Cookie Policy

Last updated: 17 July 2026

1. The short version

We only use cookies that are essential for the service to work - signing you in, keeping anonymous chats connected to your browser, and protecting forms against forgery. We do not use advertising or third-party analytics cookies.

2. The cookies we set

Cookie Purpose Lifetime
_support_session Keeps you signed in and secures forms (CSRF protection). It also holds the session identifier that connects an anonymous chat to your browser so you can continue the conversation. This cookie is shared across our subdomains so that signing in on the main site also signs you in on an organisation's support portal. Session
remember_user_token Set only if you tick "remember me" when signing in, so you stay signed in between visits. Up to 2 weeks

3. Third parties

If you sign in through your organisation's single sign-on provider (Google, Microsoft, Okta or another OpenID Connect service), that provider sets its own cookies on its own domain during sign-in, governed by its own policy. Likewise, if you purchase a subscription, the checkout happens on Stripe's pages and Stripe sets its own cookies there. We set no advertising or tracking cookies anywhere.

4. Controlling cookies

You can delete or block cookies in your browser settings. Because every cookie we set is essential, blocking them means you will not be able to stay signed in, and anonymous chats will not survive a page reload.

5. Questions

Anything unclear? Email us at support@handover.support.