Skip to content

Cookie Policy

Version
2026-09-10
Effective from
Last updated

This policy describes what Collabify stores in your browser, why, and how you control it. It complements the Privacy Policy, which covers everything else we do with personal data.

The tables below are generated from our cookie registry — the same registry that drives the consent prompt. Anything not in the registry is not set, and no entry can be described one way here and another way in the prompt.

Cookie registry version: 2026-09-09.

1. What this policy covers

A cookie is a small text file your browser stores when you visit a site. The law does not distinguish by technology: a key in your browser's local storage (localStorage, sessionStorage) is covered by the same rules. This policy covers both, and both are listed separately below.

It applies to the website. The Collabify iOS and Android apps do not use cookies; what they store on your phone is described in the Privacy Policy.

2. Categories

Essential
Required for the Service to work — signing in, security, connections you start yourself, and remembering your own cookie choice. They cannot be switched off; blocking them in your browser makes signing in impossible.
Analytics
Measure how the Service is used so we can improve it. Set only with your consent.
Marketing
Advertising and retargeting cookies. Set only with your consent.

3. Cookies we set

NamePurposeCategorySet byRetention
__sessionClerk session token. Authenticates every request; required for every signed-in page.EssentialClerk (first-party, collabify.se)Session cookie (cleared when you close your browser)
__client_uatSigned-in-at timestamp that lets the server pick the right page without reading the full session token first.EssentialClerk (first-party, collabify.se)Session cookie (cleared when you close your browser)
__clerk_db_jwtClerk's hardened session JWT, used by Convex queries to verify the caller. Set in development and preview environments.EssentialClerk (first-party, collabify.se)Session cookie (cleared when you close your browser)
cb_anon_v1Anonymous visitor id. Ties a consent decision to the visit before you sign in, so the decision can be evidenced afterwards.EssentialCollabify (first-party, collabify.se)1 year
cb_consent_v1A copy of your most recent cookie choice so the page does not have to re-fetch the decision on every page view.EssentialCollabify (first-party, collabify.se)1 year
NEXT_LOCALEYour language choice. Set by next-intl when the language in the URL differs from your browser's, so the language follows you between pages.EssentialCollabify (first-party, collabify.se)Session cookie (cleared when you close your browser)
contract_review_tokenTime-boxed proof of access that lets a signed review link open a contract without signing in.EssentialCollabify (first-party, collabify.se)30 minutes
tiktok_oauth_stateOne-time value that protects the TikTok connection against forged callbacks (CSRF). Set only when you start the connection yourself.EssentialCollabify (first-party, collabify.se)10 minutes
tiktok_oauth_verifierPKCE secret binding the TikTok sign-in to your browser specifically.EssentialCollabify (first-party, collabify.se)10 minutes
tiktok_oauth_uidYour account id, so the TikTok connection lands on the right account when you return from TikTok.EssentialCollabify (first-party, collabify.se)10 minutes
tiktok_oauth_return_urlThe page you started the TikTok connection from, so you are returned to it.EssentialCollabify (first-party, collabify.se)10 minutes
tt_wl_stateThe same CSRF protection as above, for the TikTok connection in the waitlist flow.EssentialCollabify (first-party, collabify.se)10 minutes
tt_wl_verifierPKCE secret for the TikTok connection in the waitlist flow.EssentialCollabify (first-party, collabify.se)10 minutes
tt_wl_return_toThe page you started the waitlist TikTok connection from, so you are returned to it.EssentialCollabify (first-party, collabify.se)10 minutes
Clerk may temporarily set additional cookies prefixed __clerk_ while a sign-in is in flight. They are necessary for signing in and expire within minutes.

4. What we keep in browser storage

Beyond cookies, the Service keeps a few values directly in your browser. Each is either a setting you made yourself or a draft of something you are in the middle of writing — none of it is used for measurement, none of it leaves your device on its own, and none of it is an identifier that can be followed across sites. Clearing site data for Collabify in your browser removes all of it.

KeyWherePurposeRetention
theme-<business|influencer>Browser storageLight or dark appearance, per portal — the setting you picked yourself.Until you clear your browser storage
collabify.designVersionBrowser storageWhich appearance version you picked.Until you clear your browser storage
collabify.designVersion.defaultsMigratedBrowser storageA marker that your appearance choice has already been moved to the new default, so it is not overwritten.Until you clear your browser storage
collabify.codex5Browser storageOn/off for an experimental interface.Until you clear your browser storage
collabify-marketing-localeBrowser storageYour language choice on the public pages.Until you clear your browser storage
collabify.workspaceRailCollapsedBrowser storageWhether the brand workspace rail is collapsed.Until you clear your browser storage
collabify.adminRailCollapsedBrowser storageWhether the admin rail is collapsed.Until you clear your browser storage
collabify:influencer-onboarding:countryBrowser storageThe country you picked during sign-up, so you do not have to re-enter it if you break off.Until you clear your browser storage
campaignDraft_v5_createV3:<businessId>:<brandId>Browser storageThe draft of the campaign you are creating, kept locally so nothing is lost if the tab closes.Until you clear your browser storage
shopify-reconnect-banner-dismissed:<brandId>Tab storageThat you dismissed the Shopify reconnect reminder, so it does not come straight back.Until you close the tab
referralCodeBrowser storageThe invite code from the link you followed, held until you submit the sign-up form so whoever invited you can be credited.Until you clear your browser storage

5. Measurement that stores nothing on your device

We measure visits and errors, but without storing anything in your browser. The services below set neither cookies nor storage keys — they send a report when a page is shown and keep nothing on your side. There is therefore no ePrivacy consent to ask for; we list them here anyway because your IP address is processed on the server. The lawful basis is set out in the Privacy Policy.

ServicePurposeWhat is sentWhen
Vercel Web AnalyticsCounts page views so we can see which pages get used.Page URL, referrer, approximate country-level location and a technical description of the browser — to an address on our own domain, not a third-party one.In the production environment only.
Vercel Speed InsightsMeasures how fast pages load for real visitors.Page loading timings and the same technical description of the browser, to the same first-party address.In the production environment only.
SentryCaptures errors in the browser so we can fix them.The error, where in the code it happened and which page you were on. The payload is scrubbed of personal identity numbers, email addresses and keys before it is sent.Only when error reporting is switched on for the environment.
Collabify produktstatistikCounts how often features are used, in aggregate and with no link back to you.The name of the event, the page template it happened on, how long the action took, whether it succeeded, a coarse quality band for page-loading speed, and which build of the app you are on. No identifier is created, nothing is stored on your device, and two visits cannot be linked together.Always, on every page.

7. How to control it

  • In your browser: every major browser can block or clear cookies and clear stored site data. Blocking the essential cookies listed above makes it impossible to sign in to Collabify.
  • By signing out: the session cookies from signing in stop applying.
  • By deleting your account: the sign-in cookies tied to it stop working when the account is deleted.

8. Changes

We update this page whenever what we store in your browser changes. The cookie registry version at the top shows which set applies; when it changes, an earlier cookie choice no longer counts and the question is asked again.

9. Contact

Questions about this policy, or about what we store on your device, go to the data-protection address below.

Data protection
privacy@collabify.se
Company
JLRS AB
Org. no.
559484-0323
Address
c/o Mailboxes ETC, Riddargatan 3, 114 11 Stockholm

You can also complain to the Swedish Authority for Privacy Protection (IMY), the supervisory authority in Sweden.