Cookie Policy
Last updated: August 5, 2026
This page lists every cookie Plug sets, what it does, and how long it lasts, along with the browser storage we use and the third-party services that appear on our pages. It supplements our Privacy Policy. The short version: every cookie Plug sets is first-party (set by us, readable only by us), we run no advertising trackers and no third-party ad cookies, and nothing here follows you across other sites.
1. Essential cookies
These make the Service work — signing in, staying signed in, and protecting sensitive flows. Blocking them will break sign-in.
sb-…-auth-token (and numbered chunks, plus a -code-verifier cookie during sign-in)Set by our authentication provider (Supabase) to keep you signed in. Shared across getplug.io subdomains so the app works as one session.
Lasts: Long-lived; renewed while you use the app
plug_last_seenRecords your last activity so we can sign you out after about 14 days of inactivity — a security measure for abandoned sessions.
Lasts: The inactivity window (~14 days)
plug_oauth_state / plug_oauth_returnProtects the social-platform connect flow (YouTube, TikTok, Instagram, etc.) against cross-site request forgery, and remembers where to send you back.
Lasts: 10 minutes
plug_pinterest_oauth_state / plug_pinterest_oauth_returnThe same protection for the Pinterest connect flow.
Lasts: 10 minutes
pro_connect_stateThe same protection for the Stripe payout-account connect flow.
Lasts: 10 minutes
plug_handle_holdHolds the handle you claimed on the homepage or during signup (a random token) so it's still yours after the sign-in round-trip.
Lasts: 30 minutes
Plug staff accounts use an additional security cookie (plug_admin_key, 30 days) that gates the internal admin panel; it is never set for regular users.
2. Functional cookies
These remember small choices so the product behaves the way you left it.
sp_… (one per share link)Remembers that a brand unlocked a PIN-protected share link so it doesn't re-enter the PIN on every page. Contains a signed marker, not the PIN.
Lasts: 30 days
plug:dealsViewRemembers your pipeline layout choice (cards, list, or board).
Lasts: 1 year
pv_… / lv_… / iv_… (one per page or link)View-count de-duplication on public pitch pages, plugd.cc links, and shared deal/invoice links, so refreshes aren't counted as new views. Contains no identifier — just a marker that the view was counted.
Lasts: 30 minutes
plug_utm_sourceIf you arrive through a tagged link (for example a creator's link-in-bio), records that channel as a single word (like “linktree”) so we can attribute your signup to it. Nothing about you.
Lasts: 30 days
3. Measurement cookies
We use one first-party measurement cookie — the only non-essential Plug cookie that contains a persistent identifier. (The sign-in cookies above necessarily identify your account, but only to keep you signed in — never for analytics.)
plug_anon_idA random identifier that lets us count signup-funnel events on our own marketing pages (for example, that a visitor tried the handle claim and later signed up). Linked to your account if you sign up. First-party only — never shared, no cross-site tracking, no advertising.
Lasts: 90 days
Our page-view analytics (Vercel Web Analytics) is cookieless — it reports aggregate page views without setting cookies or fingerprinting. Our error monitoring (Sentry) sets no cookies.
4. Third-party services on our pages
- Cloudflare Turnstile — the bot-detection challenge on signup and sign-in loads from Cloudflare and may set its own cookies in Cloudflare’s context for that check.
- Bunny video player — pages with video embed a player from mediadelivery.net, which may use its own cookies or storage for playback.
- Google Fonts — some public storefront and pitch-page themes load a display font from Google’s font CDN (no cookies, but Google receives the visitor’s IP address). The Plug app itself serves its fonts from our own servers.
- OpenStreetMap — the brand-directory map loads its map imagery from OpenStreetMap’s tile servers, which receive your IP address and the map area you view.
5. Browser storage (localStorage and sessionStorage)
Besides cookies, we use your browser’s own storage for small things that mostly stay on your device: interface preferences and dismissed banners, in-progress drafts (like onboarding answers), and signup-attribution tags (a referral or source marker that is sent to us and stamped onto your account if you sign up). Our free public deal tracker tool stores its deal list only in your browser — we never receive it. Clearing your browser’s site data removes all of this.
6. Your choices
You can clear or block cookies and site data any time in your browser settings — per-site or globally. Blocking essential cookies will sign you out; blocking functional and measurement cookies only loses the conveniences described above. We don’t set advertising or cross-site tracking cookies, so there is no ad tracking to opt out of. Questions? Email support@getplug.io.