Legal

Cookie Policy

Last updated: February 5, 2026

This Cookie Policy explains what cookies are, how GlobalLeadSuite uses them, and how you can control them from the in-app cookie banner or Settings → Data.

1. What are cookies?

Cookies are small text files placed on your device by websites you visit. They are widely used to make websites work — or work more efficiently — as well as to provide information to the owners of the site.

2. Categories we use

Essential (always on)

Required to run the Service. Cannot be disabled without breaking core functionality.

| Cookie | Purpose | Retention | |--------|---------|-----------| | session_token | Authenticated session (Emergent Auth). | 7 days | | glms_session | Anonymous audit trail for cookie-consent records. | 1 year | | glms_ref | Affiliate attribution on signup. | 30 days | | __cf_bm | Cloudflare Bot Management. | 30 min |

Analytics (opt-in)

Only set when you accept via the cookie banner. Currently not used in this build — reserved for a future product-analytics integration.

Marketing (opt-in)

Only set when you accept via the cookie banner. Currently not used in this build — reserved for future personalisation and campaign attribution.

3. Local storage (not cookies but similar)

For completeness, we also use localStorage for:

  • glms_lang — your language preference (EN/IT/ES/FR/DE)
  • glms_cookie_consent — your consent decision (mirrors the server audit record)
  • glms_session — a client-side flag to skip /auth/me probes on public pages
  • glms_lang_nudge_dismissed — remembers you dismissed the "switch to Italian" nudge

None of these hold personal data beyond your explicit UI choices.

4. How to control cookies

  • In-app banner: shown at first visit. Choose "Accept all", "Reject non-essential" or "Customize" to pick categories.
  • Change your mind later: go to Settings → Data → Cookie preferences to update.
  • Browser controls: most browsers let you clear or block cookies from Settings → Privacy. Note that clearing session_token will log you out.

5. Third-party cookies

Third-party services we integrate with may set their own cookies on their subdomains:

  • Stripe (checkout.stripe.com) — payment processing
  • Emergent Auth (auth.emergentagent.com) — Google sign-in flow
  • Cloudflare (__cf_bm, __cflb) — bot management + load balancing

We do not control these cookies directly. Please refer to each provider's cookie policy.

6. Changes

We update this policy whenever we add or remove a cookie. The "Last updated" date at the top reflects the latest revision.

7. Contact

privacy@globalleadsuite.example (placeholder)

This document is provided as an informational reference for the GlobalLeadSuite platform. It is not legal advice. For commercial deployment or specific jurisdictions, consult a qualified attorney in your country. Templates are provided in English only.