Cookie Policy
Last updated: September 2026
Cookie Policy
Last updated: September 2026
What cookies are
Cookies are small text files placed on your device when you visit a website. Cladior uses cookies and similar browser storage to keep your session active, remember your preferences, and operate the platform securely.
This page names every cookie we set. If it is not listed here, we did not set it.
Cookies we set
Strictly necessary
Required for the platform to function. They cannot be turned off, and under UK and EU rules they do not require your consent.
| Name | Purpose | Lifetime |
|---|---|---|
sb-a-<id> | Authenticates your account after sign-in. One per linked account, so signing into a second account does not sign you out of the first. httpOnly, Secure, SameSite=Lax. | Until expiry or sign-out |
cladior-active-id | Records which of your linked accounts is currently active. Changes only when you switch accounts. httpOnly. | Until expiry or sign-out |
www_sid | Identifies the browser session so you can see and revoke your own active devices from the dashboard. Alongside it we store the IP address, user agent and a derived device label for that session, which is what makes the device list readable. httpOnly, Secure, SameSite=Lax. | 30 days |
We do not set a CSRF token cookie. Requests that change something are POST only and our cookies are SameSite=Lax, which addresses the same risk without another cookie.
Referral
| Name | Purpose | Lifetime |
|---|---|---|
cldr_ref | Set only if you arrive through a referral link carrying a ?ref= code, so the person who referred you is credited if you later sign up. It holds that code and nothing else. httpOnly, Secure, SameSite=Lax. | 90 days |
This is the only cookie we set that is not strictly necessary. It is first party, it is not readable by JavaScript, it is never shared, and it is not used to build a profile of you or to target advertising. If you never follow a referral link, it is never set.
Browser storage, not cookies
cladior:themein localStorage stores whether you chose light or dark mode. It stays on your device and is only read to paint the correct theme before the page appears.
Analytics and advertising
Cladior runs no analytics scripts, no advertising pixels and no third-party trackers. Not Google Analytics, not a Meta pixel, not a session recorder, nothing of that kind. Aggregate usage is derived from our own server logs.
If that ever changes, we will ask for your consent before any such script runs, you will be able to refuse as easily as accept, and this page will be updated to name what was added. Nothing non-essential will load unless you have agreed to it.
Third-party cookies
Stripe sets two cookies, __stripe_mid and __stripe_sid, when a payment form is loaded. Unlike a hosted checkout on someone else's page, the Stripe payment form runs inside ours, so these are set on the Cladior domain. They exist for fraud detection and to tie a payment attempt together, they carry no advertising purpose, and they are governed by Stripe's own policies.
Flutterwave may still set cookies during payment for transactions that predate September 2026 or that are retried against it. Those are set on their hosted pages rather than ours.
Cloudflare may set operational cookies as part of edge delivery and bot protection. These are security and performance related and are not used for advertising or cross-site tracking.
Managing cookies
You can block or delete cookies in your browser settings, usually under Privacy or Security. Blocking strictly necessary cookies will stop sign-in from working, and clearing cookies will sign you out of Cladior. Clearing cldr_ref or cladior:theme costs you nothing except a referral credit and your theme choice.
Changes
We will update this page if we add, change or remove a cookie. The date at the top reflects the most recent revision.
Contact
Questions about cookies: privacy@cladior.com.