Last updated: 15 August 2026
This Cookie Policy explains how AMP Academy uses cookies and similar technologies to recognize you when you visit our platform, remember your preferences, and provide a secure learning environment.
This Cookie Policy ("the Cookie Policy") explains how AMP Academy Private Limited ("the Company," "we," "us," or "our") uses cookies, local browser storage, web beacons, and similar tracking technologies when you visit or interact with the online pastry education platform located at amp-academy.com and artisanpastryacademy.com ("the Platform").
Cookies are small text files stored by your browser when you visit a website. We use cookies, session storage, and local storage to help you log in, navigate between pages, remember your language choice, and keep your account secure.
1.1. In this Cookie Policy, "Cookies" means small text files stored on your computer, tablet, mobile smartphone, or other web-enabled device when you access websites on the internet. "Session Storage" means a browser storage mechanism that maintains temporary data only while a browser tab remains open. "Local Storage" means client-side browser storage that retains key-value data persistently until explicitly cleared. "User" means any individual who interacts with the Platform.
1.2. First-party cookies are set directly by our Fastify API server and Next.js frontend application to enable secure authentication, session management, and interface language preferences.
1.3. Third-party cookies are placed by external technology partners for payment processing (PayPal, PayHere), edge security and video delivery (Cloudflare), and aggregated traffic telemetry (Google Analytics 4).
1.4. Session cookies expire automatically when you close your web browser, while persistent cookies remain on your device for a designated lifespan or until manually cleared.
We use strictly necessary cookies to make our platform work, preference cookies to remember your settings, analytics cookies to understand site performance, and security tokens to protect video streaming.
2.1. We classify our Cookies and storage tools into the following four functional categories:
Strictly necessary (essential) cookies: These cookies are required for core platform functionality and security. They authenticate user sessions through Better Auth, enforce role-based access permissions (Students, Chefs, and Administrators), protect forms against cross-site request forgery (CSRF) attacks, and maintain edge network defense via Cloudflare. The Platform cannot function without these cookies, so they cannot be disabled in platform settings.
Preference and functionality cookies: These cookies remember your choices and interface settings across browsing sessions. They store your selected interface language (NEXT_LOCALE for English or Sinhala), video player volume levels, and dashboard layout configurations.
Performance and analytics cookies: These cookies collect aggregated, pseudonymous data about how visitors navigate and interact with our Services. They record page load times, discovery paths, and technical errors, enabling us to optimize user interface responsiveness and improve curriculum structure.
Security and video streaming tokens: These short-lived tokens and cookies work in conjunction with Cloudflare Stream to deliver adaptive bitrate video streams. They authenticate your enrollment status, validate signed JSON Web Tokens (JWTs), and prevent unauthorized stream scraping or link sharing.
Here is a complete list of the cookies and storage technologies used across AMP Academy, who provides them, their purpose, and how long they stay on your device.
3.1. The following schedule details the active Cookies and storage identifiers deployed across the Platform:
Identifier | Provider | Category | Purpose | Duration |
|---|---|---|---|---|
| AMP Academy (First-party) | Essential | Authenticates active user sessions and validates role-based permissions across API requests | 30 days |
| AMP Academy (First-party) | Essential | Protects web forms, checkout flows, and API endpoints against cross-site request forgery attacks | Session |
| AMP Academy (First-party) | Preference | Stores the User's preferred interface language ( | 365 days |
| Cloudflare, Inc. (Third-party) | Essential / Security | Validates that a client has successfully passed Cloudflare security challenges and bot verifications | 365 days |
| Cloudflare, Inc. (Third-party) | Essential / Security | Distinguishes human traffic from automated bots to protect edge infrastructure against DDoS attacks | 30 minutes |
| Google LLC (Third-party) | Analytics | Distinguishes unique users to generate aggregated statistical reports on platform traffic | Two years |
| Google LLC (Third-party) | Analytics | Persists session state and interaction telemetry across page navigations in Google Analytics 4 | Two years |
| Cloudflare, Inc. (Third-party) | Analytics | Collects lightweight, privacy-friendly core web vitals and page performance metrics without tracking personal identities | Ephemeral / Session |
| Cloudflare Stream (Third-party) | Essential / Security | Validates signed JSON Web Tokens authorizing access to encrypted HLS video streams for paid lessons | Less than six hours |
| PayPal, Inc. (Third-party) | Functional / Payment | Maintains checkout session security and anti-fraud verification during USD payment transactions | Session / 30 days |
| PayHere (Private) Limited (Third-party) | Functional / Payment | Manages transaction session state and banking security parameters during LKR payment gateway checkouts | Session |
In addition to cookies, we use browser local storage for non-sensitive interface preferences like sidebar collapse state and video player volume. We never store passwords or banking details in local storage.
4.1. The Platform uses browser Local Storage and Session Storage managed through Zustand client state stores.
4.2. Local Storage is used strictly for non-sensitive interface settings, including:
Collapsible sidebar and navigation menu layout states.
Unsubmitted draft step progress within the course creation wizard.
Video player custom playback speed and volume preferences.
4.3. The Company does not store passwords, credit card numbers, bank account details, or sensitive cryptographic keys in browser Local Storage or Session Storage.
You can control and manage cookies through your browser settings. Keep in mind that blocking essential cookies will prevent you from logging in, making purchases, or streaming videos.
5.1. Most modern web browsers allow you to view, manage, delete, or block cookies through their settings menus.
5.2. You can manage cookie controls in major browsers by following their official configuration guides:
Google Chrome: Settings > Privacy and Security > Third-party cookies
Mozilla Firefox: Settings > Privacy & Security > Cookies and Site Data
Apple Safari: Preferences > Privacy > Manage Website Data
Microsoft Edge: Settings > Cookies and site permissions > Manage and delete cookies and site data
5.3. To opt out of Google Analytics measurement across all websites, you can install the official Google Analytics Opt-out Browser Add-on provided by Google LLC.
5.4. If you choose to block or delete strictly necessary Cookies, significant features of the Platform will become unavailable. Specifically, you will be unable to log in to your account, complete course purchases, access your student dashboard, or stream protected video lessons.
We respect Global Privacy Control signals where required by law.
6.1. Some web browsers transmit "Do Not Track" (DNT) or "Global Privacy Control" (GPC) signals to websites with which the browser communicates.
6.2. Because there is currently no universal industry standard for interpreting DNT signals, our systems do not alter their data collection practices upon receiving generic DNT headers.
6.3. We honor GPC signals where required by applicable data protection laws, treating such signals as a valid request to opt out of non-essential analytics and third-party data tracking.
We may update this cookie policy from time to time. If you have questions about how we use cookies, please contact us.
7.1. We may update this Cookie Policy periodically to reflect changes in technical infrastructure, cookie deployments, or legal standards.
7.2. When material changes are made, we will notify registered Users by email or by displaying a prominent notification banner on the Platform at least 14 days before revisions take effect.
7.3. If you have questions or concerns regarding our use of Cookies or this Cookie Policy, you may contact us by:
Email: [email protected]
Postal address:
AMP Academy Private Limited
420/1, Thalagala
Kiriwattuduwa
Sri Lanka