1. What Cookies Are
Cookies are small files stored by your browser. Similar technologies include local storage and server-side event records. First-party cookies are set by Cardora; third-party cookies may be set by a provider whose service you use through Cardora.
2. Authentication and Essential Cookies
Cardora and its authentication provider use session cookies to sign users in, refresh sessions, protect accounts, and provide requested app features. Their names and durations may vary as the authentication service manages and rotates them. Blocking these cookies may prevent sign-in or other account features from working.
3. First-Party Analytics Cookies
When first-party usage analytics is enabled, Cardora uses the following HTTP-only, same-site cookies. They are sent only to Cardora and are not readable by browser scripts.
cardora_anonymous_id— a random browser identifier used to count visits and connect acquisition steps without storing an email address; normally expires after 180 days.cardora_session_id— a random identifier used to group and deduplicate events in one browsing session; normally expires after 30 minutes.cardora_first_touch— stores the first recognized campaign or search attribution and landing path; normally expires after 90 days.cardora_latest_touch— stores the latest recognized campaign or search attribution and landing path; normally expires after 30 days.
Attribution values can include campaign source, medium, campaign, content, term, and a page path. They are normalized and length-limited. These cookies do not contain account passwords, one-time passwords, email addresses, card content, contact-exchange values, or full destination URLs.
4. Related Measurement Events
Cardora may associate the identifiers above with limited server-side events such as landing-page views, calls to action, signup steps, card creation or publication, sharing, profile views, vCard downloads, link clicks, contact-exchange submissions, upgrades, checkout starts, and subscription starts. Event records may include timestamps, coarse device class, referring hostname, campaign attribution, and an account or card identifier for signed-in activity.
Analytics records are designed not to store raw IP addresses, full user-agent strings, submitted contact details, card-field values, or outbound destinations. They are used to measure whether Cardora's pages and product flows work and are generally retained for 90 days.
5. Payment and Other Provider Cookies
Authentication, payment, hosting, security, or wallet-integration providers may use cookies or similar technologies when their features are requested. Those technologies are controlled by the relevant provider and may be governed by its own notice. Cardora does not use third-party advertising cookies through its first-party analytics system.
6. Managing Cookies
You can inspect, block, or delete cookies using your browser settings. Blocking all cookies may prevent authentication and other Cardora features from working. Deleting an analytics cookie causes a new random identifier to be created if measurement remains enabled on a later visit.
Cardora does not currently provide a separate cookie-preference banner. Depending on where you live, local law may provide additional rights regarding cookies or measurement data. You can ask about those rights or request deletion of information linked to your account by emailing privacy@cardora.io.
7. Changes to This Notice
We may update this notice when our use of cookies or providers changes. We will update the effective date above and provide additional notice when required.
8. Contact
Cookie questions can be sent to privacy@cardora.io.