Legal
Cookie Policy
Last updated: 29 September 2026
1. The short version
Without your permission, our public website sets no cookies, and signing in to Primemgr sets only the ones needed to keep you signed in and secure. We ask once whether you allow analytics cookies (PostHog), which show us how the site and the product are used; nothing is set for analytics unless you say yes, and you can change your answer below at any time. We do not use advertising cookies, and we do not let anyone else track you on our site.
2. What a cookie is
A cookie is a small text file a website stores in your browser so it can recognise your browser on the next request. The same rules apply to similar technology, such as local storage; we use those only for your cookie choice and, if you allow them, analytics.
3. The cookies we always set
All of these are strictly necessary. None of them is used to follow you around the web.
| Cookie | When it is set | What it does | How long it lasts |
|---|---|---|---|
| authjs.session-token (__Secure-authjs.session-token on our live site) | When you sign in | Keeps you signed in, so each page knows which account and workspace you are using. | Until you sign out, or 30 days without use |
| authjs.csrf-token (__Host-authjs.csrf-token on our live site) | When you open a sign-in form | Protects sign-in forms against cross-site request forgery. | Until you close the browser |
| authjs.callback-url (__Secure-authjs.callback-url on our live site) | When you sign in | Returns you to the page you were on after signing in. | Until you close the browser |
| authjs.pkce.code_verifier and authjs.state | Only when you choose "Sign in with Google" | Secures the sign-in exchange with Google. | 15 minutes |
| __Host-admin-session | Only for our own staff signing in to the operations console | Keeps a staff member signed in to the admin area. | 8 hours or sign-out |
4. Analytics cookies (only if you allow them)
If you choose Allow, we use PostHog, a product analytics service (United States), to count page views and see which features are used, so we can fix what confuses people. PostHog then stores ph_…_posthog (a cookie) and a matching entry in local storage, holding a random identifier for this browser, for up to a year; when you are signed in it is linked to your account by an internal number, never your name or email. On our public pages and while signing up we may also record how pages are used (clicks and scrolling, with anything typed hidden). We never record inside the product’s screens, and we never run analytics on the pages a business’s own customers open, such as a quote, an invoice, a booking or the customer portal. Your choice itself is kept in your browser’s local storage as pm-analytics-consent.
5. Paddle, our payment provider
When you open the checkout to buy or change a plan, it is provided by Paddle, our reseller and merchant of record, and it runs Paddle’s own code. Paddle may set cookies of its own inside that checkout to take the payment securely and prevent fraud. Those are controlled by Paddle and described in its privacy notice. The checkout only loads when you choose to open it.
6. Controlling cookies
You can block or delete cookies in your browser settings. If you block the cookies above, you can still read our website, but you will not be able to sign in, because signing in depends on them.
7. If this changes
If we add another cookie that is not strictly necessary, we will list it here first and, where the law requires, ask for your consent before it is set. See also our Privacy Policy.
8. Contact
Questions about cookies: admin@primemgr.com.