Legal · Version 2026-09-01
Cookie Policy
Promotlr currently uses first-party cookies and browser storage only for requested authentication, security, account switching, drafts, and interface preferences.
- Effective date
- September 1, 2026
- Legal contact
- support@promotlr.com
1. Scope
Cookies are small values stored by a browser and sent with later requests. Local storage stays in the browser and is not automatically sent with each request. This policy covers both technologies on Promotlr. The Privacy Policy explains the related processing of identifiers and device information.
2. Cookies currently used
| Name | Purpose | Lifetime | Classification |
|---|---|---|---|
promotlr_session | Authenticates the currently active account and prevents unauthorized access. | A browser-session cookie by default, backed by a server session that expires after 12 hours. Selecting “Remember for 30 days” makes both persist for up to 30 days. Removed earlier on sign-out, revocation, or deletion. | Strictly necessary |
promotlr_admin_session | Keeps an authorized staff session separate from an impersonated or customer session. | A browser-session cookie by default, with the same 12-hour server limit. It persists for up to 30 days only when the staff user selects “Remember for 30 days”. | Strictly necessary for staff security |
promotlr_remembered_sessions | Supports the signed-in account switcher after the user selects “Remember for 30 days”, without exposing raw session records to page scripts. | Set only for remembered sign-ins; up to 30 days. An entry stops working when its underlying server session expires and is pruned during later session-management actions. Cleared when remembered sessions are revoked. | Strictly necessary for the explicitly requested account-switching feature |
promotlr_google_oauth_state | Prevents OAuth request forgery and preserves the selected plan, referral URL parameter, remember preference, and displayed legal-document versions during Google authentication. | 10 minutes or until the callback completes. | Strictly necessary when Google sign-in is requested |
All listed cookies are first-party, HTTP-only cookies with a SameSite restriction and are sent securely over HTTPS in production. Promotlr does not currently set advertising, cross-site tracking, audience measurement, or affiliate-attribution cookies. Referral links pass the referral code directly to the signup URL instead of storing a 90-day referral cookie.
3. Local storage currently used
promotlr:campaign-name-draft:…preserves an unsaved campaign-name edit for the automation the user is editing and is removed after save or discard.promotlr_recent_support_emojisremembers recently selected support-chat emoji choices on that browser.promotlr:text-editor:saved-colorsremembers text-editor colors selected by the user.promotlr:onboarding-trial-modal-seen:…remembers that a signed-in user dismissed the onboarding or trial notice.
These values provide an interface state, draft, or preference explicitly requested through the product. They are not used to follow users across websites or build advertising profiles. They normally remain until the related action removes them or the user clears site data.
4. Why no consent banner is currently shown
Promotlr’s current browser storage is limited to storage necessary to provide authentication, security, and user-requested features such as remembered account switching, drafts, and interface preferences. Where applicable law exempts storage that is strictly necessary for a service expressly requested by the user, Promotlr relies on that exemption rather than consent. This conclusion does not extend to analytics, advertising, affiliate tracking, or optional personalization.
Promotlr must obtain any legally required consent before adding non-essential browser storage. A future optional category must have a genuine reject path, remain off before consent, and be documented here with its provider, purpose, and lifetime.
5. Browser controls
You can delete cookies and local storage in browser settings. Blocking an authentication or OAuth cookie will prevent the associated sign-in function. Clearing draft or preference storage removes only the locally remembered interface state. Signing out through Promotlr is the safest way to revoke the server-side session as well as clear the active cookie.
6. Changes
Promotlr will update the version and effective date when storage practices materially change. If a new technology requires consent, it will not be enabled for that user until the required choice has been provided.