Cookie & Storage Policy
Effective date: May 4, 2026
1. What StellarTies Stores in Your Browser
StellarTies sets no cookies on the stellarties.com domain. Everything we keep is stored in your browser's localStorage: first-party, readable only by stellarties.com, and never sent to or readable by any third party. Here is every item, in full:
stellarties_token— Session token. A random token that authenticates your requests to our API after you sign in. No personal data is embedded in it. Removed when you sign out.stellarties_refresh_token— Refresh token. Lets you stay signed in without re-entering your password. Removed when you sign out.stellarties_a11y— Accessibility preference. Remembers the display option you chose (larger text and/or higher contrast). Kept until you change it or clear your browser data.st_utm— Campaign attribution. Records which marketing link or ad first brought you here — theutm_source,utm_medium,utm_campaign,utm_contentandutm_termtags on the link, plus the ad-click identifier the ad platform appends to the URL when you click an ad (gclidfrom Google,fbclidfrom Meta,msclkidfrom Microsoft). First-touch only: a later visit does not overwrite it. Auto-expires after 30 days, and is cleared the moment you start a trial.st_ref— Referral handle. Records the handle of a creator or partner who referred you, so any referral credit is attributed correctly. First-touch only. Auto-expires after 30 days, and is cleared once a referral is recorded.st_trial_ineligible— Trial-used flag. A plain1marking that this browser has already used its free trial, so we don't offer it again. Kept until you clear your browser data.st_trial_gated/st_trial_gated_dismissed— Dashboard-state flags. Plain1values that remember your dashboard is in the trial-gated state and that you dismissed the related banner, so it isn't shown repeatedly. Kept until you clear your browser data.st_auth_ui— Sign-in interface preference. Records whether you view sign-in and sign-up as in-page forms or as our hosted sign-in page, when you've explicitly chosen one via a link. Kept until you clear your browser data or choose the other option.
A few short-lived values also live in sessionStorage, which your browser erases when you close the tab: security values that protect the sign-in exchange (stellarties_pkce_verifier, stellarties_oauth_state), the last inputs you entered into a "try it" form, a tool's chosen observer location, an invite code mid-acceptance, and one-time interface flags. None of these persist beyond the browser tab.
2. Cookies Set by Service Providers We Redirect You To
Some flows redirect your browser to providers we use to operate the service. Those providers set their own cookies on their domains during those flows. We do not control these cookies and they are not readable from stellarties.com:
- AWS Cognito: session cookies during the authentication flow. Required for sign-in to function. See AWS Privacy Notice.
- Stripe Checkout & Customer Portal: cookies required for payment processing, fraud prevention, and the billing portal. See Stripe Privacy Policy.
These cookies are strictly necessary for sign-in and payment to work. Disabling them in your browser will break those flows.
3. First-Party Analytics Beacon
StellarTies aggregates page-engagement metrics (which pages are visited, how long visitors spend on them).
The beacon is first-party (no third-party host involved), cookie-less (it sets nothing in your browser), and works from a short-lived random visitor hash, not from a persistent identifier we can use to recognize you across sessions.
We do NOT use:
- Third-party analytics services (Google Analytics, Mixpanel, etc.)
- Third-party tracking pixels
- Advertising networks or retargeting
- Cross-site tracking of any kind
4. Other Third-Party Connections
We load fonts from Google Fonts (fonts.googleapis.com). This involves a third-party connection to Google servers but is not tracking. Google may receive your IP address for this request. See Google Fonts Privacy.
5. Purpose of Stored Items
The session and refresh tokens exist solely to maintain your authenticated session so you can reach your saved partners, reports, and forecasts. The accessibility value stores a display preference you chose. None of these track you.
st_utm and st_ref exist for first-party measurement: they let us see which marketing link, ad, or referral first brought you to StellarTies, so we can tell what's working and credit referrals correctly. The ad-click identifiers in st_utm (gclid, fbclid, msclkid) are IDs that Google, Meta, and Microsoft add to a link when you click one of our ads — we simply remember which ad brought you. These values stay in your browser, are readable only by stellarties.com, hold no profile of you, and are used for nothing beyond attributing your visit to the campaign that referred it.
6. Duration
The session and refresh tokens persist until you sign out (which removes them) or clear your browser data; the server may also invalidate a session independently. The accessibility preference persists until you change it. st_utm and st_ref automatically expire 30 days after they are set — earlier if you start a trial or a referral is recorded. The trial-state flags persist until you clear your browser data. The sessionStorage values in §1 are erased when you close the browser tab.
7. How to Clear
To remove StellarTies data from your browser:
- Sign out using the Sign Out button on your Account page (removes the session and refresh tokens).
- Open your browser's Developer Tools > Application > Local Storage and delete any
stellarties_*,st_utm,st_ref,st_trial_*, orst_auth_uientry individually. - Or clear all site data via your browser's Settings > Privacy > Clear browsing data. This removes every item above, including the campaign-attribution and referral keys (note: this also clears cookies set by Cognito and Stripe on their own domains).
st_utm and st_ref also clear themselves after 30 days with no action from you.
8. Why We Don't Show a Cookie Banner
stellarties.com sets no cookies of its own. The provider cookies in §2 (Cognito, Stripe) are strictly necessary for sign-in and payment, and ePrivacy / GDPR do not require consent for strictly-necessary cookies.
Everything else we store is listed in §1 with its purpose: the session and refresh tokens keep you signed in, one value stores your accessibility preference, the trial flags stop us repeating an offer, and st_utm / st_ref record which link, ad, or referral first brought you here. All of it is first-party only — stored in your browser, readable only by stellarties.com, never sent to or readable by any third party, and not used to track you across other sites. st_utm and st_ref expire after 30 days; §7 shows how to clear anything sooner.
9. Contact
Questions about this policy: privacy@stellarties.com