1. Scope
This Cookie Notice applies to Cardberry websites, applications, and related services that link to it (collectively, the “Services”). It should be read with our Privacy Policy and Terms of Use.
Necessary technology only. As of the effective date, Cardberry does not use advertising cookies, analytics cookies, cross-site behavioral tracking, social-media pixels, or session-replay technology. The public marketing site does not set Cardberry cookies.
3. Technology we use
Account and security cookies
The merchant application uses first-party, necessary cookies to create and maintain authenticated sessions, remember whether a session should persist, prevent misuse, and support secure account actions. These cookies are host-only and are not used to track you across unrelated sites.
Cloudflare Turnstile
Account creation, sign-in, and password-recovery forms use Cloudflare Turnstile to distinguish legitimate requests from automated abuse. Turnstile may process request, browser, device, and interaction information and may use necessary cookies or similar storage. Cloudflare handles that information under its Privacy Policy.
Shopify connection state
When an authorized merchant connects Shopify, Cardberry sets a short-lived, first-party security cookie that binds the connection callback to the browser and account that started it. It expires after approximately 10 minutes and is cleared when the callback completes.
Authorized support sessions
If a Cardberry platform operator starts an authorized support session at a merchant’s request or for legitimate support and security purposes, a necessary first-party cookie may preserve the merchant’s prior session so it can be restored when support ends. It is not used for advertising or cross-site tracking.
4. Browser storage
Theme preference
Cardberry stores your light or dark theme choice in local storage under a Cardberry-specific key. This preference remains until you change it or clear local site data.
Active workflow state
The merchant application uses session storage to remember the identifier and status of an active import or Shopify sync while you move between application pages or reload a tab. This data is limited to workflow state and is cleared as the task completes, when Cardberry no longer needs it, or when the browser clears the tab’s session storage.
5. Duration and providers
Necessary cookies last only as long as required for their function. Some expire with the browser session, some expire within minutes after a security flow, and an authenticated session may persist for the period selected or configured for that account. Cardberry may adjust exact cookie names and durations as security and service behavior evolve without changing the purposes described here.
Cardberry’s hosting and security providers may process ordinary network request logs. Request logs are not cookies, but related information is described in our Privacy Policy.
6. Your choices
Most browsers let you view, delete, or block cookies and clear local or session storage. Browser controls vary by provider and device. Blocking necessary cookies or storage may prevent you from signing in, connecting Shopify, restoring a support session, remembering a preference, or completing an active workflow.
Because Cardberry does not sell or share personal information for cross-context behavioral advertising and does not use advertising cookies, we do not currently respond differently to Do Not Track or Global Privacy Control signals. If we introduce optional cookies or tracking, we will update this notice and provide consent or opt-out controls where applicable law requires them.
7. Changes and contact
We may update this notice when the technology used by the Services changes. We will post the updated notice here, revise the effective date, and provide additional notice or choices where required.
Questions about this notice can be sent to Cardberry at privacy@cardberry.ai.