Beacon Cookie Policy
Last updated: [LAST UPDATED DATE — e.g. June 20, 2026] Version: 1.0 (draft)
This Cookie Policy explains how [LEGAL ENTITY NAME] ("Beacon", "we", "us", or "our") uses cookies and similar technologies on the Beacon platform at warmbeacon.com and related subdomains (the "Service"). It should be read alongside our Privacy Policy.
> Plain-language summary. Beacon uses one cookie: a strictly-necessary login/session cookie that keeps you signed in. We do not use analytics, advertising, or third-party tracking cookies, and we do not load tracking pixels or marketing scripts on our website. Because our only cookie is essential to operate the Service you asked to use, it does not require your consent under EU/UK ePrivacy and GDPR rules.
1. What cookies and similar technologies are
A cookie is a small text file that a website stores on your device so it can be recognized on later requests — for example, to remember that you are logged in. Similar technologies include browser storage mechanisms such as localStorage, which a site can use to remember a small preference on your device.
Cookies can be:
- First-party (set by the site you are visiting — here, Beacon) or third-party (set by another domain).
- Session cookies (deleted when you close your browser) or persistent cookies (kept until they expire or you delete them).
2. The cookies Beacon actually uses
Beacon uses a single, strictly-necessary first-party cookie. We do not use any others.
| Cookie | Type | Purpose | Duration | |---|---|---|---| | beacon_session | Strictly necessary (first-party, persistent) | Authentication. After you log in, this cookie holds a signed, server-revocable session token so the Service knows who you are on each request and keeps you signed in. It is HttpOnly (not readable by page scripts), Secure (sent only over HTTPS in production), and SameSite=Lax (which also helps protect against cross-site request forgery). | Up to 30 days, or until you log out, delete your account, or clear it from your browser. Logging out immediately clears this cookie and invalidates the underlying server session. |
That is the complete list. We do not set any other cookies on warmbeacon.com.
3. Cookies we do NOT use
To be explicit:
- No analytics or measurement cookies. We do not use Google Analytics, Segment, Mixpanel, PostHog, Plausible, Fathom, or any similar tool on our website.
- No advertising or marketing cookies. We do not run ad pixels, retargeting tags, or social-media trackers (e.g., no Meta/Facebook pixel, no LinkedIn or Google Ads tags).
- No third-party tracking cookies of any kind on warmbeacon.com.
- No separate CSRF cookie. Cross-site request forgery protection is provided by the
SameSite=Laxattribute on the session cookie above, not by an additional token cookie.
> Note on email tracking. Beacon offers open- and click-tracking for the outbound emails our customers send to their prospects. That tracking uses tracking pixels and link redirects inside those emails — it is not a cookie on the warmbeacon.com website, and it is governed by our Privacy Policy and the customer's own outreach. It is mentioned here only to avoid confusion.
4. Similar technologies (browser storage)
Beacon uses a single, non-tracking key in your browser's `localStorage` to remember that you have dismissed the in-app "activation checklist" banner, so it does not reappear on every visit. This flag is stored per workspace and holds only a yes/no dismissal value. It is not a cookie, is never sent to our servers or any third party, is not used to identify or track you, and you can clear it at any time through your browser's site-data settings.
5. Third-party cookies (Stripe at checkout)
Beacon does not embed third-party cookies on its own pages. However, when you start a paid subscription, you are taken to a payment page hosted by Stripe (our payment processor). On that Stripe-hosted page, Stripe may set its own cookies — including strictly-necessary and fraud-prevention cookies — under Stripe's control and privacy/cookie policies, not Beacon's. We recommend reviewing Stripe's cookie and privacy notices at [stripe.com/privacy](https://stripe.com/privacy). We do not receive or read these Stripe cookies.
6. Legal basis and consent
Under the EU/UK ePrivacy rules and the GDPR, cookies that are strictly necessary to provide a service the user has explicitly requested do not require prior consent. Beacon's only cookie — the beacon_session login cookie — is strictly necessary to authenticate you and operate the Service. Because we use no analytics, advertising, or other non-essential cookies, we do not display a cookie consent banner, as there is nothing requiring consent. If we ever introduce non-essential cookies (for example, optional analytics), we will update this policy and, where the law requires it, obtain your consent through an appropriate consent mechanism before setting them.
7. How to control cookies
You remain in control of cookies in your browser. You can:
- Delete the session cookie or block cookies for warmbeacon.com via your browser settings.
- Log out of Beacon at any time, which immediately clears the
beacon_sessioncookie and ends the server session. - Clear
localStoragefor the site through your browser's "clear site data" controls.
Most browsers also let you manage cookies site-by-site. Instructions for common browsers: [Chrome], [Safari], [Firefox], [Edge].
> Important: Because beacon_session is essential, blocking or deleting it will log you out and prevent you from signing in to Beacon. The Service cannot keep you authenticated without it. Blocking strictly-necessary cookies does not stop other tracking, because we don't do any.
8. Changes to this policy
We may update this Cookie Policy from time to time — for example, if we add a new technology or subprocessor. When we do, we will revise the "Last updated" date above and, for material changes (such as introducing any non-essential cookie), provide a more prominent notice and obtain consent where required.
9. Contact
Questions about this Cookie Policy or our use of cookies can be sent to:
[LEGAL ENTITY NAME] [REGISTERED BUSINESS ADDRESS] Email: [PRIVACY CONTACT EMAIL — e.g. privacy@warmbeacon.com]
For more on how we handle personal data generally, see our Privacy Policy.