Cookie Policy
Last updated: February 5, 2026
This Cookie Policy explains what cookies are, how GlobalLeadSuite uses them, and how you can control them from the in-app cookie banner or Settings → Data.
1. What are cookies?
Cookies are small text files placed on your device by websites you visit. They are widely used to make websites work — or work more efficiently — as well as to provide information to the owners of the site.
2. Categories we use
Essential (always on)
Required to run the Service. Cannot be disabled without breaking core functionality.
| Cookie | Purpose | Retention |
|--------|---------|-----------|
| session_token | Authenticated session (Emergent Auth). | 7 days |
| glms_session | Anonymous audit trail for cookie-consent records. | 1 year |
| glms_ref | Affiliate attribution on signup. | 30 days |
| __cf_bm | Cloudflare Bot Management. | 30 min |
Analytics (opt-in)
Only set when you accept via the cookie banner. Currently not used in this build — reserved for a future product-analytics integration.
Marketing (opt-in)
Only set when you accept via the cookie banner. Currently not used in this build — reserved for future personalisation and campaign attribution.
3. Local storage (not cookies but similar)
For completeness, we also use localStorage for:
glms_lang— your language preference (EN/IT/ES/FR/DE)glms_cookie_consent— your consent decision (mirrors the server audit record)glms_session— a client-side flag to skip/auth/meprobes on public pagesglms_lang_nudge_dismissed— remembers you dismissed the "switch to Italian" nudge
None of these hold personal data beyond your explicit UI choices.
4. How to control cookies
- In-app banner: shown at first visit. Choose "Accept all", "Reject non-essential" or "Customize" to pick categories.
- Change your mind later: go to Settings → Data → Cookie preferences to update.
- Browser controls: most browsers let you clear or block cookies from Settings → Privacy. Note that clearing
session_tokenwill log you out.
5. Third-party cookies
Third-party services we integrate with may set their own cookies on their subdomains:
- Stripe (checkout.stripe.com) — payment processing
- Emergent Auth (auth.emergentagent.com) — Google sign-in flow
- Cloudflare (
__cf_bm,__cflb) — bot management + load balancing
We do not control these cookies directly. Please refer to each provider's cookie policy.
6. Changes
We update this policy whenever we add or remove a cookie. The "Last updated" date at the top reflects the latest revision.
7. Contact
privacy@globalleadsuite.example (placeholder)