Cookie Policy
Linkbase AB | Last Updated: 2026-07-12
1. Introduction
This Cookie Policy describes how Linkbase AB ("Linkbase", "we", "us", or "our") uses cookies and similar browser storage on our marketing website at linkbase.se (the "Website") and in the Linkbase application at dashboard.linkbase.se (the "Application").
Cookies are small text files stored in your browser by websites you visit. Browsers also offer similar storage — localStorage (kept until deleted) and sessionStorage (deleted when the tab closes) — that websites can use for the same kinds of purposes. For transparency, this policy covers all of these and lists every item we actually set, by name.
2. No analytics, no marketing — and no consent banner
Neither the Website nor the Application uses analytics cookies, marketing or advertising cookies, or any third-party tracking. Everything listed in this policy is either strictly necessary (required for the service you are asking for, such as staying signed in or paying securely) or functional (remembers a choice you made, such as your theme or a trusted device).
Under the Swedish Electronic Communications Act (lagen [2022:482] om elektronisk kommunikation) and the EU ePrivacy rules, consent is required only for cookies and storage that are not necessary for providing the service the user has requested. Because we use no such cookies, we do not show a cookie consent banner — there is nothing to consent to. If we ever introduce analytics or marketing cookies, we will implement a consent solution where declining is as easy as accepting before any such cookie is set, and update this policy.
3. Cookies on the marketing website
The Website sets no cookies and uses no browser storage. It loads no analytics, embeds no third-party content, and serves its fonts from our own domain. The only possible exception is a strictly necessary security cookie from our hosting provider, described in Section 6.
4. Cookies in the application
The Application sets the following cookies. Names starting with __Secure- are the production names; they can only be sent over encrypted (HTTPS) connections.
| Name | Set by | Purpose | Lifetime | Category |
|---|---|---|---|---|
| __Secure-better-auth.session_token | Linkbase (sign-in) | Keeps you signed in to your account | 7 days, renewed while you use the Service | Strictly necessary |
| __Secure-better-auth.two_factor | Linkbase (sign-in) | Holds your pending sign-in while you complete two-factor authentication | 10 minutes | Strictly necessary |
| __Secure-better-auth.trust_device | Linkbase (sign-in) | Remembers a device you chose to trust so two-factor authentication is not asked for again on that device | 30 days | Functional |
| __Secure-better-auth.last_used_login_method | Linkbase (sign-in) | Highlights the sign-in method you used last time on the sign-in page | 30 days | Functional |
| sidebar_state | Linkbase (interface) | Remembers whether you keep the navigation sidebar open or collapsed | 7 days | Functional |
| __stripe_mid | Stripe (payment pages only) | Payment fraud detection and prevention when you enter card details | 1 year | Strictly necessary |
| __stripe_sid | Stripe (payment pages only) | Payment fraud detection and prevention when you enter card details | 30 minutes | Strictly necessary |
The two __stripe cookies are set by Stripe, our payment processor, and only on the pages where you enter card details. They exist to detect and prevent payment fraud and are described in Stripe's privacy documentation.
5. Browser storage in the application
The Application stores the following preferences in localStorage. These values stay on your device and are never transmitted to us.
| Name | Set by | Purpose | Lifetime | Category |
|---|---|---|---|---|
| linkbase-webapp-theme | Linkbase (interface) | Your light/dark theme preference | Until you delete it | Functional |
| automation-runs-column-visibility:v3 | Linkbase (interface) | Which columns you chose to show in the automation-runs table | Until you delete it | Functional |
| usage-history-column-visibility:v1 | Linkbase (interface) | Which columns you chose to show in the usage-history table | Until you delete it | Functional |
| shopify-orders-column-visibility:v4 | Linkbase (interface) | Which columns you chose to show in the Shopify orders table | Until you delete it | Functional |
The following is kept in sessionStorage and is deleted automatically when you close the tab.
| Name | Set by | Purpose | Lifetime | Category |
|---|---|---|---|---|
| linkbase:chunk-load-reload-attempted | Linkbase (interface) | Prevents a reload loop when a new version of the application is deployed while you have it open | Until the tab closes | Strictly necessary |
| reactivate-company:<company id>:selected-integrations | Linkbase (interface) | Remembers which integrations you selected while completing the subscription reactivation flow | Until the tab closes | Functional |
| sentryReplaySession | Sentry (error monitoring) | Keeps an error-diagnostics session together across page navigations so we can debug technical problems; recordings are masked and contain no readable text or input values | Until the tab closes | Functional |
6. Third-party services
A small number of third-party services run in the Application for security, payments, and error monitoring. None of them is used for advertising or cross-site tracking:
- Cloudflare Turnstile (challenges.cloudflare.com) verifies that sign-up and sign-in attempts come from a human. It sets no cookies on Linkbase domains.
- Stripe (js.stripe.com) is loaded only on pages where you enter card details and sets the two fraud-prevention cookies listed in Section 4. If you proceed to Stripe's hosted checkout at checkout.stripe.com, Stripe's own cookie policy applies on that domain.
- Sentry receives error and performance reports from the Application (via Sentry's EU ingest endpoint) so we can find and fix technical problems. It sets no cookies; its only browser footprint is the masked diagnostics key listed in Section 5.
- Sign in with Google or Microsoft redirects you to those providers' own sign-in pages, where their cookies and policies apply on their domains.
- Cloudflare hosts both the Website and the Application and may set strictly necessary security cookies (such as __cf_bm) when its protection against malicious traffic is active.
7. Managing cookies
You can delete or block cookies and browser storage at any time through your browser settings; browsers also let you clear everything a specific site has stored. Because the Application only sets what is listed above, the practical effect of blocking is limited: without the strictly necessary cookies you cannot stay signed in or complete card payments, and without the functional entries the Application simply forgets your preferences.
8. Changes to this policy
When the cookies or storage we use change, we update the tables above and the date at the top of this page. A change that would introduce analytics or marketing cookies is a material change: as described in Section 2, it would be preceded by a consent solution and, where appropriate, notice by email.
9. Contact
Questions about this policy or our data practices? See our Privacy Policy or contact us:
Linkbase AB
Email: privacy@linkbase.se
Website: https://linkbase.se
Last updated 2026-07-12