Cookie Policy
This Cookie Policy explains how the Smash&Clash game (the “Game,” “we,” “us”) uses cookies and similar on-device storage on the website at www.smashandclash.in, and how that differs in our Android, Windows, and embedded editions. It is a companion to our Privacy Policy and should be read alongside it. Smash&Clash is the official digital edition of the Smash&Clash strategic card-battle game, operated by Harshit Khemani.
1. What cookies & local storage are
A cookie is a small text file that a website asks your browser to store and send back on later visits. Cookies can be set by the site you are on (“first-party”) or by another company whose code runs on the page (“third-party”). They are commonly used to keep you signed in, remember preferences, or measure how a site is used.
Browsers (and our apps) also offer other on-device storage, most importantly localStorage and IndexedDB. Like cookies, these live on your device — but unlike cookies, their contents are not automatically sent to a server with every request. We use these heavily, precisely because the data can stay with you and never reach us. We refer to cookies, localStorage, IndexedDB, and similar technologies together as “cookies and similar storage” in this policy.
2. The core Game needs no non-essential cookies
Smash&Clash is built so that playing requires no sign-up and no tracking. The core experience — versus the AI opponent, the local hotseat two-player mode, the tutorial, and mutators mode — runs entirely on your device. None of it depends on cookies, and none of it loads any optional analytics. You can refuse every non-essential cookie and still play everything.
A handful of storage items are essential to make features work at all — for example, remembering your settings, or the sign-in cookies that keep you logged in if (and only if) you choose to sign in. Those are described below and are not gated behind the consent banner, because the Game would not function as you asked without them.
3. The categories we use
We group cookies and similar storage into three categories:
- Strictly necessary. Needed for a feature you actively use. The only cookies in this category are the Clerk sign-in cookies, and they are set only if you sign in. These are exempt from consent because you cannot use the feature (staying logged in) without them.
- Analytics — cookieless (no consent needed). Vercel Web Analytics counts aggregate traffic without setting any cookies and without identifying you or tracking you across other sites. Because it sets no cookies and is non-identifying, it runs on the production website without a consent prompt.
- Analytics — optional, consent-gated. Google Analytics 4 and Microsoft Clarity use cookies to help us understand usage and improve the Game. They load only after you click Accept in the consent banner, are web-only, and are never loaded in the native apps or inside the Whop, Discord, or ChatGPT embeds.
We do not use any advertising, marketing, or cross-site tracking cookies, and we do not sell or “share” your information for behavioural advertising. See the Privacy Policy for the full picture.
4. Cookies we may set (the full list)
The table below lists the cookies that may be set on the website. Whether each one appears depends on what you do: the Clerk cookies appear only if you sign in, and the Google Analytics and Microsoft Clarity cookies appear only after you accept analytics in the consent banner. Cookie names and lifetimes are set by the respective providers and may change over time — for current durations, see each provider’s own documentation (Google for Analytics, Microsoft for Clarity).
| Name / Provider | Purpose | Category | Consent-gated? | Lifetime |
|---|---|---|---|---|
| (no cookie) — Vercel Web Analytics | Aggregate, anonymous page-view and visitor counts; approximate referrer/region. Cookieless — no identifier is stored on your device, and you are not tracked across other sites. | Analytics (cookieless) | No — sets no cookies | n/a (no cookie) |
_ga — Google Analytics 4 (Google) |
Distinguishes site visitors (client/visitor identifier) for traffic measurement. | Analytics (optional) | Yes | ~2 years (set by Google) |
_ga_<id> — Google Analytics 4 (Google) |
Maintains per-property session state for GA4 measurement. | Analytics (optional) | Yes | ~2 years (set by Google) |
_gid — Google Analytics (Google) |
Short-lived visitor identifier used by some Google Analytics configurations. | Analytics (optional) | Yes | ~24 hours (set by Google) |
_clck — Microsoft Clarity (Microsoft) |
Persistent Clarity user identifier for heatmaps and session replay. | Analytics (optional) | Yes | Persistent — as set by Microsoft (see Microsoft’s documentation) |
_clsk — Microsoft Clarity (Microsoft) |
Clarity session identifier, linking page views within one session. | Analytics (optional) | Yes | Session — as set by Microsoft |
CLID — Microsoft Clarity (set via clarity.ms) |
Clarity cross-page identifier used to assemble heatmaps/replays. | Analytics (optional) | Yes | Persistent — as set by Microsoft |
ANONCHK — Microsoft |
Anonymised check used by Clarity/Microsoft; not used for advertising by us. | Analytics (optional) | Yes | Short-lived — as set by Microsoft |
MUID — Microsoft |
Microsoft unique identifier read by the Clarity tag. | Analytics (optional) | Yes | Persistent — as set by Microsoft |
__client — Clerk |
Clerk client/session handshake to keep you signed in. Only if you sign in. | Strictly necessary | No (essential) | Session / as set by Clerk |
__session — Clerk |
Clerk active session token for the signed-in session. Only if you sign in. | Strictly necessary | No (essential) | Session / as set by Clerk |
__clerk_* — Clerk |
Clerk authentication and session helper cookies. Only if you sign in. | Strictly necessary | No (essential) | Session / as set by Clerk |
The Clerk sign-in cookies are strictly necessary only while you are signed in; if you never sign in, none of them are set. The Google Analytics and Microsoft Clarity cookies are set by Google and Microsoft respectively as third parties, and their exact names and lifetimes are determined by those providers — see their privacy statements via the third-party services table in our Privacy Policy.
5. On-device storage (not cookies)
Much of what the Game remembers is kept in localStorage (and, for match records, IndexedDB) on your device. This data stays on your device and is not sent to us — it is not a cookie and is never transmitted with your web requests. We use it so the Game can work offline and so you keep control. Notable items include:
| Key | What it stores |
|---|---|
Settings & preferencessmashclash.volumes, smashclash.a11y.*, smashclash.ruleset, smashclash.inputHints.v, smashclash.cueSeen.v |
Audio & haptics on/off, accessibility options (upright numbers, reduced motion), ruleset choice, and which hints/cues you have already seen. |
Analytics consent choicesmashclash.consent.analytics |
Whether you accepted or declined Google Analytics + Microsoft Clarity in the banner. This is stored in localStorage, not a cookie. Clearing it makes the banner appear again. |
Local player identitysmashclash.pid, smashclash.name, smashclash.avatar |
Your stable on-device player id (a code like p-<base36>), your chosen/auto-generated display name, and your cosmetic avatar token. |
Profile / standings write tokensmashclash.profileToken |
A one-time secret token that proves you own your public profile and community standings, so only your device can update them. The secret stays on your device; our backend stores only a one-way (sha256) hash of it. |
Progress, friends & clubssmashclash.elo, smashclash.games, smashclash.friends, smashclash.myClubs, IndexedDB match records |
Your rating, games played, friends list, club memberships, and local match history (pruned to the newest 200) used to compute your rank locally. |
You can erase all of this at any time by clearing the Game’s site/app storage (or by uninstalling the app). For a fuller description of on-device data and your choices, see the On-device storage and Account & data deletion sections of the Privacy Policy.
6. How to accept or withdraw consent
When you first visit the production website, a consent banner asks whether you accept the optional analytics cookies (Google Analytics and Microsoft Clarity).
- To consent: click Accept in the banner. Only then are the Google Analytics and Microsoft Clarity tags loaded and their cookies set. Microsoft Clarity masks the content you type by default, and Google Analytics is configured to anonymise IP addresses.
- To decline: click Decline (or simply don’t accept). No optional analytics cookies are loaded, and you can still play everything — declining never limits the Game. The cookieless Vercel analytics and the strictly-necessary sign-in cookies are unaffected, as they don’t require consent.
-
To withdraw consent later (or change your mind): clear the Game’s
site storage in your browser (site settings → “Clear data” / cookies and
site data for the Game). This removes the stored consent choice
(
smashclash.consent.analytics) along with any analytics cookies, and the consent banner will appear again on your next visit so you can choose differently. Withdrawing consent is as easy as giving it.
You can also block or delete cookies in your browser settings at any time, and most browsers let you refuse third-party cookies or clear them automatically. Note that blocking the Clerk sign-in cookies will stop you from staying signed in. We recognise the Global Privacy Control (GPC) as a valid opt-out signal; because we do not sell or “share” your information for advertising, no further action is required to satisfy such a request.
7. Native apps & embeds
The Android (Google Play) and Windows app editions do not load Google Analytics or Microsoft Clarity at all — these web analytics simply do not apply to the native apps. When the Game runs embedded inside Whop, Discord, or ChatGPT, the consent banner and the optional web analytics are also skipped, and the host platform’s own cookie and privacy practices apply to that surface. In short: the consent-gated analytics cookies described above are a website-only matter.
8. Changes to this policy
We may update this Cookie Policy from time to time — for example, if a provider renames a cookie or we add or remove a tool. When we do, we will revise the “Last updated” date above and post the new version at this URL. This policy is governed by the laws of India and is designed to meet applicable global requirements (including the EU/UK ePrivacy and GDPR rules, the California CCPA/CPRA, and India’s DPDP Act 2023). It works together with our Privacy Policy.
9. Contact us
If you have any questions about cookies or this policy, contact our Founder:
Harshit Khemani
— Founder
Email:
support@smashandclash.in
Website:
www.smashandclash.in
This Cookie Policy covers the Smash&Clash website; the Android, Windows, and embedded editions are addressed where they differ. For everything else about how your information is handled, see our Privacy Policy. See also our Terms of Service and Code of Conduct.