Cookie Policy
1. Cookies and similar technologies
Cookies store information in a browser. Cove also uses local storage, scripts, pixels and server-side events to support sessions, preferences, analytics and customer-directed attribution. The technologies present depend on the page, connected features, browser restrictions and provider settings.
This Policy supplements the Privacy Policy. The current banner has an Accept acknowledgment; it does not prevent optional scripts from loading or provide Reject, preference-management or automatic GPC controls.
2. Sessions and preferences
Authentication uses NextAuth session technology, including a secure session cookie in production. Authentication flows may also use security, callback and authorization cookies. These support login, session integrity and connected-account flows.
Local storage remembers settings such as appearance, calendar view, selected calling number, import mapping, selected leads or dialer progress, and a cookie-banner acknowledgment. Local storage can persist until cleared; clearing it may reset preferences. The banner acknowledgment is not a server-side consent history or a control over other scripts.
3. Microsoft Clarity
Cove loads Microsoft Clarity for behavioral analytics and session replay. It may process pages, interactions such as clicks and scrolling, device/browser information, identifiers and session data to understand use and improve the website. Session replay reconstructs interactions; provider masking/settings affect what content is processed. Do not assume that the presence of masking removes every privacy risk.
Clarity loads before cookie-banner acceptance and is included in the application page document, rather than being limited by that acceptance. Microsoft may use information for analytics, security and advertising-related purposes under its terms. Cove does not claim that the banner blocks this processing.
Cookies documented by Microsoft include _clck and _clsk, and third-party identifiers such as CLID, ANONCHK, MR, MUID and SM. Actual storage depends on browser and provider behavior; not every visitor receives every cookie.
See Microsoft's Privacy Statement and its Clarity cookie documentation for current details.
4. Meta Pixel and server-side attribution
Hosted lead pages with a configured Meta Pixel may load Facebook's pixel script and send PageView and Lead events. Advertising identifiers such as _fbp, _fbc and a click identifier may be used for matching and attribution. The current banner does not gate these scripts.
Where enabled, Meta Conversions API sends events from Cove's servers. Events may include hashed contact identifiers, IP/browser information, campaign identifiers and lead outcomes. Blocking browser cookies alone may not stop server-side events. See the Privacy Policy for the associated data and purposes.
Meta's handling is also described in the Meta Privacy Policy. We do not describe this as anonymous information simply because identifiers are hashed.
5. Affiliate attribution and other providers
When a referral code is present, Cove stores affiliate_code in local storage and a first- party cookie with an approximately 30-day lifetime. This attributes referrals and supports the affiliate program. Local storage may remain after the cookie expires. This storage is not currently conditioned on the banner acknowledgment.
Payment and connected identity services may use their own session, security and fraud- prevention technologies when you interact with them. Customer email providers may report delivery, opens and clicks when configured. Their behavior and retention depend on the relevant provider and account settings; this Policy does not assert that every optional tracker is active.
6. Available choices and limitations
Your browser can block or clear cookies and local storage or restrict scripts, although that may affect login, saved preferences, payments or integrations. Provider privacy tools may offer additional choices. Browser settings are not necessarily a complete opt-out of server-side or other processing.
Cove currently has no Reject button, preference center, later-change cookie control, or automatic GPC handling. Accept dismisses the banner; it is not a promise that scripts waited for consent. Where law requires consent, an opt-out mechanism or a response to a qualifying signal, these obligations are not waived by this description.
For privacy requests, contact support@covecrm.com or legal@covecrm.com. See the state privacy supplement. A request email does not automatically change your browser settings.
7. Duration and updates
Session/security technology follows the relevant session or provider lifetime. Preferences and acknowledgment storage may persist until cleared. Analytics and advertising identifiers follow provider settings and retention. We have not represented a fixed lifetime for every third-party cookie. Cookie lifetime and a provider's retention of already collected information are different.
We may revise this Policy as technologies or practices change and identify the updated date/version. Required additional notice or consent must be handled separately; changing this document does not itself implement tracking controls.