Cookie Policy
This page lists every cookie and similar storage mechanism CorriDraw uses, what it is for, how long it lasts, and how to opt out. It is a companion to our Privacy Policy.
Cookies we set
| Name | Purpose | Lifetime | Category | Party |
|---|---|---|---|---|
| cd_session | Keeps you signed in. Carries a signed reference to your session, never the password. | 30 days, sliding | Strictly necessary | First party |
| cd_csrf | Anti-CSRF token paired with the session cookie to block forged requests. | Session | Strictly necessary | First party |
| cd_workspace | Remembers the workspace you last opened so the dashboard reopens where you left off. | 180 days | Functional | First party |
| cd_theme | Stores your light/dark/system theme choice so the editor doesn’t flash on load. | 1 year | Functional | First party |
| cd_consent | Records your cookie-banner choices so we don’t ask again every page load. | 1 year | Strictly necessary | First party |
| sa_user, sa_session | Privacy-respecting page-view analytics from Simple Analytics. No personally identifying data is collected. | Session | Analytics | Third party (Simple Analytics) |
| _ga, _ga_* | Google Analytics, set only after you accept analytics in the cookie banner. Used to understand which features get used. | Up to 2 years | Analytics (opt-in) | Third party (Google) |
1. What are cookies?
Cookies are small text files a website places on your device to remember things between page loads. We also use related technologies — localStorage, sessionStorage, and IndexedDB — for things that do not need to round-trip to the server (UI preferences, draft autosaves, offline boards). For brevity we call all of them “cookies” on this page.
2. Categories
- Strictly necessary. Required for the service to work at all — sign-in, security, and remembering your cookie choices. These cannot be turned off.
- Functional. Remember your preferences (theme, last workspace, sidebar collapse state) so the app feels personal.
- Analytics. Help us understand which features are used so we know where to invest. Off by default until you accept them in the cookie banner.
- Marketing. We do not currently use any.
3. How to control cookies
The first time you visit corridraw.com you will see a cookie banner where you can accept analytics or stick with strictly-necessary only. You can change your mind at any time:
- Open Account → Privacy and toggle “Allow analytics cookies.”
- Or click the small “Cookies” link in the bottom-right of any page to reopen the banner.
- Most browsers also let you block or delete cookies from their settings; doing so may sign you out and disable some features.
We honour the Global Privacy Control signal: if your browser sends GPC, we treat it as an opt-out of analytics cookies for that session.
4. Do Not Track
There is no industry consensus on how to interpret the legacy DNT header, so we do not act on it directly — we honour Global Privacy Control instead.
5. Third-party cookies
CorriDraw uses third-party cookies only for analytics, and only after you opt in. The third parties listed in the table above act as data processors on our behalf and are bound by their own privacy commitments, which we have reviewed.
6. Updates
When we add or remove a cookie we update this page and bump the “Last updated” date at the top. If we add a new analytics or marketing cookie we will also re-prompt you for consent.
7. Contact
Cookie questions: privacy@corridraw.com