Cookie Policy

Last updated: September 2026

Cookie Policy

Last updated: September 2026

What cookies are

Cookies are small text files placed on your device when you visit a website. Cladior uses cookies and similar browser storage to keep your session active, remember your preferences, and operate the platform securely.

This page names every cookie we set. If it is not listed here, we did not set it.

Cookies we set

Strictly necessary

Required for the platform to function. They cannot be turned off, and under UK and EU rules they do not require your consent.

NamePurposeLifetime
sb-a-<id>Authenticates your account after sign-in. One per linked account, so signing into a second account does not sign you out of the first. httpOnly, Secure, SameSite=Lax.Until expiry or sign-out
cladior-active-idRecords which of your linked accounts is currently active. Changes only when you switch accounts. httpOnly.Until expiry or sign-out
www_sidIdentifies the browser session so you can see and revoke your own active devices from the dashboard. Alongside it we store the IP address, user agent and a derived device label for that session, which is what makes the device list readable. httpOnly, Secure, SameSite=Lax.30 days

We do not set a CSRF token cookie. Requests that change something are POST only and our cookies are SameSite=Lax, which addresses the same risk without another cookie.

Referral

NamePurposeLifetime
cldr_refSet only if you arrive through a referral link carrying a ?ref= code, so the person who referred you is credited if you later sign up. It holds that code and nothing else. httpOnly, Secure, SameSite=Lax.90 days

This is the only cookie we set that is not strictly necessary. It is first party, it is not readable by JavaScript, it is never shared, and it is not used to build a profile of you or to target advertising. If you never follow a referral link, it is never set.

Browser storage, not cookies

  • cladior:theme in localStorage stores whether you chose light or dark mode. It stays on your device and is only read to paint the correct theme before the page appears.

Analytics and advertising

Cladior runs no analytics scripts, no advertising pixels and no third-party trackers. Not Google Analytics, not a Meta pixel, not a session recorder, nothing of that kind. Aggregate usage is derived from our own server logs.

If that ever changes, we will ask for your consent before any such script runs, you will be able to refuse as easily as accept, and this page will be updated to name what was added. Nothing non-essential will load unless you have agreed to it.

Third-party cookies

Stripe sets two cookies, __stripe_mid and __stripe_sid, when a payment form is loaded. Unlike a hosted checkout on someone else's page, the Stripe payment form runs inside ours, so these are set on the Cladior domain. They exist for fraud detection and to tie a payment attempt together, they carry no advertising purpose, and they are governed by Stripe's own policies.

Flutterwave may still set cookies during payment for transactions that predate September 2026 or that are retried against it. Those are set on their hosted pages rather than ours.

Cloudflare may set operational cookies as part of edge delivery and bot protection. These are security and performance related and are not used for advertising or cross-site tracking.

Managing cookies

You can block or delete cookies in your browser settings, usually under Privacy or Security. Blocking strictly necessary cookies will stop sign-in from working, and clearing cookies will sign you out of Cladior. Clearing cldr_ref or cladior:theme costs you nothing except a referral credit and your theme choice.

Changes

We will update this page if we add, change or remove a cookie. The date at the top reflects the most recent revision.

Contact

Questions about cookies: privacy@cladior.com.