Legal center

Cookie Notice

How TightLedger uses cookies, browser storage, and similar technologies.

Effective July 23, 2026Version 2026-08-04
On this page
  1. 1. Cookies and similar technologies
  2. 2. What TightLedger currently uses
  3. 3. Categories
  4. 4. Launch storage inventory
  5. 5. Consent and your controls
  6. 6. EU/EEA and UK rules
  7. 7. United States and Canada
  8. 8. Browser and device controls
  9. 9. Third-party technologies
  10. 10. Changes and contact

1. Cookies and similar technologies

Cookies are small text records placed on a device by a website. Similar technologies include local storage, session storage, software development kit identifiers, pixels, and other methods that store information on or access information from a device. This notice uses “cookies” as a convenient term for all of them.

2. What TightLedger currently uses

TightLedger currently uses strictly necessary browser storage for requested account, security, routing, and consent functions. The web application keeps access tokens only in memory, uses session storage for a non-secret per-tab account marker and short-lived provider handshakes, and uses local storage to remember the cookie choice. Session refresh uses an HTTP-only secure cookie that browser scripts cannot read. Authentication and infrastructure providers may set strictly necessary security, session, or load-balancing cookies when those production features are active.

We do not currently use analytics cookies, marketing cookies, cross-site advertising pixels, or behavioral profiling cookies. The consent interface lists those optional categories as inactive. Choosing “Accept all” does not cause an inactive technology to be installed.

3. Categories

  • Essential — always active when necessary to provide a requested feature, protect accounts, route traffic, prevent abuse, or remember privacy choices.
  • Functional — preferences that improve convenience but are not essential. No functional cookie is currently listed in the launch inventory.
  • Analytics — measurement of website or product use. TightLedger does not currently use analytics cookies.
  • Marketing — advertising, campaign attribution, or tracking across unrelated services. TightLedger does not currently use marketing cookies.

4. Launch storage inventory

  • tightledger.session — sessionStorage; stores a non-secret per-tab marker with email, sign-in time, and public account projection; it never stores the access token and expires within 24 hours or when the tab/session is closed.
  • tightledger.consent — localStorage; stores consent version, category choices, and decision time; retained until cleared, replaced by a new version, or withdrawn through Cookie settings.
  • tightledger.plaid.pending — sessionStorage; stores a Plaid connection ID, legal-entity scope, short-lived Link handle, and expiry for redirect continuity; expires within four hours.
  • tightledger.stripe.pending and tightledger.quickbooks.pending — sessionStorage; store a connection ID, opaque anti-forgery state, and timestamps for redirect continuity; expire within 30 minutes.
  • tightledger.pending-email-handshake — sessionStorage; stores the Gmail or Outlook provider, connection ID, opaque anti-forgery state, and timestamps for redirect continuity; expires within 30 minutes.
  • tightledger.pending-crm-handshake — sessionStorage; stores the Salesforce, HubSpot, or Zoho provider, connection ID, opaque anti-forgery state, and timestamps for redirect continuity; expires within 30 minutes.
  • Authentication/security cookie — provider cookie, if deployed; maintains a secure signed-in session or protects a request; session-based or for the duration documented by the active identity provider.
  • Infrastructure security/load-balancing cookie — provider cookie, if deployed; protects the service or consistently routes a request; short-lived according to the active infrastructure provider.

6. EU/EEA and UK rules

Under applicable EU ePrivacy rules and UK PECR, storing or accessing information on a device generally requires clear information and consent unless the technology is strictly necessary to provide a service the user requested or another narrow exception applies. Where consent is required, it must be freely given, specific, informed, and indicated by an unambiguous positive action.

We apply the consent control to cookies and similar browser-storage technologies, not only files named cookies. Optional technologies will not load before the required consent.

7. United States and Canada

US state privacy laws may provide rights to know about online identifiers and to opt out of certain sale, targeted advertising, sharing, or profiling. TightLedger does not currently sell cookie data or use it for cross-context behavioral advertising.

Where Canadian privacy law applies, we identify purposes, limit collection and retention, use safeguards, and obtain meaningful consent when required. Cookie choices can be withdrawn at any time, subject to technologies necessary to provide a requested service.

8. Browser and device controls

Most browsers let you block or delete cookies and site storage. Blocking essential storage may prevent sign-in, security features, or saved preferences from working. Browser signals such as Global Privacy Control will be evaluated and honored where legally required and technically applicable.

9. Third-party technologies

A provider may place a technology only for the purpose described in the current inventory and under its own privacy terms. Before enabling an optional provider, we will document its identity, purpose, data, duration, and category and update this notice and consent manager.

10. Changes and contact

We will update the version and effective date when this notice or the storage inventory changes. A material new optional use will trigger a new consent request where required.

Contact privacy@tightledger.com with questions or to exercise privacy rights. Contractual questions may be sent to legal@tightledger.com.