1. Scope and rule
This policy explains cookies, local storage and similar device operations used by Speartip. Under Section 25 TDDDG, we use non-essential device storage or access only after consent. Storage strictly necessary to transmit a communication or provide a service you expressly request does not require that consent. The related personal-data processing is described in the Privacy Notice.
2. Your choice
Optional analytics is off by default. You can accept or reject it with equal prominence and reopen Privacy settings at any time. Withdrawal stops future optional loading and removes known Clarity cookies accessible to Speartip; provider-side data already lawfully collected remains subject to the retention described in the Privacy Notice. Browser deletion may also be used.
3. Consent record
speartip_consent_v2 in local storage records the policy version, analytics choice, decision time and expiry for up to six months. It is strictly necessary to remember and enforce your selection. When it expires or the purposes materially change, we ask again.
4. Account sessions
speartip_account_access_token and speartip_operator_access_token are HTTP-only, Secure in production and SameSite=Lax cookies used to authenticate the requested vendor or Speartip team session for up to 15 minutes. speartip_account_refresh_token and speartip_operator_refresh_token securely renew that session for up to 30 days. Logout, revocation or security action can end them sooner.
5. Sign-in transactions
A short-lived HTTP-only OIDC transaction cookie binds a Google or LinkedIn callback to the browser, carries integrity-protected state and expires after approximately ten minutes. A pending-registration email cookie may retain the verified registration address for up to 24 hours to complete the requested flow.
6. Launch and upload sessions
speartip_launch_asset_session and speartip_launch_onboarding_session associate uploaded assets, checkout recovery and submission state with the requested launch flow for up to 24 hours. They are HTTP-only, Secure in production and SameSite=Lax.
7. Form storage
speartip_launch_draft and speartip_launch_onboarding_state in session storage preserve a launch form within the current browser tab. They may include entered business and contact details. They are removed after successful submission, when the tab session ends, or when you clear site data. Do not use a shared device for confidential drafts.
8. Microsoft Clarity
If and only if you consent to analytics on a public page, Clarity may set _clck for up to one year to retain a browser’s Clarity identifier and preferences, and _clsk for about one day to combine page views into a session. Depending on Microsoft routing, CLID may identify first-time Clarity observation for up to one year; MUID may act as a Microsoft browser identifier; ANONCHK may record its transfer status for about ten minutes; MR may support its refresh for about seven days; and SM may synchronize it during a session. Actual provider cookies and durations can change; current details are available in Microsoft’s cookie list. Clarity is not loaded in vendor or admin workspaces.
9. Stripe-hosted checkout and billing portal
Speartip does not embed Stripe.js or Stripe payment frames. When you deliberately start checkout or billing management, your browser navigates to Stripe’s separate hosted service. Stripe may use technologies required for payment, authentication, fraud prevention, security, load balancing and saved payment choices under the information and controls presented there. Those operations occur on Stripe’s domain under Stripe’s notice; returning to Speartip does not copy full card credentials to us.
10. Server-side measurement
GoAccess and our aggregate first-party performance counters do not use cookies, local storage, fingerprinting or another device identifier. Standard request delivery still necessarily transmits connection data as described in the Privacy Notice.
11. Browser controls
Browsers let you inspect, block and delete site data. Blocking necessary storage can prevent sign-in, security, upload, checkout recovery or draft functions. Browser-level opt-out signals are respected where legally required; the in-site settings remain the authoritative choice for optional services we control.
12. Updates and provider details
We review this list when features or providers change and obtain renewed consent before adding a materially different optional purpose. Questions or discrepancies can be reported to legal@speartip.eu.
