Legal · Version 2026-09-01

Cookie Policy

Promotlr currently uses first-party cookies and browser storage only for requested authentication, security, account switching, drafts, and interface preferences.

Effective date
September 1, 2026

1. Scope

Cookies are small values stored by a browser and sent with later requests. Local storage stays in the browser and is not automatically sent with each request. This policy covers both technologies on Promotlr. The Privacy Policy explains the related processing of identifiers and device information.

2. Cookies currently used

NamePurposeLifetimeClassification
promotlr_sessionAuthenticates the currently active account and prevents unauthorized access.A browser-session cookie by default, backed by a server session that expires after 12 hours. Selecting “Remember for 30 days” makes both persist for up to 30 days. Removed earlier on sign-out, revocation, or deletion.Strictly necessary
promotlr_admin_sessionKeeps an authorized staff session separate from an impersonated or customer session.A browser-session cookie by default, with the same 12-hour server limit. It persists for up to 30 days only when the staff user selects “Remember for 30 days”.Strictly necessary for staff security
promotlr_remembered_sessionsSupports the signed-in account switcher after the user selects “Remember for 30 days”, without exposing raw session records to page scripts.Set only for remembered sign-ins; up to 30 days. An entry stops working when its underlying server session expires and is pruned during later session-management actions. Cleared when remembered sessions are revoked.Strictly necessary for the explicitly requested account-switching feature
promotlr_google_oauth_statePrevents OAuth request forgery and preserves the selected plan, referral URL parameter, remember preference, and displayed legal-document versions during Google authentication.10 minutes or until the callback completes.Strictly necessary when Google sign-in is requested

All listed cookies are first-party, HTTP-only cookies with a SameSite restriction and are sent securely over HTTPS in production. Promotlr does not currently set advertising, cross-site tracking, audience measurement, or affiliate-attribution cookies. Referral links pass the referral code directly to the signup URL instead of storing a 90-day referral cookie.

3. Local storage currently used

  • promotlr:campaign-name-draft:… preserves an unsaved campaign-name edit for the automation the user is editing and is removed after save or discard.
  • promotlr_recent_support_emojis remembers recently selected support-chat emoji choices on that browser.
  • promotlr:text-editor:saved-colors remembers text-editor colors selected by the user.
  • promotlr:onboarding-trial-modal-seen:… remembers that a signed-in user dismissed the onboarding or trial notice.

These values provide an interface state, draft, or preference explicitly requested through the product. They are not used to follow users across websites or build advertising profiles. They normally remain until the related action removes them or the user clears site data.

4. Why no consent banner is currently shown

Promotlr’s current browser storage is limited to storage necessary to provide authentication, security, and user-requested features such as remembered account switching, drafts, and interface preferences. Where applicable law exempts storage that is strictly necessary for a service expressly requested by the user, Promotlr relies on that exemption rather than consent. This conclusion does not extend to analytics, advertising, affiliate tracking, or optional personalization.

Promotlr must obtain any legally required consent before adding non-essential browser storage. A future optional category must have a genuine reject path, remain off before consent, and be documented here with its provider, purpose, and lifetime.

5. Browser controls

You can delete cookies and local storage in browser settings. Blocking an authentication or OAuth cookie will prevent the associated sign-in function. Clearing draft or preference storage removes only the locally remembered interface state. Signing out through Promotlr is the safest way to revoke the server-side session as well as clear the active cookie.

6. Changes

Promotlr will update the version and effective date when storage practices materially change. If a new technology requires consent, it will not be enabled for that user until the required choice has been provided.