Back to PermitCore

Cookie Policy

Last updated: August 28, 2026

What Are Cookies?

Cookies are small text files placed on your device by websites you visit. They are widely used to make websites work, to improve efficiency, and to provide information to website owners. PermitCore uses a minimal set of cookies strictly necessary to operate the service.

Your Cookie Choices

When you first visit permitcore.dev, a cookie banner lets you accept all optional cookies, reject them, or choose per category (Strictly Necessary / Analytics — see the table below). Once you've made a choice, a small cookie icon stays in the bottom-left corner of every page so you can change your mind at any time — you can also reach the same preferences via Cookie Settings in the footer.

Cookies We Use

Name Purpose Type Duration
ExternalCookie Temporary sign-in handshake for "Continue with Google/Microsoft/GitHub/GitLab/Okta" (HttpOnly) Strictly Necessary 10 minutes
sso_state CSRF protection during tenant single sign-on login (HttpOnly) Strictly Necessary 10 minutes
__stripe_* Stripe fraud detection during checkout (set by Stripe) Strictly Necessary Session
_ga, _ga_* Google Analytics (GA4) — aggregate, pseudonymous site usage (pages viewed, referrer, approximate location, device type). Only loaded if you accept the Analytics category below. Analytics — requires consent Up to 14 months

What We Don't Use

PermitCore does not use:

  • Advertising or targeting cookies
  • Cross-site tracking cookies
  • Social media tracking pixels

Local Storage (not a cookie, disclosed for completeness)

PermitCore also uses the browser's localStorage, which is not a cookie and is not affected by your browser's cookie settings: your cookie preference choice itself (permit_cookie_consent), a long-lived sign-in token in the admin panel (the short-lived access token itself is kept only in page memory, never in storage), and your shopping cart on the License Store (permit_cart_{store-slug}). This data never leaves your browser except as part of API requests to PermitCore servers, and you can clear it at any time by clearing your browser's local storage for the PermitCore domain — note that clearing it also resets your cookie preference, so the banner will reappear.

Managing Cookies

Strictly necessary cookies cannot be disabled without breaking core service functionality. You can manage optional categories any time via Cookie Settings, or block/delete cookies entirely through your browser settings. Note that blocking strictly necessary cookies may prevent you from signing in or completing purchases.

Browser cookie management guides: Chrome · Firefox · Safari

Contact

Questions about our cookie use: [email protected]