Cookie Policy
TL;DR: We use essential cookies only. No advertising trackers. No third-party analytics that fingerprint you. If we ever add optional cookies, we’ll show you a proper banner and let you opt out.
What cookies we set
Essential (no consent required under GDPR Art 5(3) / PECR Reg 6)
callora_session— authenticates your dashboard session. Signed, HttpOnly, Secure, SameSite=Lax. Expires 30 days.callora_admin— authenticates admin dashboard sessions. Signed HMAC-SHA256, HttpOnly, Secure, SameSite=Strict. Expires 24 hours.callora_oauth_state— anti-CSRF token for OAuth flows. Short-lived (5 minutes).NEXT_LOCALE— remembers your language preference. No PII.
Optional (require consent when enabled)
None currently active. If we add product analytics, error tracking, or A/B testing that qualifies as non-essential, we will present a consent banner and log your choice.
Do Not Track
We honour “Do Not Track” signals — no non-essential cookies are set when your browser sends DNT=1.
Third parties
Stripe Checkout, when you make a purchase, sets its own cookies on checkout.stripe.com. See Stripe’s privacy policy. Google, when you sign in with Google, sets its own cookies on accounts.google.com. We do not embed advertising or social-media tracking pixels.
Managing cookies
You can clear or block cookies via your browser settings. Blocking essential cookies will prevent sign-in and dashboard access.