Cookie Notice
Last updated 2026-07-08.
DMARCHub uses cookies only where they are strictly necessary to run the service or to remember a preference you have set. We do not use advertising cookies, retargeting pixels, or analytics that profile you or track you across sites. The analytics we use on our public pages (Plausible) is cookieless: it sets no cookies and stores nothing in your browser. Because we use only strictly necessary and preference cookies, we do not show a cookie consent banner. This notice should be read alongside our Privacy Notice, which explains how we handle personal data more generally.
Beyond the cookies described below, DMARCHub does not use local storage, session storage, or other similar technologies in your browser to store information about you. Settings such as whether you have seen our guided tour are kept against your account on our servers, not in your browser.
Cookies we set
These are first-party cookies, set on the dmarchub.io domain.
| Cookie | Purpose | Type | Retention |
|---|---|---|---|
__Secure-authjs.session-token | Keeps you signed in after authentication (a signed session token). | Strictly necessary. httpOnly, Secure, SameSite=Lax. | For the length of your session. |
__Host-authjs.csrf-token | Prevents cross-site request forgery on sign-in and form submissions. | Strictly necessary. httpOnly, Secure, SameSite=Lax. | For the length of your session. |
__Secure-authjs.callback-url / state / pkce / nonce | Secure the sign-in redirect itself - the callback URL and the anti-forgery state, PKCE and nonce values your identity provider requires. Set only during sign-in, then cleared. | Strictly necessary. httpOnly, Secure, SameSite=Lax. | A few minutes, then cleared. |
dmarchub_invite_token | Carries a team invitation securely across the sign-in redirect when you accept an invitation to join an organisation. It is encrypted, and cleared once the invitation is accepted. | Strictly necessary. httpOnly, Secure, SameSite=Lax. | 15 minutes, or until the invitation is accepted. |
xero_oauth_state | Protects the Xero accounting connection against cross-site request forgery when our team connects that integration. | Strictly necessary. httpOnly, Secure, SameSite=Lax. | 10 minutes, then cleared. |
theme | Remembers whether you chose light or dark mode, so the page renders in your choice without a flash. | Functional preference. SameSite=Lax, readable by the page. | Up to one year. |
If you are a member of our staff using the administration area, we also set a functional cookie (admin-nav-collapsed) that remembers which navigation sections you have collapsed, so the page renders the same way next time. It is not set on the customer dashboard and lasts up to one year.
Cookies set by others
A small number of cookies are set by suppliers who help us run the service securely. We do not control these directly.
- Cloudflare may set security cookies (such as
__cf_bm) on our behalf for bot management and to keep TLS sessions efficient. These are strictly necessary to protect the service. - Stripe sets cookies on its own checkout domain (
checkout.stripe.com) when you make a payment, for fraud prevention. They appear only if you go through Stripe's payment checkout. These are Stripe's own cookies, governed by Stripe's cookie policy, not ours.
Why there is no cookie banner
UK ICO guidance is that cookies which are strictly necessary to provide a service the user has asked for - and preference cookies the user sets themselves - do not require prior consent. DMARCHub uses only those kinds of cookies, so we do not present a consent banner. If we ever introduce non-essential cookies, we will ask for your consent before setting them.
Managing cookies
You can refuse or delete cookies in your browser settings at any time. Deleting the strictly necessary cookies will sign you out and prevent you from signing back in; clearing the preference cookies simply resets your theme and navigation choices.
Contact
Questions about cookies: privacy@dmarchub.io.