Cookie Policy

Last updated: 2026-05-20

This Cookie Policy explains how 3520file.com uses cookies and similar technologies to recognize you when you visit. It is a companion to our Privacy Policy — read both together for the complete picture of how we handle your data. By using the Service, you consent to the cookies described here as configured in our cookie-consent banner.

1. What Cookies Are

Cookies are small text files placed on your device when you visit a website. They let the site remember things between visits — like that you are signed in — and help us understand how the site is used. We also use similar technologies (HTML5 local storage, session storage) for the same purposes; everything in this policy applies equally to those technologies.

2. Categories of Cookies We Use

We use exactly two categories of cookies: (a) Essential cookies — required for the Service to function. These keep you signed in, remember your cookie-consent choice, and let our front-end communicate with our back-end. You cannot disable these and still use the Service. (b) Analytics and error-monitoring cookies — help us understand which parts of the Service customers actually use and capture front-end errors so we can fix them. These are loaded only after you accept the cookie banner.

3. What We Do NOT Use

We do not use advertising cookies. We do not use retargeting pixels. We do not embed social-media tracking. We do not sell, share, or rent your cookie-derived data. We do not allow third parties to set advertising cookies on our domain.

4. Managing Your Cookie Preferences

You can review and change your choices at any time via the Cookie Preferences link in the footer of any page. Essential cookies cannot be disabled because the Service does not function without them — without them you could not sign in, pay, or have us remember your consent choice itself. You can also clear cookies in your browser settings; doing so will sign you out and require you to re-accept the cookie banner on your next visit.

5. Third-Party Cookies

When we use third-party providers (Clerk for auth, Stripe for payments, PostHog for analytics, Sentry for error monitoring) those vendors may set their own cookies on their own domains as part of providing their service to us. We have reviewed each vendor and confirmed their privacy posture aligns with our Privacy Policy. Each provider operates under its own privacy policy: Clerk (clerk.com/privacy), Stripe (stripe.com/privacy), PostHog (posthog.com/privacy), Sentry (sentry.io/privacy).

6. Cookies and California Residents (CCPA)

Under the California Consumer Privacy Act we are required to disclose any "sale" or "sharing" of personal information collected via cookies — we do not engage in either. California residents have the right to opt out of any sale or sharing, although in our case there is nothing to opt out of. See the California Privacy Rights section of our Privacy Policy for full details.

7. Cookies and European Residents (ePrivacy / GDPR)

Under the EU ePrivacy Directive and GDPR we obtain your consent before setting any non-essential cookie. Our cookie-consent banner is shown to you on first visit and your choice is remembered for one year via the cookie_consent cookie. You can revoke consent at any time using the Cookie Preferences link in the footer.

8. Changes

We will update this Cookie Policy whenever we add or remove a cookie. Material changes — for example introducing a new analytics provider — will be reflected in the cookie banner and announced via email to active customers at least 30 days in advance. The "Last updated" date above always reflects the current version.

9. Contact

Questions about cookies or to revoke your consent in writing: privacy@3520file.com.

Cookie Details

CookieProviderTypePurposeDuration
__session, __clerk_*, __client_uatClerkEssentialAuthentication session, signed-in state, cross-subdomain session sharingSession and 1 year
cookie_consent3520file (first-party)EssentialStores your cookie-consent choice so we do not re-prompt you on every visit1 year
__stripe_mid, __stripe_sidStripeEssential (payments)Fraud detection during checkout. Set only on the checkout page.1 year (mid), 30 minutes (sid)
ph_*, posthog_*PostHogAnalyticsAnonymous usage analytics and funnel events. Loaded only with consent.1 year
sentry-*SentryError monitoringCaptures front-end errors so we can fix them. No PII. Loaded only with consent.Session