Cookie Policy
Last updated: August 8, 2026
1. What we set
| Name | Type | Purpose | Duration |
|---|---|---|---|
cab_vid | First-party analytics cookie | Random visitor ID so we can count unique visits to our public pages. Not linked to ad networks. | 12 months |
cab_sid | Session storage | Per-session ID for first-party analytics. | Until tab closes |
cab_utm | First-party cookie | Remembers which campaign link first brought you here (UTM parameters and the page you landed on), for first-touch attribution. | 90 days |
cab_utm_last | First-party cookie | Remembers the most recent campaign link you arrived through, so a return visit is credited separately from your first one. | 90 days |
cab_attr_pending, cab_attr_pending_last | Session storage | Holds which campaign links you arrived through while you decide on this notice (the first and the most recent), so accepting on a later page still credits the right one. Contains no identifier, never leaves your browser, and is discarded if you decline. | Until tab closes |
cab_variant_pending | Session storage | Remembers which version of a campaign page’s headline you were shown while you decide on this notice, so you keep seeing the same one. A single letter, no identifier, never leaves your browser, and discarded if you decline. | Until tab closes |
cab_consent | First-party cookie | Remembers your choice on the analytics notice server-side, so the site can honor it without JavaScript. | 12 months |
cab_consent_v1 | Local storage | Client-side mirror of the same analytics choice. | Until cleared |
cabana_demo_tour_v2 | Local storage | Remembers your progress through the demo checklist so a refresh doesn't restart it. | Until cleared |
demo_access | Essential cookie | Keeps the CRM demo unlocked after you request access. | 14 days |
ugc_creator | Essential cookie | Keeps you signed in to your dashboard. | Session |
cabana_admin | Essential cookie | Keeps the site owner signed in to the admin area. | Session |
2. Cookies a creator adds to their own page
Creators can put their own Meta, TikTok, or Google Analytics measurement id on the public page and media kit we host for them. We load that creator’schosen scripts on those pages, and only once you accept the notice - they set those companies’ cookies and report the visit to them directly, under their cookie policies rather than ours. One caveat we cannot fix from our side: these are the creator’s own tags running in your browser, and if their Google Analytics is set to follow in-page navigation, their tag can keep seeing pages you open afterwards in the same tab until you reload. We address every event we send to the creator whose page you are on; that setting lives in their analytics account, not in our code. Which services run therefore differs from creator to creator, so the table above cannot list them; the choice of whether to use any is the creator’s. Declining the notice stops all of them loading.
3. Your choices
Essential cookies are required for signing in and the demo to work. Analytics is optional: choose “Decline analytics” in the notice shown on your first visit and we won’t set cab_vid or record pageview/click events from your browser. Declining does not stop Plausible, where it is enabled, because it sets no cookie and holds nothing about you to decline. What it receives is the address of the public page you viewed, plus any campaign tags in the link you followed (utm_*, and the click ids ad networks append to their own links) so a visit can be credited to the ad that brought it. Everything else in the address is stripped before it is sent, and pages whose address is itself private are never reported. You can also clear or block cookies in your browser settings at any time.
Payment pages served by Stripe set Stripe’s own cookies under Stripe’s cookie policy.
More on how we handle data generally is in our Privacy Policy.