Cookie Policy
Effective date: 7 July 2026 · Last updated: 11 August 2026
1. The short version
ZapInto uses one analytics tool and no advertising trackers. Most of what follows is strictly necessary — sign-in, security, and remembering your consent. The two non-essential cookies are ph_phc_… (PostHog analytics, EU-hosted) and zap_ref (affiliate credit), and in the EEA, UK, and Switzerland each is set only if you say yes to its category in the banner. Declining never limits the service.
2. Every cookie we use
__session (and instance-suffixed variants, e.g. __session_…)
Provider: Clerk (our sign-in provider)
Keeps you signed in — holds the authentication session token issued at login.
__client_uat (and instance-suffixed variants)
Provider: Clerk
Records the time of the last sign-in update so the app knows whether the session is fresh.
__client
Provider: Clerk (set on clerk.zapinto.com)
Identifies this browser to the sign-in service so your session can be maintained.
clerk_active_context
Provider: Clerk
Tracks which signed-in account is active during the visit.
__cf_bm
Provider: Cloudflare (protecting the sign-in service)
Bot management — distinguishes real visitors from automated traffic on the sign-in domain.
_cfuvid
Provider: Cloudflare (protecting the sign-in service)
Session consistency and rate limiting on the sign-in domain.
__clerk_db_jwt
Provider: Clerk
Development-instance session handling (not set in production).
cookieyes-consent (and cookieyes-* helpers)
Provider: CookieYes
Remembers the consent choices you made in the cookie banner.
theme
Provider: ZapInto (first-party, browser storage)
Remembers your light or dark theme choice. Pure functionality, no tracking.
zap_ref
Provider: ZapInto (first-party)
Remembers which affiliate link brought you here so that affiliate can be credited if you sign up. Set only after you consent in the EEA/UK/Switzerland.
ph_phc_…_posthog
Provider: PostHog (product analytics, EU-hosted)
Visitor and session identifiers for usage statistics and session recordings. Set only after analytics consent in the EEA/UK/Switzerland; a localStorage entry with the same name holds the rest of the state.
We also use localStorage on your device for your theme preference (light/dark). It never leaves your browser.
3. Your consent
In the EEA, UK, and Switzerland, non-essential cookies are set only after you accept them in the banner, which offers Accept and Reject with equal prominence. You can change or withdraw your consent at any time via Cookie Settings in the footer — it reopens the same banner. Your consent choice is logged by CookieYes so we can demonstrate it, as the GDPR requires.
4. More detail
How we process personal data — including the affiliate attribution that follows the zap_ref cookie — is covered in the Privacy Policy. Questions? Contact us— pick "Privacy & data requests".