cookies and similar technologies on our own websites and web application (monetizelux.com, luxedge.io and their subdomains, including the seller and buyer dashboards), and the one cookie Lux sets on a seller's website through the Lux tag. It should be read together with our Privacy Policy.
How the seller tag actually works, stated precisely. Our seller customers (publishers) embed the Lux tag on their own websites to request real-time offer decisions for consumers who do not meet the seller's marketing-qualification criteria. The tag transmits seller-configured coarse attributes, a salted pseudonymized consumer identifier, and an impression identifier to Lux so that a slate of offers can be selected, displayed, and measured.
Lux sets a cookie in that context, and it is a third-party cookie, partitioned by top-level site — not a first-party integration of the seller's site. The distinction is deliberate and is the reason the control below matters: the cookie carries the Partitioned attribute (CHIPS), so the browser keys a separate, unrelated cookie jar for each site on which the tag appears. The same browser visiting two different sellers therefore yields two unrelated identifiers, and Lux cannot join them.
What follows from that: the tag does not perform cross-site behavioral tracking, does not build advertising profiles across unrelated websites, and cannot — partitioning removes the capability rather than merely prohibiting the practice. Cookies set by a seller's or buyer's own website, other than the Lux cookie described in §4, are governed by that party's own cookie policy.
2. What are cookies?
Cookies are small text files placed on your device when you visit a website. Similar technologies include pixels, tags, local storage, and software development kits. They can be “session” (deleted when you close your browser) or “persistent” (remain until they expire or are deleted), and “first-party” (set by us) or “third-party” (set by a partner).
3. Categories of cookies we use
-
Strictly necessary. Required for the site and application to function, including authentication, session management, load balancing, and security. These cannot be switched off in our systems.
-
Analytics / performance. Help us understand how the Services are used so we can improve them.
-
Functional. Remember your choices and preferences.
-
Marketing. Lux does not currently set marketing cookies on its own properties; if that changes, they will be set only with consent where required. The Lux tag on seller sites sets no marketing cookies.
4. Cookies we set
Verified against the implementation on 2026-08-11. Lux sets two cookies and no others; there is no analytics or advertising cookie on any Lux property.
| Name | Provider | Where it is set | Purpose | Category | Expiry |
|---|---|---|---|---|---|
lux_cid |
Lux | On a seller's site, by the Lux tag | Pseudonymous measurement identity: distinguishes repeat views so an offer is not shown too often, holds a consumer to a stable A/B measurement arm, and attributes a conversion to the decision that produced it | Strictly necessary for the measurement function; not advertising | 1 year (Max-Age=31536000, with an Expires fallback) |
ci_session |
Lux | On Lux's own dashboard | Authentication and session state for the Lux dashboard | Strictly necessary | Session |
4.1 lux_cid — attributes and what they are for
lux_cid is set with SameSite=None; Secure; Partitioned; HttpOnly; Path=/. Each attribute is load-bearing rather than boilerplate:
Partitioned(CHIPS) — the browser keys the cookie by top-level site, so the same browser on two different sellers produces two unrelated identifiers. This is what makes cross-site profiling impossible rather than merely prohibited.HttpOnly— script on the page cannot read the value, so a seller's other vendors cannot harvest it.SecureandSameSite=None— required for a partitioned cross-site cookie; it is transmitted only over HTTPS.Path=/— required by the partitioning mechanism.
The value is HMAC-signed (<identifier>.<signature>, checked with a constant-time comparison). A value that is absent, malformed, unsigned or forged is discarded and replaced. This is measurement integrity, not access control: without it a browser could select its own experiment arm or rotate its identity to defeat frequency capping. The cookie carries no personal information — it is an opaque identifier, and it is never joined to a name, email address or telephone number, none of which Lux holds for a consumer.
Where the cookie is blocked. Some browsers (notably Safari) block this cookie outright. In that case Lux derives a one-way, salted digest instead, and the seller's placement identifier is inside that digest — so the fallback path is isolated per seller in the same way the cookie path is isolated per site. No identifier spans sellers on either path.
One residual we disclose rather than smooth over: the cookie path partitions by top-level site and the fallback path by placement identifier. These are equivalent today because each seller has exactly one placement. If a seller takes a second placement the two paths diverge, and the governing decision record must be revisited before that happens.
5. Managing your preferences
Where required by law, we request your consent before setting non-essential cookies via our cookie banner / preference center. You can change your choices at any time via [PREFERENCE CENTER LINK]. You can also control cookies through your browser settings, and manage certain analytics/advertising cookies through industry opt-out tools. Blocking some cookies may affect how the Services work.
6. Do Not Track / Global Privacy Control
A Global Privacy Control (GPC) signal is expressed by the consumer's browser to the site they are visiting — the publisher's site, not Lux. Lux receives a server-to-server request for a contextual ad decision and does not see the browser's signal directly.
Where a publisher forwards a GPC signal to Lux, Lux honours it by suppressing targeted optimization for that request: the decision is made without personalised optimization, and the interaction is not used to train the model.
Status, stated plainly because this policy is published before the service carries live traffic: GPC suppression is implemented in code and awaits coordinated deployment and seller integration verification. Lux has served no live consumer traffic to date, so no consumer's signal has been received and disregarded.
Lux does not separately act on the legacy Do-Not-Track header, which has no consistent meaning across browsers; GPC is the signal Lux honours.
7. Changes and contact
We may update this policy from time to time. Questions: pcozens.inc@gmail.com.