Trust and legal · Version 2026-08-20
Cookie Policy
Effective 20 August 2026
Only strictly necessary storage is enabled by default.
Necessary storage
CatchMate uses a secure session cookie for up to 14 days, a short-lived OAuth transaction cookie during Google sign-in, a development email-authentication browser binding for up to one year, an authentication-device identifier used to recognise security events, a CSRF token tied to the active session, and local preferences for language, theme, accessibility, and consent state.
These items are provided by CatchMate except the Google and Stripe cookies set on their own domains when you choose those services. Necessary storage cannot be disabled through CatchMate controls because authentication and transaction security would stop working; it can be cleared in your browser, which may sign you out.
Optional categories
Analytics, personalization, advertising, and cross-site tracking require separate affirmative consent before their code or network requests load.
Your choices
You can change or withdraw optional consent without losing core account access. CatchMate treats supported Global Privacy Control signals as an opt-out request where required.
Current cookie register
Session: CatchMate, authentication and security, up to 14 days. OAuth transaction: CatchMate, sign-in integrity, normally under 10 minutes. Development email authentication: CatchMate, challenge binding, up to one year and inactive outside local development. Recognised device: CatchMate, new-device security alerts, retained until expiry or the device is forgotten.
Language, theme, accessibility, and consent preferences: CatchMate local storage, retained until you change them or clear site data. Stripe and Google may set their own necessary cookies on hosted pages under their published policies. CatchMate currently does not load advertising cookies.
Version 2026-08-20 · Effective 20 August 2026