Cookie Policy
The short version. Porter sets no cookies of its own, anywhere. There is no analytics, no advertising pixel, no session replay, and no third-party script of any kind on the pages you are reading. That is why you were not shown a consent banner: consent is owed for storage that is not strictly necessary, and there is none here to consent to. The signed-in dashboard and the chat widget do store a few things in your browser, and the signup page loads Stripe to take payment — all of it required to make the thing you asked for work. This page lists every one of them by name, including the ones we would rather not have to mention.
1. Cookies, and what we actually use
A cookie is a small file a website asks your browser to keep and send back
on every later request. Related technologies — localStorage,
sessionStorage, pixels, fingerprinting scripts — do similar
jobs by different means, and the law that matters here treats them the same
way. So this page covers all of them rather than only cookies.
Porter sets no HTTP cookies of its own anywhere. Not on
this website, not in the dashboard, not in the widget. The only cookies that
can appear are Stripe’s, on the signup page, and
section 5 explains why. That is not an accident of
scale: the
dashboard signs you in with a token held in localStorage and sent
in a request header, specifically because the dashboard and our identity
provider are different origins and browsers increasingly refuse cookies in
that position.
2. What these pages store
Nothing. The public pages — the home page, Features, Contact, this page, and the other policy pages — write nothing to your browser and load nothing from anyone else’s server. There is no Google Analytics, no Google Tag Manager, no Meta pixel, no LinkedIn Insight tag, no Hotjar, and no error-reporting agent.
Typefaces used to be the exception. They were loaded from Google’s font CDN, which meant your IP address reached Google before the first word appeared. They are now served from our own servers, so that no longer happens.
One page genuinely is different, and it would be easy to leave it out of a page like this: the signup page, where you enter card details. Section 5 covers it on its own.
3. What the dashboard stores
These are written only after you sign in at /admin, and only in the browser you signed in with. All of them are strictly necessary: three keep you signed in and pointed at the right account, and one remembers a panel you collapsed.
| Name | What it holds | Why | Kept until |
|---|---|---|---|
afchat:admin-token |
Your short-lived sign-in token | Proves who you are on each request, so you are not asked to sign in again on every click | You sign out |
afchat:appwrite-session |
Your identity-provider session | Lets a new token be issued without a fresh password prompt | You sign out |
afchat:admin-site |
Which of your sites you were last looking at | Keeps you on the same account when you come back, if you manage more than one | You sign out |
porter.setup.collapsed |
0 or 1 |
Remembers that you collapsed the setup checklist, so it stays closed | You clear your browser data |
4. What the widget stores
The Porter widget runs on our customers’ websites, not on this one. If you are a renter who met Porter on a letting agent’s site, this is the section for you — and that agent, not Porter, is the one who decides what happens to your data. Their privacy policy governs it; ours explains our part in section 2.
| Name | What it holds | Why | Kept until |
|---|---|---|---|
afchat:token: |
Your sign-in token, if you signed in to see your own tenancy | Without it, nobody can be shown their own lease, balance, or work orders at all | You sign out |
afchat:convo: |
The id of the conversation you are in | Keeps one conversation continuous instead of restarting it on every message | You close the tab |
afchat:lang: |
The language you picked | Answers you in the language you chose, rather than asking again | You clear your browser data |
None of these track you. They are scoped to the one site the widget is embedded on, they are never read across sites, and they are never used to build a profile or to advertise to you.
5. The signup page
Signing up means paying, and paying means Stripe. Unlike every other page
described here, the signup page does run a third party’s
code: Stripe’s checkout form is embedded in the page rather than
hosted on a separate Stripe site, so Stripe’s script loads from
js.stripe.com and Stripe may set its own cookies and storage in
that context. Stripe uses them to process the payment and to detect fraud, and
what it does with them is governed by
Stripe’s privacy
policy.
This is not something you can meaningfully be asked to consent to separately: without it there is no way to take the payment you came to make, which puts it squarely in the strictly-necessary category. It happens only on that page, only when you choose to start a subscription, and never on the pages you browse beforehand.
Your card number is entered inside Stripe’s own form and is never sent to us or stored by us. The page itself stores one thing of ours:
| Name | What it holds | Why | Kept until |
|---|---|---|---|
porter:checkout |
The id of the checkout you started | Lets you pick up where you left off if the page reloads mid-payment, instead of starting again | You close the tab |
6. Third parties
Apart from Stripe on the signup page, no third party runs code on this website. Two others appear elsewhere in the product, and each is worth being precise about:
- Google Fonts is loaded by the widget on a customer’s site only if that customer has chosen a Google font in their brand settings, and by the dashboard to preview that choice for the person making it. It is never loaded for a visitor to this website.
- Calendly is where the “book a demo” links point. It is an ordinary link, not an embed: nothing of Calendly’s runs or is loaded until you choose to click through to their site.
7. Why there is no consent banner
Under the ePrivacy rules and the state privacy laws that follow the same logic, consent is required before storing or reading anything on your device that is not strictly necessary for a service you asked for. Analytics, advertising, and cross-site tracking all need it. Keeping you signed in does not.
Everything listed above is in the second category. There is no non-essential storage to refuse, so a banner asking you to accept or reject it would be theatre — it would suggest a choice that does not exist and train you to dismiss the ones that do. If we ever add analytics or anything that tracks you, this page changes first and a real choice appears with it.
8. Managing what is stored
You can delete everything on this page from your browser at any time, through its settings for site data. The dashboard items are also removed when you sign out, and the widget’s conversation id disappears when you close the tab. Clearing them signs you out and loses your language preference; nothing else breaks.
Because we run no advertising or analytics, there is nothing for a Global Privacy Control or Do Not Track signal to switch off. We honour them by having nothing to disable.
9. Changes
If this changes, the date at the top of the page changes with it. A change that introduced non-essential storage would also be announced in the product before it took effect, and would come with a way to say no.
10. Contact
Questions about anything here: [email protected].
[COMPANY LEGAL NAME]
[REGISTERED MAILING ADDRESS]
[email protected]
This page describes how the site and product actually behave today, and the privacy policy covers the data itself. Neither is legal advice. The bracketed values above must be filled in before launch.