Cookie Policy
Effective 16 August 2026 · Last updated 16 August 2026
Cookies and similar technologies used on the Zipper control plane and widgets.
1. Strictly necessary
Authentication cookies issued by Supabase SSR keep you signed in to the dashboard. They are first-party, HttpOnly, SameSite=Lax, and required to operate the Service.
A CSRF-adjacent session identifier is used on state-changing dashboard actions.
2. Portcullis
The Portcullis widget may set a short-lived first-party clearance cookie on the embedding site (name prefix tz_pc_) so a solved challenge can be reused on the same page flow. It is not an advertising cookie and expires with the token TTL.
3. Analytics
The marketing site does not load third-party advertising pixels. First-party, aggregated page counters may be used. You can reject non-essential cookies in the banner; necessary cookies cannot be disabled.