Cookie Policy

GReviewPilot sets only the cookies needed to sign you in and keep your session secure. We run no advertising or analytics trackers.

Last updated:

The short version

We use strictly necessary cookies only. We do not use cookies for advertising, cross-site tracking, profiling, or third-party analytics, and we do not sell or share cookie data.

Because every cookie we set is essential to delivering a service you asked for, no consent banner is required. If we ever add optional cookies, we will ask for consent before setting them.

Cookies we set

CookiePurposeLifetime
__Secure-authjs.session-tokenKeeps you signed in and identifies your workspace and role. Set HttpOnly, Secure, and SameSite=Lax, so it cannot be read by JavaScript or sent from other sites.Session, or 30 days with “Remember me”
__Host-authjs.csrf-tokenProtects sign-in and form submissions against cross-site request forgery.Session
__Secure-authjs.callback-urlRemembers where to return you after sign-in, so a deep link survives the login step.Session

On local development the same cookies appear without the __Secure- and __Host- prefixes, because those prefixes require HTTPS.

Google and cookies

When you connect your Google Business Profile, Google’s own sign-in and consent pages are served from Google’s domains and may set their own cookies. Those are governed by Google’s cookie policy, not ours.

GReviewPilot itself receives no Google cookies. Our connection to Google uses OAuth tokens stored encrypted on our server, never a browser cookie.

Websites you publish

Sites built with the GReviewPilot website builder do not set tracking cookies by default. If you embed third-party content — a maps widget, a video, or your own analytics — that provider may set cookies on your visitors. You are responsible for disclosing those on your own site.

Controlling cookies

You can clear or block cookies in your browser settings. Blocking our session cookie will sign you out and prevent you from signing back in, because there is no other way for us to recognise an authenticated request. Signing out clears the session cookie immediately.

Questions