Skip to content

Legal

Cookie Policy

The cookies we use, why each one is needed, and how you can control them.

Last updated: 29 September 2026

1. The short version

Without your permission, our public website sets no cookies, and signing in to Primemgr sets only the ones needed to keep you signed in and secure. We ask once whether you allow analytics cookies (PostHog), which show us how the site and the product are used; nothing is set for analytics unless you say yes, and you can change your answer below at any time. We do not use advertising cookies, and we do not let anyone else track you on our site.

2. What a cookie is

A cookie is a small text file a website stores in your browser so it can recognise your browser on the next request. The same rules apply to similar technology, such as local storage; we use those only for your cookie choice and, if you allow them, analytics.

3. The cookies we always set

All of these are strictly necessary. None of them is used to follow you around the web.

CookieWhen it is setWhat it doesHow long it lasts
authjs.session-token (__Secure-authjs.session-token on our live site)When you sign inKeeps you signed in, so each page knows which account and workspace you are using.Until you sign out, or 30 days without use
authjs.csrf-token (__Host-authjs.csrf-token on our live site)When you open a sign-in formProtects sign-in forms against cross-site request forgery.Until you close the browser
authjs.callback-url (__Secure-authjs.callback-url on our live site)When you sign inReturns you to the page you were on after signing in.Until you close the browser
authjs.pkce.code_verifier and authjs.stateOnly when you choose "Sign in with Google"Secures the sign-in exchange with Google.15 minutes
__Host-admin-sessionOnly for our own staff signing in to the operations consoleKeeps a staff member signed in to the admin area.8 hours or sign-out

4. Analytics cookies (only if you allow them)

If you choose Allow, we use PostHog, a product analytics service (United States), to count page views and see which features are used, so we can fix what confuses people. PostHog then stores ph_…_posthog (a cookie) and a matching entry in local storage, holding a random identifier for this browser, for up to a year; when you are signed in it is linked to your account by an internal number, never your name or email. On our public pages and while signing up we may also record how pages are used (clicks and scrolling, with anything typed hidden). We never record inside the product’s screens, and we never run analytics on the pages a business’s own customers open, such as a quote, an invoice, a booking or the customer portal. Your choice itself is kept in your browser’s local storage as pm-analytics-consent.

5. Paddle, our payment provider

When you open the checkout to buy or change a plan, it is provided by Paddle, our reseller and merchant of record, and it runs Paddle’s own code. Paddle may set cookies of its own inside that checkout to take the payment securely and prevent fraud. Those are controlled by Paddle and described in its privacy notice. The checkout only loads when you choose to open it.

6. Controlling cookies

You can block or delete cookies in your browser settings. If you block the cookies above, you can still read our website, but you will not be able to sign in, because signing in depends on them.

7. If this changes

If we add another cookie that is not strictly necessary, we will list it here first and, where the law requires, ask for your consent before it is set. See also our Privacy Policy.

8. Contact

Questions about cookies: admin@primemgr.com.

Other policies