Skip to content

Cookie Policy

Effective: January 1, 2026Last updated: September 6, 2026

1. What Are Cookies?

Cookies are small text files that websites place on your device when you visit them. They are widely used to make websites work efficiently, remember your preferences, and provide information to website owners.

Cookies can be first-party (set by the website you are visiting) or third-party (set by a different domain, typically for analytics or advertising purposes). Aclamia uses first-party cookies only for core functionality, plus the security cookies of Cloudflare and Google described below and a small amount of first-party local storage for optional analytics. We do not use third-party advertising cookies. ("Cookies" below is used loosely to cover both cookies and similar local-storage technologies.)

2. Cookies We Use

Aclamia uses four categories of cookies and similar technologies:

Strictly Necessary Technologies

These technologies are essential for the Service to function and cannot be disabled without affecting core features. Some are browser storage rather than cookies.

TechnologyPurposeStorageDuration
Firebase authentication stateKeeps you signed in. The web app does not issue an Aclamia session cookie; API requests carry a Firebase ID token in the Authorization header.Firebase-managed browser persistenceUntil sign-out or browser storage is cleared
Cookie consent preferenceRemembers whether you accepted or declined analyticsLocal storage (aclamia-cookie-consent)Until browser storage is cleared
Cloudflare security (__cf_bm and similar)Bot protection for the images and files we host, which are delivered through CloudflareCookie set by CloudflareUp to 30 minutes
Google reCAPTCHA Enterprise (Firebase App Check)Bot protection for sign-in and API access, where enabledCookie set by Google on its own domainsUp to 6 months

Our application is served from Google Cloud. The images and files we host are delivered through Cloudflare, which may set short-lived security cookies to distinguish humans from automated traffic; and where Firebase App Check is enabled, Google reCAPTCHA Enterprise sets its own cookie on Google's domains. Both are strictly necessary for protecting the Service, contain no profiling information, and are not used for advertising.

Functional Preferences and Referral Attribution

These technologies remember preferences or preserve a valid referral code while you complete registration. They are not used for advertising.

TechnologyPurposeStorageDuration
Locale routing (NEXT_LOCALE)Set by the site's internationalization layer so pages are served in the language you are browsingCookieSession — until you close your browser
Theme preferenceRemembers your light/dark mode choiceLocal storagePersistent
Referral attribution (app_ref)Preserves a valid ?ref= code so the referral can be attributed when you registerCookieUp to 90 days

Once you are signed in, the dashboard also keeps small interface-state entries in your browser's local or session storage — for example which of your businesses is selected, whether the sidebar is collapsed, the product tab you were on, and whether you dismissed a promotional banner. They contain no profiling information, are never shared for advertising, and disappear when you clear your browser storage.

Analytics

These technologies help us understand how users interact with the Service so we can improve it. Analytics is off by default and only runs after you accept it. Data is anonymized — we cannot identify individual users from it.

TechnologyProviderPurposeStorage
ph_* (PostHog)PostHogAggregate page views & feature usageBrowser local storage

PostHog runs in first-party mode and stores its data in your browser's local storage, not in cookies. Autocapture and session replay are disabled, and no personally identifiable information is included in events. PostHog only loads after you accept analytics; if you decline — or later withdraw consent via the Cookie Settings button — future analytics collection stops immediately. Data already stored in your browser is not automatically cleared; you can remove it through your browser's site-data controls, without affecting platform functionality.

Payment Processing Cookies

These cookies are set by Stripe, on Stripe's own domains, when you proceed to Stripe's secure hosted checkout or billing portal. No Stripe script runs on this website.

CookieProviderPurposeDuration
Stripe hosted checkout and billing portal cookiesStripeFraud prevention and payment security on Stripe's pagesSession / varies

Stripe cookies are set only when you proceed to Stripe's hosted checkout or billing portal — reached from the pricing page or from the billing and product pages of your dashboard. They are required for secure payment processing and fraud prevention.

3. How to Manage Cookies

You have several options for managing cookies:

Cookie Settings button. Click "Cookie Settings" in the footer of any page to reopen the cookie consent banner and update your preferences.

Browser settings. You can control cookies through your browser settings. Most browsers allow you to:

  • View and delete existing cookies.
  • Block cookies from specific websites.
  • Block third-party cookies.
  • Set up notifications when a cookie is placed.

Disabling strictly necessary technologies will break authentication and other core features. Disabling analytics will not affect your use of the platform.

For instructions on managing cookies in your specific browser, visit:

4. No Advertising or Behavioral Tracking

Aclamia does not use:

  • Advertising cookies or behavioral tracking cookies.
  • Cross-site tracking technologies.
  • Social media tracking pixels.
  • Data brokers or advertising networks.

Our analytics are strictly for product improvement, not for targeted advertising.

5. Changes to This Policy

We may update this Cookie Policy when we add, change, or remove cookies. The "Last updated" date at the top of this page reflects the most recent change. For material changes, we will notify active subscribers by email.

Questions? Contact us at aclamia.com/contact.