Cookie Policy
Last updated: 2026-06-26
This Cookie Policy explains how SlashHub Limited uses cookies and similar tracking technologies on our websites and applications.
1. What Are Cookies?
Cookies are small text files that websites store on your device when you visit them. They allow the site to remember your actions and preferences over time. We also use similar technologies including localStorage, sessionStorage, and IndexedDB, which function similarly to cookies and are covered by this Policy.
2. Categories of Cookies We Use
(a) Strictly Necessary — required for authentication, security (CSRF tokens, rate limiting), load balancing, and session management. These cookies cannot be disabled because the Services cannot function without them.
(b) Functional — remember your preferences (theme: dark/light, language: en/zh-HK, last-used workspace, sidebar collapsed state). Disabling these cookies will reduce the quality of your experience but the Services will still function.
(c) Analytics — anonymised usage statistics that help us understand which features are popular, where users encounter errors, and how to prioritise improvements. We use first-party analytics only; we do not share data with third-party analytics providers.
(d) Marketing — only with your explicit consent. We do not currently use marketing cookies or third-party advertising trackers; this category is reserved for future use and will be opt-in.
3. Specific Cookies We Set
(a) `refresh_token` — HttpOnly Secure cookie scoped to the parent domain. 30-day TTL. Used to issue new access tokens without re-authentication.
(b) `sso_token` — HttpOnly Secure cookie scoped to the parent domain. 30-day TTL. Rotated on every cross-product exchange. Enables Single Sign-On across SlashHub products.
(c) `slashone-csrf` — HttpOnly cookie that holds the CSRF token. 24-hour TTL. Used to prevent cross-site request forgery on state-changing endpoints.
(d) `locale` — remembers your language preference (en / zh-HK). 1-year TTL.
(e) `theme` — remembers your dark/light mode preference. 1-year TTL.
(f) `sidebar:collapsed` — remembers the sidebar state in the dashboard. 1-year TTL.
4. LocalStorage & SessionStorage
We use localStorage to store the access token (short-lived, 15 minutes) and the user profile, so that the user does not have to log in on every page load. We use sessionStorage to cache the list of linked product accounts (30 seconds TTL) for the cross-product switcher.
You can clear localStorage and sessionStorage from your browser's developer tools at any time. Clearing them will log you out of the Services.
5. Third-Party Cookies
The Services may embed content from or interact with third-party services (e.g. Stripe for payments, Firebase Auth for sign-in). These third parties may set their own cookies. We do not control these cookies; please refer to their respective cookie/privacy policies.
6. Managing Cookies
You can manage cookies in several ways: (a) use the cookie preferences banner shown on your first visit; (b) adjust your browser settings to block or delete cookies; (c) use private/incognito mode (though this will log you out on every page load).
Note that blocking strictly necessary cookies will prevent the Services from functioning (you will not be able to log in).
7. Do Not Track
Some browsers offer a "Do Not Track" (DNT) header. We respect DNT by default: when DNT is enabled, we do not set analytics or marketing cookies. Strictly necessary cookies (authentication, security) are always set regardless of DNT because the Services cannot function without them.
8. Contact
For questions about this Cookie Policy, contact privacy@slashhub.hk.