Cookies and browser storage
Last updated: October 4, 2026
Cookies are small values your browser sends back with requests. Local storage, session storage and IndexedDB keep information in your browser for the features described below. They are not all cookies. Read our Privacy Policy for information sent to SAH and its providers.
Portal cookies
The portal's cookies support sign-in, abuse prevention and the safe operation of tours. Analytics reuses the sign-in cookie to identify signed-in requests and does not extend your login. We set no additional analytics cookie and no advertising cookie. Optional display choices and drafts are listed separately below.
astro-sessionKeeps you signed in and connects you to your account and cart. It contains an opaque session identifier, not your password. It also identifies signed-in first-party analytics requests. Analytics does not create a cookie or extend the login.
Lifetime: 1 day; 30 days if you select Remember me. Changing your password preserves the remaining session lifetime (with a 1-day fallback). Logging out ends the session.
Protection: Path=/; HttpOnly; SameSite=Lax; Secure in production (off on local development).
sah_register_browserGroups registration attempts from the same browser to limit abuse; it does not identify an approved account.
Lifetime: 24 hours from issue or refresh on the registration form/API.
Protection: Path=/; HttpOnly; SameSite=Lax; Secure on HTTPS.
sah_tour_worldPrevents practice tours from making real changes.
Lifetime: 15 minutes from the latest tour request; removed when the tour ends.
Protection: Path=/; HttpOnly; SameSite=Strict; Secure on HTTPS.
HttpOnly prevents scripts from reading a cookie. Secure restricts it to HTTPS. SameSite limits when it is sent on requests from other sites. All three portal cookies are scoped to this site's host and the whole site path.
Cloudflare security cookies
Cloudflare may set additional cookies at a protected entry point or security challenge. A local development site does not pass through Cloudflare Access, so these are conditional provider cookies, not cookies observed on every portal visit.
CF_Authorizationauthenticates Cloudflare Access on the protected site or its sign-in domain. Its lifetime follows the configured Access session; the provider default is 24 hours. Access also usesCF_AppSession(24 hours),CF_Session(4 hours), andCF_Device(30 days) for login security. OptionalCF_Bindingfollows the Access session.cf_clearancerecords a successful Cloudflare challenge when challenge clearance or Turnstile pre-clearance is enabled. Its lifetime follows the site's Challenge Passage setting. Challenge processing can also usecf_chl_*cookies.
The exact set, scope and flags depend on the deployed security settings. See Cloudflare's Access cookie reference and security cookie reference. Turnstile's form token is not itself a portal cookie.
Local storage: drafts and preferences
These values can survive closing your browser. Unless a clearing action is stated, the portal sets no timed expiry; they remain until removed by the feature, you or your browser. Labels in angle brackets vary by account, item or view. Staff tools only use their entries when those tools are used.
sah:search:recent:<user or guest>- The five most recent searches, for search suggestions. Clear in search; signed-in history is cleared on sign-out.
sah:checkout:<customer>- Prevents duplicate order submissions; removed when the submission key is retired.
catalogue-draft:<company>:<username>- Unsaved staff catalogue change requests; cleared when emptied.
dress-submit:<account>:<submission identity>- Recovers staff mockup submissions after an interrupted request; removed on acceptance or a definitive refusal.
dress-follow:<account>- Remembers mockup batches being followed; entries are removed when marked done.
mockup-mask-draft:<reference>- Unsaved staff image-mask edits; removed when the draft is dropped.
sah.strings.v1.<version>- Caches derived decoration placement information.
mockups:made-from; mockups:mask-literal; mockups:recent-open- Staff mockup display preferences.
mask-queue:glance; mask-glance:per-row; kept-review:flags- Staff image-review marks and grid preferences.
sah:catalog:view:<user>; sah-admin-tz; docs-topics- Catalogue layout, email-log time zone and help-topic display preferences.
tour:<user>:<tour>- Remembers tour progress and completed runs.
Session storage: work in this tab
These values include the first-party analytics visit state described in our Privacy Policy. They normally last for the tab's session, or until the feature clears them. Browsers that restore tabs may restore session data too.
portal-analytics-tab-v1- First-party analytics visit state: a random visit ID, portal username and role, last permitted page and activity timestamp. Reused for the same user within 30 minutes of activity, rotated after inactivity or a user change, and cleared on signed-out pages. A same-origin BroadcastChannel with the same name separates copied tabs on a best-effort basis. Tab restoration may preserve this value. Event queues stay only in memory; no analytics local storage or offline archive is created.
sah:client-errors; sah:fetch-ring; sah:action-ring- Signed-in troubleshooting context: up to 10 errors, 20 requests and 30 navigation/click/shortcut actions. Form values and request bodies are not intentionally recorded. Cleared on logged-out pages.
catalogue-selection:<company>:<username>; library-selection:<company>:<username>; library-selection:<company>:<username>:query- Staff catalogue/library selections and query selections in this tab.
sah:decorate-draft:client:<client>; sah:decorate-draft:general; sah:decorate-draft:last- Unsaved decoration editor state and last draft; cleared by Keep, Save or Start over.
order-note:<customer>:<order>; sah:cart-held-removals- Order-confirmation notes and recovery of deferred cart removals.
portal:pending-toast; sah:edit-line-focus; media-search-focus- One-time notifications and keyboard focus across navigation; removed when consumed.
mockups:view-address:<view>- Remembers the staff mockup view's filters within this tab.
tour:active; tour-world:<world>:local:<key>; tour-world:<world>:session:<key>- The active practice tour and isolated copies of its browser storage; discarded on tour exit.
IndexedDB: unsent feedback
sah-feedback / drafts (key: login); chunks (auto-increment key, login index)- Unsent feedback text, picture, transcript and recording chunks. Drafts older than 7 days are discarded when read; sending or discarding clears the draft and chunks. Stranded chunks have no independent timed cleanup.
These drafts stay in this browser until you send them. Browser speech recognition used during recording may separately process audio through the browser provider, as explained in the Privacy Policy.
Clearing or blocking storage
Use your browser's site-data settings to remove cookies, local storage and IndexedDB for this site. Closing a tab normally clears its session storage. Clearing cookies signs you out; clearing other storage can discard unsent feedback, drafts, selections and preferences. Blocking essential storage can prevent login, registration or checkout from working.
For questions or help with submitted information, contact office@stuffedanimalhouse.com or 604-857-0086.