Back to Home
Cookies
Last updated: 7 September 2026
ShipSafe uses a small set of essential cookies. They keep you signed in and protect account actions from cross-site request forgery. By default we do not set analytics, advertising, or third-party tracking cookies.
What we set
- sessionHTTP-only cookie holding your Firebase session. Set after you sign in, valid for 5 days, then you sign in again. Cannot be read by JavaScript.
- csrf_tokenHTTP-only cookie used to verify that mutating requests (POST/PUT/PATCH/DELETE) came from this app and not a third party.
- csrf_token_clientNon-HTTP-only companion of csrf_token. The client reads it and sends the value in a request header so the server can validate the pair. It contains no personal data.
- firebase_tokenLegacy ID-token cookie name. Logout still clears it if present. New sessions use
sessiononly; do not set or accept this cookie for auth.
What we do not set (default)
- No analytics cookies (GA, Plausible, and similar)
- No advertising or retargeting cookies
- No third-party embed trackers on the marketing pages
- No cross-site tracking identifiers
Consent
Essential cookies above are required to operate sign-in and form protection, so no banner is required for them. Optional analytics are off on this site (config.cookies.nonEssentialEnabled is false). No consent banner is shown until that flag is on and gated scripts are added.
If you sign out or delete these cookies in your browser, you will need to sign in again.
Contact
Questions about cookies: support@shipsafe.st. See also our Privacy Policy and Terms of Service.