This page lists every cookie and browser storage key Decolinker uses, what each one is for, and how long it lasts. It supplements our Privacy Policy, which covers personal data more broadly.
In plain terms: We run no analytics, no advertising pixels and no cross-site tracking. Everything below is either needed to sign you in and keep the site secure, or is the single cookie that credits the creator whose link brought you here.
1. What we do not do
Decolinker has no Google Analytics, no Google Tag Manager, no Meta or TikTok pixel, no advertising network and no cross-site behavioural profiling. We do not sell or share personal data with data brokers. If you visit our public pages without signing in and without arriving through a tracking link, your browser receives no cookies from us at all.
2. Cookies that need your consent
One purpose falls into this category: attributing a sale to the creator who referred it. It is not strictly necessary, because the site and the merchant store both work without it. The people it benefits are the merchant, the creator and us, so in the EU, the EEA and the UK we ask first and set nothing until you agree.
Attribution
- _attr — set on our link domain when you click a tracking link. Stores only an internal reference to that link. Lasts up to 30 days; your browser may expire it sooner, and Safari and some iOS browsers typically cap it near seven days.
- _atk — the same reference, stored on the merchant own store rather than on our site, as both a cookie and a local storage entry. Also up to 30 days. On Shopify stores this is set only when the store own consent settings permit it. On other platforms the merchant own cookie banner governs it.
- _atk_bc_synced and _atk_wix_synced — local storage entries on a merchant store that stop the same click being reported twice. No independent purpose.
If you decline, none of these are set and no sale is credited to a creator. Nothing else about the site changes.
3. Cookies that are strictly necessary
These do not require consent because the service you asked for cannot work without them. They are set only when you sign in, begin a sign-in, or connect a store.
Signing in and staying signed in
- authjs.session-token (__Secure-authjs.session-token over HTTPS) — keeps you signed in. Up to 30 days.
- authjs.csrf-token (__Host- prefixed over HTTPS) — protects sign-in forms against cross-site request forgery. Expires when you close your browser.
- authjs.callback-url — remembers which page to return you to after sign-in. Expires when you close your browser.
- authjs.pkce.code_verifier, authjs.state and authjs.nonce — security values used only during a Google sign-in. 15 minutes or less.
Choosing an account type and connecting a store
- decolinker_pending_oauth_role — remembers whether you chose merchant or affiliate while you are away at Google. 10 minutes.
- decolinker_shopify_state and decolinker_oauth_state_<platform> — security values that verify a store connection came back from the platform we sent you to. 10 minutes.
- decolinker_pending_shopify_shop — carries the store address from a Shopify App Store install through signup so the install can be matched to your new account. 30 minutes.
Remembering your choice
- dl_consent — records whether you accepted or declined the attribution cookie, so we do not ask again on every page. Stores only the word granted or denied. Lasts 180 days.
4. Why you may be asked more than once
Our tracking links use a different domain from our main site, and a browser deliberately keeps the two separate. A choice you make on one is not readable on the other, so you may see the banner again. We could avoid this only by using a third-party cookie that follows you between domains, which is exactly the kind of tracking this policy exists to say we do not do.
5. Third parties that can set cookies
Stripe sets its own cookies for fraud prevention, but only on the billing page inside a merchant dashboard, never on our public pages. Stripe use of them is covered by the Stripe privacy policy.
Shopify loads its own App Bridge library inside the Decolinker app in the Shopify admin. That surface is for merchants inside Shopify and is governed by Shopify own policies.
Sentry records application errors so we can fix crashes. It sets no cookie, records no session replay, and its reports are routed through our own domain rather than sent directly to Sentry from your browser.
6. Changing your mind
You can clear cookies for this site at any time in your browser settings, which resets your choice and makes the banner appear again. You can also block cookies entirely; sign-in will stop working, but the public pages will not.
7. Contact
Questions about this policy can go to our contact page. Decolinker LLC, 30 N Gould St Ste R, Sheridan, WY 82801, United States.