Skip to content

Cookies and browser storage

Last updated: October 4, 2026

Cookies are small values your browser sends back with requests. Local storage, session storage and IndexedDB keep information in your browser for the features described below. They are not all cookies. Read our Privacy Policy for information sent to SAH and its providers.

Portal cookies

The portal's cookies support sign-in, abuse prevention and the safe operation of tours. Analytics reuses the sign-in cookie to identify signed-in requests and does not extend your login. We set no additional analytics cookie and no advertising cookie. Optional display choices and drafts are listed separately below.

astro-session

Keeps you signed in and connects you to your account and cart. It contains an opaque session identifier, not your password. It also identifies signed-in first-party analytics requests. Analytics does not create a cookie or extend the login.

Lifetime: 1 day; 30 days if you select Remember me. Changing your password preserves the remaining session lifetime (with a 1-day fallback). Logging out ends the session.

Protection: Path=/; HttpOnly; SameSite=Lax; Secure in production (off on local development).

sah_register_browser

Groups registration attempts from the same browser to limit abuse; it does not identify an approved account.

Lifetime: 24 hours from issue or refresh on the registration form/API.

Protection: Path=/; HttpOnly; SameSite=Lax; Secure on HTTPS.

sah_tour_world

Prevents practice tours from making real changes.

Lifetime: 15 minutes from the latest tour request; removed when the tour ends.

Protection: Path=/; HttpOnly; SameSite=Strict; Secure on HTTPS.

HttpOnly prevents scripts from reading a cookie. Secure restricts it to HTTPS. SameSite limits when it is sent on requests from other sites. All three portal cookies are scoped to this site's host and the whole site path.

Cloudflare security cookies

Cloudflare may set additional cookies at a protected entry point or security challenge. A local development site does not pass through Cloudflare Access, so these are conditional provider cookies, not cookies observed on every portal visit.

  • CF_Authorization authenticates Cloudflare Access on the protected site or its sign-in domain. Its lifetime follows the configured Access session; the provider default is 24 hours. Access also uses CF_AppSession (24 hours), CF_Session (4 hours), and CF_Device (30 days) for login security. Optional CF_Binding follows the Access session.
  • cf_clearance records a successful Cloudflare challenge when challenge clearance or Turnstile pre-clearance is enabled. Its lifetime follows the site's Challenge Passage setting. Challenge processing can also use cf_chl_* cookies.

The exact set, scope and flags depend on the deployed security settings. See Cloudflare's Access cookie reference and security cookie reference. Turnstile's form token is not itself a portal cookie.

Local storage: drafts and preferences

These values can survive closing your browser. Unless a clearing action is stated, the portal sets no timed expiry; they remain until removed by the feature, you or your browser. Labels in angle brackets vary by account, item or view. Staff tools only use their entries when those tools are used.

sah:search:recent:<user or guest>
The five most recent searches, for search suggestions. Clear in search; signed-in history is cleared on sign-out.
sah:checkout:<customer>
Prevents duplicate order submissions; removed when the submission key is retired.
catalogue-draft:<company>:<username>
Unsaved staff catalogue change requests; cleared when emptied.
dress-submit:<account>:<submission identity>
Recovers staff mockup submissions after an interrupted request; removed on acceptance or a definitive refusal.
dress-follow:<account>
Remembers mockup batches being followed; entries are removed when marked done.
mockup-mask-draft:<reference>
Unsaved staff image-mask edits; removed when the draft is dropped.
sah.strings.v1.<version>
Caches derived decoration placement information.
mockups:made-from; mockups:mask-literal; mockups:recent-open
Staff mockup display preferences.
mask-queue:glance; mask-glance:per-row; kept-review:flags
Staff image-review marks and grid preferences.
sah:catalog:view:<user>; sah-admin-tz; docs-topics
Catalogue layout, email-log time zone and help-topic display preferences.
tour:<user>:<tour>
Remembers tour progress and completed runs.

Session storage: work in this tab

These values include the first-party analytics visit state described in our Privacy Policy. They normally last for the tab's session, or until the feature clears them. Browsers that restore tabs may restore session data too.

portal-analytics-tab-v1
First-party analytics visit state: a random visit ID, portal username and role, last permitted page and activity timestamp. Reused for the same user within 30 minutes of activity, rotated after inactivity or a user change, and cleared on signed-out pages. A same-origin BroadcastChannel with the same name separates copied tabs on a best-effort basis. Tab restoration may preserve this value. Event queues stay only in memory; no analytics local storage or offline archive is created.
sah:client-errors; sah:fetch-ring; sah:action-ring
Signed-in troubleshooting context: up to 10 errors, 20 requests and 30 navigation/click/shortcut actions. Form values and request bodies are not intentionally recorded. Cleared on logged-out pages.
catalogue-selection:<company>:<username>; library-selection:<company>:<username>; library-selection:<company>:<username>:query
Staff catalogue/library selections and query selections in this tab.
sah:decorate-draft:client:<client>; sah:decorate-draft:general; sah:decorate-draft:last
Unsaved decoration editor state and last draft; cleared by Keep, Save or Start over.
order-note:<customer>:<order>; sah:cart-held-removals
Order-confirmation notes and recovery of deferred cart removals.
portal:pending-toast; sah:edit-line-focus; media-search-focus
One-time notifications and keyboard focus across navigation; removed when consumed.
mockups:view-address:<view>
Remembers the staff mockup view's filters within this tab.
tour:active; tour-world:<world>:local:<key>; tour-world:<world>:session:<key>
The active practice tour and isolated copies of its browser storage; discarded on tour exit.

IndexedDB: unsent feedback

sah-feedback / drafts (key: login); chunks (auto-increment key, login index)
Unsent feedback text, picture, transcript and recording chunks. Drafts older than 7 days are discarded when read; sending or discarding clears the draft and chunks. Stranded chunks have no independent timed cleanup.

These drafts stay in this browser until you send them. Browser speech recognition used during recording may separately process audio through the browser provider, as explained in the Privacy Policy.

Clearing or blocking storage

Use your browser's site-data settings to remove cookies, local storage and IndexedDB for this site. Closing a tab normally clears its session storage. Clearing cookies signs you out; clearing other storage can discard unsent feedback, drafts, selections and preferences. Blocking essential storage can prevent login, registration or checkout from working.

For questions or help with submitted information, contact office@stuffedanimalhouse.com or 604-857-0086.