Cookie Policy
How AssetStacc uses cookies and similar browser storage across the public website, the SaaS platform, the customer portal, the technician portal and the demo workspace.
Categories
Strictly necessary (always active) — Keeps the site working: routing, load balancing, form submission protection and remembering this cookie choice. Cannot be switched off.
Security and authentication (always active) — Signs you in and keeps that session safe — session tokens, cross-site request forgery protection and abuse/rate-limit signals. Only set once you sign in or submit a protected form.
Functional (off until you allow it) — Remembers preferences you set inside the app — theme, navigation layout, saved filters and dashboard tile order. Turning this off does not sign you out; the app just forgets those preferences.
Analytics and performance (off until you allow it) — Aggregated usage measurement so we can see which pages and workflows fail or stall. No analytics tag is loaded until you allow this category.
Marketing and advertising (off until you allow it) — Measures whether an ad or campaign led to a service request. Nothing in this category loads unless you allow it, and we do not sell or share personal information for cross-context behavioural advertising.
Cookie inventory
| Cookie | Provider | Category | Purpose | Duration | Security |
|---|---|---|---|---|---|
| sb-<project>-auth-token | AssetStacc (Lovable Cloud auth) | Security and authentication | Keeps you signed in and identifies your workspace on every request. | 1 hour access token, refreshed until sign-out or inactivity expiry | Secure, SameSite=Lax, first-party, cleared on sign-out |
| __Host-csrf / TanStack CSRF token | AssetStacc | Strictly necessary | Blocks cross-site request forgery against server functions and forms. | Session | Secure, HttpOnly, SameSite=Lax, Path=/ |
| as_cookie_consent | AssetStacc | Strictly necessary | Stores your cookie choices so they can be enforced everywhere. | 12 months | Secure, SameSite=Lax, Path=/, no personal data |
| assetstacc.theme / nav / tile preferences | AssetStacc | Functional | Remembers theme, navigation layout and dashboard tile order. | Until cleared | First-party browser storage, no identifiers shared with third parties |
| _ga / _ga_* (only after consent) | Google Analytics | Analytics and performance | Aggregated page and workflow performance measurement. | Up to 24 months | Secure, SameSite=Lax — not loaded unless analytics consent is given |
| Google Ads conversion cookies (only after consent) | Marketing and advertising | Attributes a mobile-service request to the campaign that produced it. | Up to 24 months | Secure, SameSite=None — not loaded unless advertising consent is given | |
| Square payment session cookies | Square (payment processor) | Strictly necessary | Set only on the hosted payment step to process a card payment and prevent payment fraud. AssetStacc never stores card data. | Payment session | Secure, HttpOnly, set by Square on their domain |
Your choices
Use the Cookie Preferences link in the footer of any page to change or withdraw your consent at any time. Withdrawing consent stops future optional cookies immediately.
California residents: AssetStacc does not sell personal information and does not share it for cross-context behavioural advertising. Rejecting the advertising category also acts as your “Do Not Sell or Share My Personal Information” signal, and we honour Global Privacy Control browser signals where they are sent.
Privacy requests: use the privacy request form to access, correct, export or delete your personal information, or email info@assetstacc.com. Every request gets a written answer within 45 days.
