Cookie Policy
Last updated: August 10, 2026
This page lists every cookie Plug sets, what it does, and how long it lasts, along with the browser storage we use and the third-party services that appear on our pages. It supplements our Privacy Policy. The short version: every cookie Plug sets is first-party (set by us, readable only by us), we run no advertising trackers and no third-party ad cookies, and nothing here follows you across other sites. If you are in the EU/EEA or UK, we go further and don’t set the non-essential ones at all — see section 7.
1. Essential cookies
These make the Service work — signing in, staying signed in, and protecting sensitive flows. Blocking them will break sign-in.
sb-…-auth-token (and numbered chunks, plus a -code-verifier cookie during sign-in)Set by our authentication provider (Supabase) to keep you signed in. Shared across getplug.io subdomains so the app works as one session.
Lasts: Long-lived; renewed while you use the app
plug_last_seenRecords your last activity so we can sign you out after about 14 days of inactivity — a security measure for abandoned sessions.
Lasts: The inactivity window (~14 days)
plug_oauth_state / plug_oauth_returnProtects the social-platform connect flow (YouTube, TikTok, Instagram, etc.) against cross-site request forgery, and remembers where to send you back.
Lasts: 10 minutes
plug_pinterest_oauth_state / plug_pinterest_oauth_returnThe same protection for the Pinterest connect flow.
Lasts: 10 minutes
pro_connect_stateThe same protection for the Stripe payout-account connect flow.
Lasts: 10 minutes
plug_handle_holdHolds the handle you claimed on the homepage or during signup (a random token) so it's still yours after the sign-in round-trip.
Lasts: 30 minutes
Plug staff accounts use an additional security cookie (plug_admin_key, 30 days) that gates the internal admin panel; it is never set for regular users.
2. Functional cookies
These remember small choices so the product behaves the way you left it.
sp_… (one per share link)Remembers that a brand unlocked a PIN-protected share link so it doesn't re-enter the PIN on every page. Contains a signed marker, not the PIN.
Lasts: 30 days
plug:dealsViewRemembers your pipeline layout choice (cards, list, or board).
Lasts: 1 year
pv_… / lv_… / iv_… (one per page or link)View-count de-duplication on public pitch pages, plugd.cc links, and shared deal/invoice links, so refreshes aren't counted as new views. Contains no identifier — just a marker that the view was counted. Not set in the EU/EEA or UK, where we de-duplicate on our own servers instead.
Lasts: 30 minutes
plug_utm_sourceIf you arrive through a tagged link (for example a creator's link-in-bio), records that channel as a single word (like “linktree”) so we can attribute your signup to it. Nothing about you. Not set in the EU/EEA or UK.
Lasts: 30 days
plug_viaRemembers which affiliate's link brought you here so they get credit if you sign up (90 days, last link wins). Not set for EU/EEA/UK visitors.
Lasts: 90 days
3. Measurement cookies
We use one first-party measurement cookie — the only non-essential Plug cookie that contains a persistent identifier. (The sign-in cookies above necessarily identify your account, but only to keep you signed in — never for analytics.)
plug_anon_idA random identifier that lets us count signup-funnel events on our own marketing pages (for example, that a visitor tried the handle claim and later signed up). Linked to your account if you sign up. First-party only — never shared, no cross-site tracking, no advertising. Not set — and not read — in the EU/EEA or UK.
Lasts: 90 days
Our page-view analytics (Vercel Web Analytics) is cookieless — it reports aggregate page views without setting cookies or fingerprinting. Our error monitoring (Sentry) sets no cookies.
4. Third-party services on our pages
- Cloudflare Turnstile — the bot-detection challenge on signup and sign-in loads from Cloudflare and may set its own cookies in Cloudflare’s context for that check.
- Google Fonts — some public storefront and pitch-page themes load a display font from Google’s font CDN (no cookies, but Google receives the visitor’s IP address). The Plug app itself serves its fonts from our own servers.
- OpenStreetMap — the brand-directory map loads its map imagery from OpenStreetMap’s tile servers, which receive your IP address and the map area you view.
5. Browser storage (localStorage and sessionStorage)
Besides cookies, we use your browser’s own storage for small things that mostly stay on your device: interface preferences and dismissed banners, in-progress drafts (like onboarding answers), and — if you followed a creator’s invite link — the invite code from that link, which is sent to us and attached to your account if you sign up, so the person who invited you gets credited. Our free public deal tracker tool stores its deal list only in your browser — we never receive it. Clearing your browser’s site data removes all of this.
6. Your choices
You can clear or block cookies and site data any time in your browser settings — per-site or globally. Blocking essential cookies will sign you out; blocking functional and measurement cookies only loses the conveniences described above. We don’t set advertising or cross-site tracking cookies, so there is no ad tracking to opt out of. Questions? Email support@getplug.io.
7. If you are in the EU/EEA or UK
You may be wondering why this site has no cookie banner. It’s because there is nothing to ask you about. EU and UK rules require your permission before a site stores anything non-essential on your device — a site’s own analytics included. Rather than put a consent pop-up in front of you, we detect that you’re visiting from the EU/EEA or UK and simply don’t set those cookies.
Concretely: the measurement cookie (plug_anon_id) and the channel-attribution cookie (plug_utm_source) are never written or read, and the view-counting markers (pv_ / lv_ / iv_) are replaced by a count kept on our own servers. What remains is only the essential and functional cookies in sections 1 and 2 — the ones that sign you in and remember a setting you chose — which don’t require consent. Detection uses the country our host infers from your IP address; if it can’t tell, you get the standard set, and either way you can clear or block everything in your browser.