Legal
Cookie policy
Draft — pending legal review; not legal advice.
This page describes how the platform works today. It has not yet been approved by counsel, and bracketed items such as [Company legal name] are placeholders the operator still has to fill in. Last updated .
1.In short
We use one cookie to keep you signed in and, only when you follow a partner’s tracking link, two cookies that help credit the right partner for a sale. We do not use advertising cookies, and the site loads no third-party analytics or tracking scripts — its security policy only allows content from our own domain.
3.Other browser storage
- Selected organisation (
spm_org, session storage): if your login belongs to more than one organisation, remembers which one you are working in. Cleared when you close the tab. - Your access token is kept only in the page’s memory, never in cookies or storage, and disappears when you close the page.
4.Why attribution cookies are used
When you follow a partner’s link, the redirect records the click (with a keyed hash of your IP address and browser, not the raw values) and forwards you to the vendor’s website with a click id in the address. The vendor sends that id back when you pay, and our servers check it against the click log. The cookies above are a fallback for when the id cannot be passed along.
They are used only to decide which partner, if any, earns a commission on a purchase you make from the vendor. Whether this processing requires your consent, and how consent is collected, is [to be confirmed by counsel].
5.Your choices
You can block or delete cookies in your browser settings. If you block spm_refresh you will need to sign in again on each visit. Blocking the attribution cookies does not stop you buying software; it may mean a partner who referred you is not credited.
6.Changes and contact
We will update this page when the cookies we use change; the date at the top shows the latest version. Questions: contact us or write to [privacy contact email].