Cookie Policy

COOKIE POLICY

Last updated May 17, 2026

This Cookie Policy explains how CoreBase (doing business as CoreBase) ("Company," "we," "us," and "our") uses cookies and similar technologies when you visit our website at https://www.corebasehq.com ("Website"). It explains what these technologies are, why we use them, and your rights to control them.

What are cookies?

Cookies are small data files placed on your device when you visit a website. They are widely used to make websites work, work more efficiently, or provide reporting information.

Cookies set by the website owner (in this case, CoreBase) are called "first-party cookies." Cookies set by other parties are called "third-party cookies." Third-party cookies enable features such as authentication, security, and analytics to be provided on or through the Website.

Why do we use cookies?

We use only strictly necessary cookies. These cookies are required for the Website to function — they support sign-in/sign-out, session management, and protection against automated bots. We do not use analytics, advertising, profiling, or targeting cookies.

You cannot opt out of strictly necessary cookies, because the Website cannot operate without them. If your browser blocks them, sign-in and most authenticated areas of the Website will not work.

Cookies we set

The following table lists the cookies actually set on your device when you visit our Website. We update this list whenever the cookies we use change.

NameProviderPurposeTypeDuration
__client.clerk.corebasehq.comClerk authentication session — identifies your signed-in sessionFirst-party (via Clerk)~1 year
__client_uat.corebasehq.comClerk user authentication token — signals authentication state to our appFirst-party~1 year
__client_uat_<instance>.corebasehq.comClerk instance-scoped authentication token (e.g. __client_uat_smWMMhD6)First-party~1 year
__cf_bm.clerk.corebasehq.comCloudflare Bot Management — distinguishes humans from bots to protect the auth endpointThird-party (Cloudflare)30 minutes
_cfuvid.clerk.corebasehq.comCloudflare rate-limiting / trusted-traffic identificationThird-party (Cloudflare)Session

Service providers:

What about analytics?

We use Vercel Analytics and Vercel Speed Insights for aggregated, privacy-friendly traffic measurement. These tools are cookieless — they do not set persistent identifiers on your device and do not track you across sites. See Vercel's Privacy Policy for details.

We do not use Google Analytics, Facebook Pixel, advertising networks, or cross-site trackers.

Other browser storage

In addition to cookies, our authentication provider (Clerk) uses localStorage to keep your sign-in state on the device. localStorage entries are not cookies — they are not sent to servers automatically and are managed by your browser like any site data. You can clear them at any time from your browser's site-data settings.

How can I control cookies on my browser?

Because we only set strictly necessary cookies, there is no in-app cookie preference center to toggle. If you wish to block these cookies anyway, you can do so through your browser settings — note that doing so will prevent sign-in and most product functionality.

The following pages explain how to manage cookies in major browsers:

We may update this Cookie Policy whenever the cookies we use change, or for other operational, legal, or regulatory reasons. The "Last updated" date at the top reflects the most recent revision.

Where can I get further information?

If you have questions about our use of cookies, please email us at [email protected].

CoreBase