Skip to content
Preliminary draft — not attorney-approved

These pages are first-pass language and are not legal advice. They are written by the team to be honest and easy to read; consult your own counsel before relying on them in a contract. We'll mark the date each section was last revised at the top of the page.

Preliminary draft · Cookies & local storage

Cookies & local storage

The four categories of cookie/localStorage state Tollcast sets, and how to turn each off.

Last updated 2026-08-17 — language is a working draft, not legal advice.

What we set

The cookies Tollcast sets

Tollcast sets a small, fixed set of cookies + localStorage items. We don't run third-party analytics or ad pixels beyond the Meta-pixel opt-in.

NamePurposeLifetime
better-auth.session_token + csrfsign-in session cookie + CSRF token14 days, refreshed on activity
tollcast-themelight/dark theme preferencepersistent on localStorage
tollcast-utmcaptures the incoming UTM params for the funnelstored in sessionStorage, dropped on tab close
Meta pixel (only after explicit consent)conversion tracking on ads the team runsgated by the same consent described in `/privacy`

We don't run analytics beyond the Polsia platform analytics that ship with the runtime. No third-party tracking outside the Meta-pixel opt-in.

How to clear

Clearing or refusing the cookies

Modern browsers let you block or wipe these cookies. The signing cookie is the only one strictly required for sign-in; clearing it signs you out. The theme and UTM tokens are optional.