Privacy & cookies
Coaptive ships a Privacy page at /legal/privacy. Visitors reach it from the Legal page. The cookie banner’s default policy link is the same path.
You cannot edit, duplicate, or delete it, and the slug stays privacy so that address keeps working. Legal is locked the same way; Hide on that row only controls the footer link.
Cookies the software sets
The session cookie is an id. Names, email, and records stay on the server.
| Cookie | When | What it contains |
|---|---|---|
{app}-session | Every visit that starts a session | Encrypted session id. On Coaptive Core the name is coaptive-core-session (this host only, 24 hours idle). On Coaptive GME it is coaptive-session (shared with .coaptive.dev). |
XSRF-TOKEN | With the session | Encrypted form-protection token. It does not identify the visitor. |
remember_web_59ba36addc2b2f9401580f014c7f58ea4e30989d | Remember me on login | Encrypted user id, remember token, and a hash of the password hash. Lasts 400 days. |
coaptive_locale | CMS language switcher only | A language code. Not set on GME. Lasts 1 year. |
coaptive_consent | After the visitor answers the cookie banner | Whether analytics and marketing were allowed. Lasts 1 year. Written only when the banner is enabled. |
Banner and analytics
Tools → Privacy & Consent turns the banner on, sets the policy URL, and enables Google Consent Mode v2 when Google Analytics or Tag Manager is on. Settings live in storage/app/private/privacy-settings.json.
System → Analytics can add Google Analytics 4, Tag Manager, Hotjar, Microsoft Clarity, Meta Pixel, PostHog, Matomo, Umami, Plausible, or Fathom. Those tools are off until you enable them. With the banner on, non-Google tags stay blocked until the visitor accepts analytics or marketing.
Not cookies
Appearance (coaptive.color_mode) and the accessibility widget (coaptive.a11y) use this browser’s local storage.