AutoPosting ProPricing →
// COOKIE POLICY

Cookie Policy

Last updated September 8, 2026

We use first-party cookies for sign-in and security, a non-essential first-touch attribution cookie (ap_attr), and optional Google Analytics cookies. Google Analytics is off until you choose Allow analytics. Declining, closing the notice, or pressing Escape does not enable it. You can change your choice with the Cookie settings button on any page. We do not enable advertising or retargeting features.

Our Google Analytics integration measures allowlisted public marketing pages only, not sign-in, registration, customer/admin dashboards, the extension, or tools that accept dealership text. The page-view fields we send contain a fixed page label and canonical public path without query strings, URL fragments, or referring URLs. We do not send account identifiers, email addresses, phone numbers, vehicle records, or buyer conversations to Google Analytics. If you allow it, Google receives standard request information such as your IP address and browser/device information, plus pseudonymous analytics identifiers and usage events. Google processes that data under its own terms and Privacy Policy; it is not anonymous simply because we omit account details. Google Signals, advertising personalization and automatic user-provided data collection are disabled.

Optional Google measurement includes scrolling and eligible public demo-video engagement, plus application-controlled events for selected calls to action, extension/download links, phone/email links, pricing and billing choices, FAQ openings, sections viewed, and checkout attempts or checkout-page creation. Our application-controlled event fields use fixed labels, plan/billing choices, and a coarse source category such as search, social or direct—not typed form values, contact details, raw campaign text, full clicked URLs or error messages. Approved embedded-video measurement can include the public demo’s title, URL, provider, duration and playback progress. Automatic search, form, outbound-link and file-download collection is disabled in favor of these controlled events.

These events describe website interactions, not necessarily business outcomes: a phone/email click does not prove contact, an extension/download click does not prove installation, a request to open the demo does not prove it played, and checkout creation does not prove payment. This Google integration does not send a purchase or successful-registration event. Confirmed payment records remain in our billing systems.

Separately, we measure site traffic with Vercel Web Analytics, which is cookieless: it reports aggregate page views, referrers, country, device class, and fixed interaction events such as CTA clicks, demo plays, plan choices and sections viewed. Those events contain labels chosen by us—not anything a visitor typed—and do not create a cross-site profile or store an identifier on the visitor’s device. The Google Analytics choice does not change this existing Vercel measurement or the first-touch attribution described below.

After Stripe accepts a request to create a hosted checkout, AutoPosting Pro attempts to keep one server-side acquisition checkpoint so a browser click is not mistaken for a working checkout. That checkpoint contains only the selected plan and billing interval, a coarse fixed first-touch source category, and the landing-page version when present. Dynamic campaign and referrer text is not stored in this checkpoint. It contains no name, email, IP address, raw URL or referrer, Stripe session or customer ID, account ID, or visitor identifier, and it is not directly linked to an account. If that best-effort checkpoint cannot be recorded, checkout continues; aggregate checkpoint counts are therefore a lower bound, not a complete count of Stripe sessions.

When someone activates a phone or email link on one of our public marketing pages, the page also attempts a best-effort server checkpoint containing only the fixed channel (phone or email) and a coarse source category derived in the browser from ap_attr, if present. The request omits cookies and the browser referrer, and the product audit record stores no name, email address, phone number, destination, message, page, link position, raw URL, referrer, UTM text, account, organization, visitor identifier, or IP address. The server may use the request IP transiently for abuse limiting, and ordinary Vercel infrastructure logs still apply as described below. This activation count is not a lead: repeats, accidental or automated clicks, and clicks whose phone or email handler fails may count, while copied contact details or blocked requests may not.

For an exact campaign link registered by AutoPosting Pro, the normal site client may submit a best-effort first-party campaign-arrival checkpoint after a visible page matches the registered path and all four campaign parameters. The application payload contains only one fixed campaign code; the server derives the fixed source and landing labels from its own registry. This request is separate from the first-touch ap_attr cookie, does not read that cookie, and explicitly omits all cookies and the browser referrer. The application table stores only the UTC day, fixed registered code, and a count bounded at 5,000 per code per day. It stores no per-event timestamp, full URL, raw UTM value, name, account, organization, visitor or device identifier, or IP address. The request IP may be processed transiently into a short-lived HMAC rate-limit key, and ordinary Vercel infrastructure logs still apply outside this application counter. A recorded checkpoint means only that the endpoint incremented the registered key’s daily counter; it does not prove the URL rendered, a link click, referring site, unique or human visitor, dealership, lead, signup, purchase, or customer. Direct or replayed requests, copied links, reloads, multiple tabs, automation, and previews may count; blockers, hidden pages, network failures, request limits, and write failures may be missed. A count of 5,000 means at least 5,000 recorded submissions because the counter stops increasing at that cap. The admin report reads a rolling 90-day window; older daily aggregate rows follow the service’s general retention practice rather than being automatically deleted when they leave that report.

Cookies we set

The cookies below are first-party (stored for this website). That does not mean all data stays with us: the optional Google Analytics cookies support measurement sent to Google. Sign-in cookies are marked HttpOnly and Secure where supported and generally appear only during sign-in. Google Analytics cookies and ap_attr are script-readable. Unlike opt-in Google Analytics, ap_attr is written on your first visit to an allowlisted public marketing page. A deliberately source-tagged link to the signed-out login page may also establish the campaign source, but the login path itself is not retained as marketing landing evidence; signed-in, operational, legal and arbitrary missing routes do not write it. It stores bounded arrival information: a classified source, referring host and path without the query string, landing path, campaign labels supplied in UTM parameters, first-touch time, and the homepage version when applicable. AutoPosting Pro does not intentionally put personal information in those fields, but an outside link publisher can place personal text in a campaign label or referring path. Campaign links should never contain personal information. On non-HTTPS local development the __Secure-/__Host- prefixes are dropped.

CookiePurposeDurationEssential
_ga, _ga_K61D0MQKVFGoogle Analytics browser and session measurement on allowlisted public marketing pages, only after you choose Allow analytics. These pseudonymous identifiers help measure page views, scrolling, demo engagement, selected link and button activations, plan choices and checkout steps; they are not connected by our integration to your AutoPosting Pro account, inventory, or messages. Advertising signals are disabled.30 days; no sliding extensionNo — opt-in
__Secure-next-auth.session-tokenKeeps you signed in to the client portal and admin dashboard.8 hoursYes
__Host-next-auth.csrf-tokenProtects sign-in and account forms against cross-site request forgery.Browser sessionYes
__Secure-next-auth.callback-urlReturns you to the page you came from after signing in.Browser sessionYes
apf_tdRemembers a device you explicitly trusted after two-factor sign-in, so we do not have to email you a code on every login from that device.30 daysYes
meta_pickEncrypted, short-lived cookie used only during the Facebook connection flow, while you choose which Facebook Page to connect.10 minutesYes
ap_attrRemembers how you first arrived at this site (for example: a search result, a link from another site, or a campaign link) so that if you later start checkout or create an account we know which channel to credit. Written once, on your first visit, and never updated after that. AutoPosting Pro does not add your name, email, account, advertising or device identifier to it, and never uses it to follow you elsewhere. It can copy bounded campaign labels and the referring host and path already supplied by the arrival link or browser; those labels are not guaranteed to be free of personal text that a link publisher put there.30 daysNo

Browser storage (not cookies)

We also use your browser’s localStorage for small UI and consent preferences. These preference values are not sent to our servers:

  • autopostingpro:setup:progress — remembers which steps of the portal setup checklist you have completed.
  • ap_google_analytics_consent_v1 — remembers your explicit Google Analytics choice until you change it or clear browser storage. If storage is blocked, your choice applies only in the current tab.
  • ap_cookie_notice_v1 — an older notice-dismissal preference. It is not permission for Google Analytics and is no longer used to make that choice.

What we do not use

  • No advertising or retargeting cookies.
  • No session recording or analytics collection of typed messages, customer account details, or dealership inventory.
  • No Google advertising signals, advertising personalization, or cross-domain analytics linking enabled by this integration.
  • We do not sell or share your data for advertising.

Third-party services

  • Google Analytics — optional website measurement after your consent, with Google’s processing described above. Data retention in Google Analytics is controlled by the property settings and is separate from our 30-day browser-cookie expiration.
  • Stripe — payments happen on Stripe’s own hosted checkout page (checkout.stripe.com). Stripe sets its own cookies there under its own privacy policy; card details never touch our servers.
  • Iconify CDN — the site loads its icon graphics from the Iconify CDN. Those requests carry standard web-request data (IP address, browser info) like any resource load, and set no AutoPosting Pro cookies.
  • Infrastructure logs — our hosting provider (Vercel) keeps standard server logs (IP address, user agent, timestamps) for security and operations, and the domain’s DNS and email routing run through Cloudflare. These are ordinary infrastructure records, not tracking cookies.

Managing cookies

Use Cookie settings → Turn off analytics to withdraw Google Analytics permission. This disables further collection by our integration and removes its accessible host-only analytics cookies; it does not recall requests already sent or automatically delete data Google has already received. Requests in flight may finish. You can also block or delete cookies in your browser settings. Blocking sign-in cookies prevents portal sign-in; public marketing pages still work. Blocking or deleting ap_attr changes nothing about how the site works for you and prevents durable first-touch attribution. The separate fixed-code campaign-arrival checkpoint does not use that cookie; browser privacy controls or content blockers can block its first-party request. If you start checkout or sign up directly from a current AutoPosting Pro page whose same-origin URL still contains campaign or click information, that current-page source may still be classified for that one request.

Changes & contact

If we ever add a new cookie, we will list it here and update the date above. Questions: [email protected]. See also our Privacy Policy.

This document is provided as a general template and does not constitute legal advice. Have counsel review it before relying on it.