Cookie Policy
Everything plugwith.me stores on a device, why, and whether it needs your consent. Information under § 25 TDDDG and Article 5(3) of Directive 2002/58/EC. Part of the Privacy Policy.
We set no tracking cookies, anywhere. Our marketing site, our legal pages and our customers' link pages carry no analytics tag, no advertising tag and no cross-site identifier from us. That is why you never see a consent banner from us on those pages. There is exactly one situation where a consent notice appears: when a customer has enabled their own marketing pixel on their link page. Then nothing loads until the visitor chooses.
1. Three kinds of page
plugwith.me serves three kinds of page, with different storage on each:
- Our own pages — the landing page, the blog, the legal pages. Strictly necessary storage only, no consent required.
- The customer area —
/signup,/login,/appand the operator panel at/admin. Strictly necessary storage for the session and interface state. - Customer link pages —
plugwith.me/<slug>. Nothing from us except an age-gate flag where the customer switched the 18+ gate on. Third-party pixels only where the customer configured them, and only after consent.
2. Strictly necessary storage
These are exempt from consent under § 25(2) no. 2 TDDDG because they are strictly necessary to provide the service you explicitly requested. Each is first-party. None is used for analytics, profiling or advertising.
| Name | Where | Type | Purpose | Lifetime |
|---|---|---|---|---|
sb-*-auth-token | Customer area | Local storage | Holds your Supabase Auth session so you stay signed in between pages. Without it you would be signed out on every navigation. | Until sign-out or token expiry |
admin_session | /admin only | Cookie, HttpOnly, Secure | Operator login for the platform owner. Never set for customer accounts. | Session |
deeplinker_theme | Customer area | Local storage | Remembers the colour scheme you selected. | Until you clear it |
plugwith.intent.planplugwith.intent.interval | Pricing page → checkout | Local storage | Carries the plan and billing interval you clicked into the signup and checkout flow so you do not have to pick twice. | Until you clear it |
plugwith.last_login_bounce | Customer area | Session storage | Breaks a redirect loop when a session expires mid-navigation. | Until the tab closes |
age_verified | Link pages with the 18+ gate | Session storage | Records that the visitor confirmed being 18+ so the overlay does not reappear on every click in the same tab. | Until the tab closes |
pw_consent | Link pages with a pixel | Local storage | Stores the visitor's accept/reject decision so the notice is not shown again. Written only after a choice is made — never before. | 6 months |
Storing a consent decision is itself treated as strictly necessary: it exists solely to give effect to the choice made and to avoid asking repeatedly. Rejecting stores a "rejected" value; it does not store an identifier.
3. Marketing pixels on customer link pages
Customers may add their own tracking pixel to their link pages. Where one is configured, the following third-party scripts and cookies come into play. None of them loads unless the visitor accepts.
| Pixel | Provider | Typical identifiers set | Provider's notice |
|---|---|---|---|
| Meta Pixel | Meta Platforms Ireland Ltd., Dublin, Ireland | _fbp, and reads _fbc where present; connects to connect.facebook.net and facebook.com | Meta privacy policy |
| Google Analytics / gtag | Google Ireland Ltd., Dublin, Ireland | _ga, _ga_*; connects to googletagmanager.com, google-analytics.com, analytics.google.com | Google privacy policy |
| TikTok Pixel | TikTok Technology Ltd., Dublin, Ireland | _ttp; connects to analytics.tiktok.com | TikTok privacy policy |
| Snap Pixel | Snap Group Ltd., London, United Kingdom | _scid, sc_at; connects to sc-static.net | Snap privacy policy |
These are marketing and analytics technologies. They read and write information on the device and typically build a cross-site profile for advertising measurement and targeting. They are not exempt from consent.
3.1 Who is responsible
The controller for that processing is the customer who enabled the pixel — in some configurations jointly with the provider. plugwith.me neither determines the purposes nor receives the data. Section 9.4 of the Privacy Policy explains this in full.
3.2 How the consent gate works
- The pixel code is not present as executable script in the delivered page. It is held inline and inert until a decision is made, so no third-party request can happen before consent — not even a DNS lookup.
- A notice appears identifying the page, the purpose, and the providers by name, with two buttons of equal prominence: Accept and Reject.
- Nothing is pre-ticked. Continuing to scroll, or closing the notice, is not consent. There is no "legitimate interest" tab.
- Rejecting is one click, and leaves the page completely usable — every link and button still works.
- The decision is stored in
pw_consentfor six months and can be changed at any time via the Privacy choices link in the page footer, which reopens the notice. - If the browser sends a Global Privacy Control signal, we treat it as a rejection and do not show the notice at all.
Customers can see, but not remove, this gate. It is a platform-level control precisely because consent is a legal requirement rather than a design preference — see section 11.3 of the Terms.
4. Withdrawing or changing your choice
On a link page: open the Privacy choices link in the footer of that page. The notice reappears and your new choice replaces the old one immediately. Withdrawing consent stops any further loading of the pixel; data already sent to the provider must be dealt with by that provider under their own process (links in the table above).
In your browser: every browser lets you delete cookies and site data and block third-party cookies. Doing so also removes our strictly necessary entries, which will sign you out and reset your theme, but breaks nothing permanently.
5. What we deliberately do not use
- No analytics on our own pages — no Google Analytics, no Plausible, no Matomo, no server-side tag manager.
- No advertising or remarketing tags of our own, on any page.
- No heatmaps, session recording or A/B testing tools.
- No fingerprinting, no local-storage identifiers used as a cookie substitute, no cache-based tracking.
- No social media embeds, share buttons or comment widgets.
- No externally hosted fonts — the Inter typeface is served from our own domain.
- No cookie of our own on customer link pages.
No third-party script at all — including on the signup, login and dashboard pages. The Supabase client those pages need is served from our own domain at a pinned version.
6. Changes
We update this policy whenever the inventory above changes. The version and effective date at the top identify the applicable text. If we ever introduced a technology requiring consent on our own pages, we would ask before setting it.