avut.io
Pricing
Sign inStart for free
Start for free

Legal

Cookie Policy

This policy explains the current use of cookies and browser storage in Avut PIM.

Last updated: August 15, 2026

What this policy covers

This policy explains how Avut PIM uses cookies and other technologies that store information in, or access information from, a user’s browser or device, including local storage and session storage.

Current cookie and storage use

Avut PIM uses cookies and browser storage that are strictly necessary to provide the service requested by the user, including sign-in, security, session continuity, organization routing in a multi-tenant environment, user-selected preferences such as language or theme, temporary application state needed to complete requested actions, and limited browser-side state for supported login, integration, or workflow flows.

Avut also uses privacy-minimized first-party analytics and may enable server-side PostHog product analytics to understand landing-page conversion, workspace activation, core capability adoption, retention, and categorized workflow friction. This analytics does not set or read an analytics cookie or analytics browser-storage identifier. Avut does not enable PostHog browser autocapture, session replay, heatmaps, advertising trackers, or cross-site tracking.

Authentication and security technologies

Avut PIM uses Clerk for authentication and session management. Clerk sets cookies or similar storage that are required for sign-in, maintaining an authenticated session, and protecting access to the service. These technologies are necessary for the service, and disabling them may prevent sign-in or continued use of authenticated areas.

Avut PIM also uses Cloudflare-related security services for abuse prevention and protected flows, including Cloudflare Turnstile where enabled. Depending on the active production configuration, Cloudflare may set strictly necessary security cookies or similar storage for bot protection, challenge handling, rate limiting, or abuse prevention. Whether these technologies are set, their names, and their duration depend on the active configuration.

Billing-related pages

Avut currently uses Stripe-hosted Checkout Sessions for subscription purchases and Stripe Customer Portal for subscription self-service. If a user is redirected to a Stripe-hosted checkout or billing page, Stripe may use its own strictly necessary cookies or similar storage on that page under Stripe’s own documentation and policies.

Cookie and storage inventory

The current inventory is generally as follows:

  • Clerk authentication cookies or similar storage: used for sign-in, session continuity, and access protection;
  • Cloudflare security cookies or similar storage: used for bot protection, abuse prevention, challenge handling, rate limiting, and delivery security where enabled;
  • Avut local storage: used to remember user-selected preferences such as language, theme, and interface layout;
  • Avut session storage: used for temporary routing, form state, workflow state, and other temporary information needed while the current browser tab or session is active.
  • Avut first-party analytics requests: cookieless event requests used for aggregate launch and product-funnel reporting. Monthly rotating pseudonymous identifiers are calculated on the server and raw IP addresses are not stored in the analytics table.
  • PostHog product analytics, when enabled: Avut's server sends confirmed allowlisted domain outcomes with HMAC-pseudonymous user and workspace identifiers and coarse categories. The PostHog browser SDK is not loaded and no PostHog cookie or browser-storage identifier is used.

Where third-party providers set their own cookies or similar storage, the exact names and durations may vary by configuration, browser behavior, and provider updates.

Preferences and local storage

Avut PIM may store user-selected interface preferences in browser storage, such as theme, language, and saved layout choices. Local storage is used for preferences that should remain available after the current session unless browser data is cleared. Session storage is used for temporary information needed while the current browser tab or session is active.

Clearing browser data may reset these preferences and may also interrupt sign-in, security checks, or other core parts of the service.

Consent

Avut does not currently display a consent banner for this analytics because it does not store information in, or access information from, the user's browser or device beyond the ordinary request to Avut. The resulting personal-data processing remains subject to the Privacy Policy, and Avut relies on its legitimate interests in limited internal measurement of acquisition and service adoption. Avut does not record an analytics event when the browser sends an enabled Global Privacy Control or Do Not Track signal. Individuals may also object by contacting Avut. Where applicable law, regulator guidance, or a future implementation requires consent, Avut will obtain that consent before enabling the relevant technology.

If Avut later introduces cookie-based analytics, marketing, or other non-essential browser technologies, they will not be enabled until any required consent has been obtained. Rejecting or withdrawing optional consent will be as easy as granting it.

MCP functionality does not currently introduce any identified separate non-essential browser cookies or tracking requirements.

Changes

Avut will update this policy before any cookie-based analytics, marketing, or other non-essential cookies or similar technologies are introduced in production. Avut will also review this inventory when authentication, security, billing, or analytics configurations change.

Related privacy information

For more information about how Avut processes personal data related to these technologies, including legal basis, recipients, transfers, and rights, please see Avut’s Privacy Policy and public provider register at https://avut.io/privacy/subprocessors

If you have questions about this Cookie Policy, contact admin@avut.io.

Avut PIM is developed and operated by Norleaf AS

Norwegian organisation number 938 103 984 · Bryne, Norway

AboutPartnersPrivacyTermsCookiesDPASubprocessorsPrivacy request