Cookie Policy
Current as of July 28, 2026
This Policy explains the cookies, local storage, session storage, browser signals, analytics, and related technologies used by CORE.
1. What Are Cookies
Cookies are small text files placed on your device by websites you visit. They are widely used to make websites work efficiently, provide functionality, and give website owners information about how their sites are being used.
We also use similar technologies including web beacons, local storage, session storage, random first-party identifiers, and—after non-essential personalization consent for an unauthenticated visitor—privacy-protected pseudonymous browser signals for continuity, duplicate detection, analytics, and fraud prevention. Browser fingerprinting is a separate technology, not a cookie.
2. Essential & Functional Cookies
These cookies and storage values support security, authentication, shopping-cart state, account sessions, requested features, and preferences. They are not disabled through CORE's non-essential preference control because doing so would prevent the requested function. A browser can still block or clear them, but login, checkout, saved state, security, or other features may then fail.
Examples: session cookies that keep you logged into your account, cart cookies that preserve your shop selections, consent cookies that remember your cookie preferences, and security tokens that prevent cross-site request forgery (CSRF).
Domain search, domain checkout, and broker request flows may use essential cookies or similar session storage to preserve search results, checkout state, fraud-prevention checks, and form progress.
3. Analytics Cookies
We use analytics cookies to understand how visitors interact with our website — which pages are popular, where visitors come from, how long sessions last, and where users drop off. This information helps us improve our site and services.
When enabled, optional providers may include Google Analytics, Google Tag Manager, advertising measurement tags, or a project-specific analytics tool. Provider data can be aggregated or pseudonymous and is not necessarily anonymous. CORE uses available privacy-enhancing settings when appropriate for the configuration.
You may opt out of optional analytics by choosing essential-only in the Accessibility control, using browser settings to block tracking cookies, or using a provider-specific opt-out tool.
4. Advertising & Targeting Cookies
We may use advertising cookies to deliver relevant ads to you on third-party platforms, measure the effectiveness of our advertising campaigns, and retarget visitors who have interacted with our site. These cookies track your browsing activity across websites.
The configured advertising network may include Google Ads or another platform identified in a campaign or client project. Each platform operates under its own privacy controls. You may also use industry opt-out tools where available, but the CORE essential-only control is the direct way to stop CORE from loading its optional advertising tags going forward.
Conversion tracking can send pseudonymous identifiers, campaign data, page or event information, and hashed contact data when expressly configured and lawfully supported; it is not represented as always anonymous. CORE does not enable a conversion or audience integration merely because the provider is named in this Policy.
5. Third-Party Cookies
Some pages may embed content or scripts from third-party services, such as a payment frame, map, video, or client-authorized integration. A strictly necessary requested flow may load without optional-cookie consent; non-essential embeds are gated where CORE controls loading. A third-party page or service you independently open follows that provider's controls.
Domain registration and broker flows may also involve third-party checkout, registrar, escrow, or marketplace tools. Where those tools set cookies or collect device data, their own privacy and cookie policies apply.
Third-party cookies are governed by the respective third party's privacy and cookie policies. CORE does not control third-party cookie behavior. Where third-party embeds are avoidable, we implement them with consent gating (i.e., they only load after you accept the relevant cookie category).
6. Cookie Duration
Session cookies: expire when you close your browser. They are used for authentication and temporary state storage.
Persistent cookies and local-storage values remain until their configured expiry, browser eviction, user deletion, or replacement. The first-party non-essential preference is stored for up to one year; provider durations depend on the enabled provider and its current configuration.
7. AI Assistants, Chat & Session Storage
CORE's first-party chat, sales-assistant, support, estimate, and call-continuity experiences may use cookies, local storage, session storage, and server-side session identifiers to maintain conversation state, connect an interaction to a submitted phone number or email, preserve a draft, prevent abuse, and let an authorized staff member assist with the same active session.
Storage required to deliver a feature you request is treated as functional or essential. Optional analytics, advertising measurement, and session-replay technologies remain subject to the preference and privacy-signal rules in this policy. CORE does not use functional chat storage by itself for unrelated cross-site behavioral advertising.
A configured AI, communications, transcription, or support provider may receive a scoped session or message through CORE's server-side integration and may set provider-controlled storage only when that integration requires it. Provider processing, retention, and responsibility are addressed in the Privacy Policy, applicable provider terms, and any Data Processing Addendum; CORE remains responsible for the duties it accepts.
AI and chat storage may persist for the conversation, a configured recovery window, the account or project record, or a legally permitted retention period. Clearing browser storage may reset local state but may not delete server-side records; privacy requests may be sent to legal@coretv.co.
8. Managing Your Cookie Preferences
CORE starts in essential-only mode and does not display a category-by-category pop-up banner. You may allow or disable non-essential cookies at any time using the cookie toggle inside the Accessibility control at the bottom-left of the public site.
You may also manage cookies through your browser settings. Most browsers allow you to block all cookies, block third-party cookies only, or delete existing cookies. Note that disabling essential cookies may impair site functionality including login, checkout, and account features.
Mobile device settings may also allow you to limit ad tracking or reset advertising identifiers.
9. Do Not Track
Some browsers support a 'Do Not Track' (DNT) signal. CORE honors DNT signals by disabling non-essential analytics and advertising cookies for browsers that broadcast DNT. Note that third-party platforms accessed through CORE (such as social media embeds) may not honor DNT independently.
10. Updates to This Policy
We may update this Cookie Policy as our use of cookies changes or in response to legal requirements. Material changes will be reflected by an updated 'Current as of' date and may reset the stored non-essential preference when fresh consent is required. Questions: legal@coretv.co.
11. First-party state, drafts & identity continuity
CORE uses first-party cookies, local storage, and session storage to keep authentication, security, theme and accessibility preferences, cookie choice, estimate and cart state, application progress, chat state, booking context, proposal or onboarding workspace state, and interface preferences available. Clearing these values can sign you out, reset preferences, or make an unauthenticated draft unavailable.
A random first-party visitor or device identifier supports same-browser continuity. With non-essential personalization consent, a pseudonymous browser session may also send privacy-protected browser characteristics for duplicate detection and continuity. Signed-in device observations may be used as an essential account-security control. The Privacy Policy describes the signal categories and identity-linking safeguards.
12. Analytics, advertising & campaign attribution
Google Analytics, Google Tag Manager, advertising tags, and similar non-essential scripts are denied by default and are loaded only after the visitor allows non-essential cookies. A campaign or referral parameter may be held in essential request or session state only when needed to complete the visitor's requested referral, checkout, booking, or other transaction flow; optional marketing attribution, audience building, and measurement remain consent-gated.
Allowing non-essential cookies may permit analytics, advertising measurement, remarketing, and cross-context activity by the selected providers under their terms. In some jurisdictions, this activity may be treated as targeted advertising or sharing even when CORE does not receive money for personal information. Choosing essential-only disables CORE's optional analytics and advertising storage going forward, subject to third-party content you independently choose to open.
Separately, an authenticated portal, proposal, estimate, onboarding, or support workspace may record first-party operational events needed to save progress, show decision history, secure the session, attribute the requested transaction, or notify collaborators. Those server-side service records use the signed-in session or a requested first-party session handle and are not treated as permission to load optional advertising tags.
13. Chat, remote assist & report storage
Chat and AI features use first-party storage to retain a session handle, conversation state, voice or caption preference, and limited interface geometry. Remote-assist invitations and commands are primarily server-side, time-limited records; a current chat-session handle lets the browser receive the invitation and prove that it belongs to the session.
The issue-report tool may calculate a diagnostic hash from browser information and may temporarily hold a captured or uploaded screenshot for preview and submission. Security reports, CSRF controls, rate limiting, and authentication can also use request identifiers or cookies that are strictly necessary to protect the service.
14. Reliability monitoring storage
Privacy-filtered error and performance monitoring may use a short-lived session identifier or browser storage to correlate errors and sampled replay events. This reliability processing is separate from optional advertising and Google analytics storage. Text and inputs are masked and media is blocked in the replay configuration; the Privacy Policy explains the diagnostic categories and purpose.
15. Security & public-intake state
Rate limiting, CSRF protection, duplicate detection, request-integrity checks, IP or network deny rules, and disposable-email screening are security controls and may operate from request headers, server-side configuration, and short-lived security state without placing a non-essential advertising cookie. An accepted public draft may still use the first-party estimate, cart, application, booking, report, or chat state described above. A rejected request does not receive optional analytics permission merely because a security check occurred.
Authenticated rights, refund, billing, support, and renewal workflows use the signed-in session and essential anti-forgery or continuity state to show the correct case, notice, status, and evidence to an authorized user. Clearing essential storage may end the session or interrupt an unfinished request but does not erase a case already submitted to CORE.
16. Privacy signals & controls
CORE starts in essential-only mode. The non-essential cookie toggle is located in the Accessibility control at the bottom-left of the public site; it offers essential-only or allow-all and stores the choice for up to one year. CORE does not present a category-by-category pop-up banner. You may change the toggle or clear browser storage at any time.
Supported browser privacy signals, including Global Privacy Control and Do Not Track, are treated as an essential-only preference by CORE's consent layer. Provider pages opened outside CORE and third-party software that is not controlled by CORE may apply their own signal and cookie rules.
Download this document
Save a PDF copy for your records.