Skip to content

Legal

Cookie policy

Cookie policy

Last updated: July 31, 2026

We use the minimum set of cookies to make sign-in work and to remember display preferences. No advertising cookies, no cross-site tracking, no behavioural-analytics SDK.

What we set

Cookie Purpose Lifetime Type
better-auth.session-token Authentication — keeps you signed in across page loads. HttpOnly, Secure on HTTPS, SameSite=Lax. 7 days, rolling Strictly necessary
Theme cookie — pl-theme (Placet), cv-theme (Cordon), sl-theme (Sluice), dh-theme (Duehatch), gw-theme (Gangway) Remembers your dark / light / auto theme choice. JS-readable so the bootstrap script in app.html can avoid a flash on page load. SameSite=Lax. 1 year Functional
gw-ref (Gangway) Remembers which referral link brought you here, so the referrer can be credited if you sign up. Set only when you arrive via a ?ref= link; contains the referral code, nothing about you. HttpOnly, SameSite=Lax. 60 days Functional
Paddle checkout / customer portal cookies Set by Paddle on its checkout overlay and customer-portal pages — our Merchant of Record — not by us. Governed by Paddle's cookie policy. Per Paddle Strictly necessary (only during checkout / portal)

We do not set cookies for: advertising, retargeting, behavioural profiling, A/B testing, or analytics tied to individual users.

Other storage on your device

Cookies aren't the only thing a browser stores, so for completeness — we also use localStorage in two places, and neither is shared with anyone:

Key Purpose Where
pl-theme, cv-theme, sl-theme, dh-theme, gw-theme The same theme choice as the cookie above, mirrored so the page can apply it before it renders All products
af:email:<board> The email you typed into an approval room, remembered per board so you don't retype it when you come back Placet client portals

Clearing site data in your browser removes both. Neither is readable by any other site, and nothing is sent to a third party.

Why no cookie banner

The session cookie is required to deliver the service you asked for, and the theme cookie is one you set yourself by using the theme switcher. Neither needs an opt-in banner, and we have no third-party, advertising or cross-site tracking cookies at all.

One cookie doesn't fit that description and we'd rather name it than round it up: gw-ref. Following a referral link is what sets it — you didn't ask for it, and crediting a referrer isn't necessary to deliver anything to you. What it holds is the referral code from the link and nothing about you; it is first-party and HttpOnly, is read once when a workspace is created, and is never used to profile, target or track you across sites. Refusing or clearing it costs you nothing — the product behaves identically, and only the person who referred you loses the credit.

If we ever add analytics or advertising, this policy and a banner land together.

How to disable

Browser settings — every major browser supports rejecting cookies per site. If you disable the session cookie you can't sign in. The theme cookie is optional and the site falls back to your system preference.

Contact

privacy@porthatch.app for cookie-related questions.