Pactbound

Cookie Policy

Effective: April 13, 2026. DMG L&D, LLC, a Florida limited liability company.

1. Overview

Pactbound sets strictly necessary cookies to keep you signed in, and uses Google Analytics to see which pages get read. We do not use advertising cookies, tracking pixels, or social media cookies. In the EEA, the UK and Switzerland, Google Analytics is off until you accept it — you will see a banner asking. Elsewhere it is on by default and you can turn it off on our privacy page; either way you can change your mind later. Section 6 explains what each cookie does. This Cookie Policy explains what we set, why, and how long it lasts.

2. What Are Cookies

Cookies are small text files placed on your device by a website when you visit. They are stored in your browser and sent back to the originating website on subsequent visits. Cookies serve different purposes: some are essential for a website to function, others are used to remember your preferences, and others are used to track your behavior across websites for advertising purposes. Pactbound uses only the first category: "strictly necessary" cookies.

3. Cookies We Set

The following cookies are set by Pactbound and its authentication provider (Supabase), and are first-party (set on the pactbound.com domain). One exception: Cloudflare Turnstile, our bot-protection provider, may set its own cookies on its own domain when a challenge is displayed on the signup, login, or acknowledgment forms. Those are strictly necessary to prevent automated abuse.

sb-[project-ref]-auth-token

Purpose
Stores your encrypted Supabase Auth session token. Required to keep you logged in between page requests. Set by Supabase Auth (SSR) on the pactbound.com domain.
Duration
Session / up to 1 hour (refreshed automatically on activity)
Type
Strictly necessary

sb-[project-ref]-auth-token.0

Purpose
Overflow chunk for the auth session token when the cookie payload exceeds 4KB. Works in conjunction with the primary auth token cookie. Only set when the session data requires chunking.
Duration
Session / up to 1 hour
Type
Strictly necessary

sb-[project-ref]-auth-token.1

Purpose
Additional overflow chunk, same purpose as the .0 variant. Only set when required.
Duration
Session / up to 1 hour
Type
Strictly necessary

4. Why These Cookies Are Strictly Necessary

Authentication session cookies are required for the Service to function. Without them, you cannot log in, create handoffs, access your dashboard, or perform any authenticated action. The Service cannot be provided without these cookies. There is no less privacy-invasive alternative to maintaining an authenticated session across page requests in a server-rendered web application. These cookies contain no personal data: they contain only an encrypted, opaque session identifier. The actual session data is stored server-side in our Supabase database and is never written into the cookie itself.

5. What We Do NOT Use

  • No advertising or remarketing tags. Google Analytics is present, but its advertising features are switched off in every region: ad storage, ad user data and ad personalisation are denied, so nothing here feeds ad targeting or is shared with Google Ads.
  • No Facebook Pixel, Meta Events, or any Meta tracking.
  • No advertising networks or demand-side platforms (DSPs).
  • No cross-site tracking cookies.
  • No third-party session recording tools (Hotjar, FullStory, etc.).
  • No A/B testing platforms that set cookies.
  • No social media share buttons that track you across sites.
  • No browser fingerprinting for tracking, profiling, or advertising. Our bot-protection provider (Cloudflare Turnstile) analyzes signals about your browser environment solely to tell humans from bots on the signup, login, and acknowledgment forms.

6. How We Count Visits Without Cookies

We measure which pages get read two separate ways. The first is our own, and it stores nothing on your device: when you load a page, our server derives a short code from your IP address and browser name plus a secret that changes at midnight UTC every day. The code is recorded; your IP address and browser name are not, and because the secret rotates, the same browser produces a different code tomorrow — so those records cannot be assembled into a history of one person. That one respects "Do Not Track" and Global Privacy Control: send either and we record nothing for the visit. The second is Google Analytics, which does set its own cookies and does send data to Google. In the EEA, the UK and Switzerland it stays off until you accept it. Everywhere else it is on by default, and the switch on our privacy page turns it off for good on this browser.

7. No Cookie Consent Banner Required

Under the EU ePrivacy Directive (implemented in EU member state laws) and the UK PECR, cookies that are "strictly necessary" for a service explicitly requested by the user are exempt from the requirement to obtain prior consent. Because Pactbound sets only strictly necessary authentication cookies, and because the page-view measurement in section 6 stores nothing on your device to require consent for, we do not display a cookie consent banner. This is a deliberate policy choice, not an oversight.

8. Browser Storage (Not Cookies)

In addition to cookies, Pactbound may use browser localStorage or sessionStorage for temporary application state: for example, preserving draft handoff form state between page reloads or storing UI preferences. One sessionStorage entry records which page you first arrived on and any campaign tag in that link, so a signup can be credited to the right source; it lives in the tab and is gone when you close it. This data is stored only on your device and does not identify you. You can clear this data at any time through your browser's developer tools or storage settings.

9. How to Control Cookies

All modern browsers allow you to view, manage, and delete cookies. You can also configure your browser to refuse cookies. Note that blocking authentication cookies will prevent you from logging into Pactbound. Instructions for managing cookies in common browsers:

  • Chrome: Settings → Privacy and security → Cookies and other site data
  • Firefox: Settings → Privacy & Security → Cookies and Site Data
  • Safari: Settings → Safari → Privacy → Manage Website Data
  • Edge: Settings → Cookies and site permissions → Cookies and site data

10. Do Not Track

Some browsers offer a "Do Not Track" (DNT) signal, and some send Global Privacy Control (GPC). We honour both: when either is present, the page-view measurement described in section 6 records nothing for that visit. It changes nothing about our cookies, because the only cookies we set are the authentication cookies the Service cannot run without. We set no advertising or cross-site tracking cookies for a DNT signal to switch off.

11. Changes to This Policy

If we change how we measure the site, we will update this Cookie Policy. If a change involves storing something on your device that is not strictly necessary, we will implement an appropriate consent mechanism before setting it. The effective date above reflects the current version.

12. Contact

For questions about this Cookie Policy, contact [email protected]. DMG L&D, LLC, a Florida limited liability company.