# Cookie Policy

Last updated: 19 May 2026

Impactean is unusual among SaaS products: we run no third-party analytics, marketing, or session-replay cookies. The only cookies we set are strictly-necessary cookies that keep you signed in. This page is short by design.

## What we set

| Cookie | Set by | Purpose | Duration | Necessary? |
|---|---|---|---|---|
| sb-vqlqmscprojpkfkszabh-auth-token | Impactean (via Supabase Auth) | Keeps you signed in to app.impactean.com | Refresh-rotated; expires 7 days after last activity | Yes |
| sb-vqlqmscprojpkfkszabh-auth-token-code-verifier | Impactean (via Supabase Auth) | OAuth/PKCE flow for password reset and magic link | Single-use, ~5 minutes | Yes |
| Stripe Checkout cookies | Stripe (only on /checkout while you pay) | Fraud prevention during payment | Per Stripe's policy | Yes for the duration of payment |

All cookies above are HttpOnly, Secure, and SameSite=Lax. Strictly-necessary cookies do not require consent under EU ePrivacy and the German TTDSG.

## Hosted Impactean web surfaces (tracker posture)

| Host surface | Behavioural advertising / invasive cross‑site analytics scripts |
|---|---|
| `www.impactean.com` *(marketing)* | No third‑party trackers intentionally shipped from our repository builds. |
| `app.impactean.com` *(product SPA)* | No third‑party trackers; strictly necessary authentication cookies enumerated above. |
| `*.impactean.com` Impactean‑operated editorial blog instances | Intended **parity** upon theme merges—promptly report regressions via privacy@impactean.com. |

## What we do NOT set

- No Google Analytics, Google Tag Manager, or Google Ads cookies.
- No Meta (Facebook) Pixel.
- No Mixpanel, PostHog, Segment, Heap, Amplitude, FullStory, Hotjar, Clarity, or LogRocket.
- No advertising or behavioural-tracking cookies.

If we ever introduce optional analytics, we will deploy a category-based consent banner and load nothing non-essential before you opt in.

## Managing cookies

You can clear or block cookies in your browser settings. Blocking strictly-necessary cookies will sign you out and prevent you from using app.impactean.com.

## Local storage (marketing site only)

| Key | Set by | Purpose | Duration |
|---|---|---|---|
| impactean_cookie_consent | impactean.com | Remembers your cookie-banner choice | 365 days |

This is not an advertising cookie. It does not track you across other websites.

## Contact

privacy@impactean.com
