Cookie policy
What we use
Below is the full list of cookies and trackers theStacc runs on marketing pages and in the product. Optional trackers load only after you accept them in the cookie banner.
Essential — always on
These cookies are required for the site and product to work. You cannot turn them off without breaking sign-in, security, or form protection.
- thestacc_session · keeps you signed in to the dashboard. Set by theStacc. First-party.
- csrf_token · protects forms from cross-site request forgery. Set by theStacc. First-party.
- stacc_cookie_consent · remembers your cookie banner choice (accept / reject). First-party. 12 months.
- __cf_bm · Cloudflare bot management. Distinguishes humans from bots and blocks abusive traffic.
- cf_clearance · Cloudflare challenge cookie. Set after you pass a security challenge.
- cf-turnstile-response · Cloudflare Turnstile bot check on form submissions (token, not a long-lived cookie).
- __stripe_mid / __stripe_sid · Stripe fraud-prevention identifiers when a payment form loads on app.thestacc.com.
Analytics — optional (consent required)
These help us understand how the marketing site is used. They load only if you click Accept all on the banner.
- Google Analytics 4 (GA4) · measurement ID
G-C068PB1SXV(or the ID configured in our build). Page views and events such as signup clicks and form leads. - Google Tag Manager (GTM) · container
GTM-NJ6NDTH8. Loads and manages marketing tags when consent is granted. - Microsoft Clarity · session heatmaps and anonymized interaction recordings for UX improvement.
- PostHog · product analytics on the dashboard (app.thestacc.com). Tracks product events with sensitive fields masked. Configured separately from marketing-site consent where required by product terms.
Marketing / advertising — optional (consent required)
- Meta Pixel (Facebook) · pixel ID configured on the marketing site. Used for PageView and Lead events to measure ads. Not loaded until you accept optional cookies.
- LinkedIn Insight Tag · only if a LinkedIn partner ID is configured. Used for B2B campaign measurement.
Preferences — optional
- thestacc_theme · colour preference (reserved).
- thestacc_sidebar · dashboard sidebar expanded/collapsed.
- thestacc_tz · time zone for scheduled posts.
- stacc_first_touch / visitor tracking keys · first-touch UTM and journey data used to attribute form leads (first-party localStorage).
How long they live
Cookies fall into two buckets.
- Session cookies disappear when you close the browser (sign-in session pieces, some security tokens).
- Persistent cookies stay for a fixed time. Consent preference: 12 months. Cloudflare clearance: ~30 minutes. Stripe mid: up to 12 months. GA4/Clarity/Meta cookies follow each vendor’s default (typically up to 13 months for analytics).
You can delete every cookie by clearing browser data. The next visit starts fresh — you will need to sign in again and re-set preferences and consent.
Your choices
You have three ways to control cookies on theStacc.
Cookie banner
The first time you visit thestacc.com you see a banner. Choose Accept all or Reject optional. Your choice is stored for 12 months. Change it anytime via Cookie settings in the footer.
Browser settings
Every browser lets you block cookies, delete cookies, or get a warning before a cookie is set:
- Chrome · Settings → Privacy and security → Third-party cookies.
- Safari · Settings → Privacy → Manage Website Data.
- Firefox · Settings → Privacy & Security → Cookies and Site Data.
- Edge · Settings → Cookies and site permissions → Manage and delete cookies.
Blocking essential cookies will break the dashboard. You will not be able to sign in.
Opt-out links
- Google Analytics · Google Analytics opt-out.
- Meta · Ad preferences and browser controls.
- Microsoft Clarity · clear site data or reject optional cookies on our banner.
- PostHog · posthog.com/opt-out.
- Cloudflare · security cookies cannot be opted out without losing access to protected pages.
- Stripe · set only when a payment form loads; required for fraud prevention during checkout.
Third parties
Each vendor has its own privacy policy:
- Google (Analytics / Tag Manager) — policies.google.com/privacy.
- Microsoft Clarity — privacy.microsoft.com.
- Meta — facebook.com/privacy/policy.
- PostHog — posthog.com/privacy.
- Cloudflare — cloudflare.com/privacypolicy.
- Stripe — stripe.com/privacy.
- Resend — transactional email for form notifications — resend.com/legal/privacy-policy.
We do not sell personal data. If we add a new optional vendor, we will update this page and re-prompt consent before that vendor’s cookies load.
Changes
We update this policy when we add a vendor, remove a vendor, or change how a cookie works. Every update lands here with a new "last updated" date at the top. If the change adds a new optional cookie, the banner will ask for your consent again before the cookie is dropped.
Contact
Questions about cookies:
- Email · hello@thestacc.com
- Postal · theStacc Software Pvt. Ltd., Jaipur, Rajasthan, India
- Data Protection Officer · hello@thestacc.com
A human will write back, usually within 24 hours.