KARRABO
0%
Karrabo

Cookie Policy

This policy covers cookies and similar client-side storage used across Karrabo’s web properties — the Manager Dashboard and Checkout — and how each one uses them.

Last updated 20 August 2026Karrabo Financial Solutions Limited
On this page
PropertyWhat it isProduction domain
Manager DashboardClient-facing dashboard + onboarding portaldashboard.karrabo-development.com
CheckoutStandalone payment checkout widget, used full-page or embedded in a merchant’s site via <iframe>checkout.karrabo-development.com

Each runs on its own subdomain and does not share cookies with the other — a cookie set on dashboard.karrabo-development.com is not readable on checkout.karrabo-development.com, and vice versa. This policy also covers localStorage and sessionStorage, since browsers and regulators generally treat both as “similar technologies” requiring the same disclosure.

This policy does not cover the Karrabo sign-in page you’re redirected to when you log in — it runs on a separate domain, manages its own session, and is governed by its own cookie practices.

1

Manager Dashboard (dashboard.karrabo-development.com)

NamePurposeTypeExpiryNotes
refreshTokenKeeps you signed in; used server-side to obtain new access tokens and gate access to the dashboardStrictly necessary30 daysSecurity-flagged (HttpOnly, Secure) — not readable by JavaScript. Deleted on logout or failed refresh.
invitation_dataCarries a signed record of a prospective client’s onboarding invitation through the multi-step onboarding flowStrictly necessary1 hourSecurity-flagged, signed and tamper-proof. Only set if you arrive via an onboarding invitation link.
sidebar_stateRemembers whether the dashboard sidebar is expanded or collapsedPreference7 daysPlain client-side value, no personal data.

localStorage: stores your access token, used to keep you signed in across page reloads and browser tabs and to authorize requests to our servers. Encrypted at rest. Cleared when you log out.

2

Checkout (checkout.karrabo-development.com)

The checkout widget sets no cookies at all.

StorageKeyPurposeNotes
sessionStoragewallet payment session snapshotResumes an in-progress wallet payment after the customer is redirected out to a wallet provider’s OAuth page and back (/wallet/callback)Cleared once the payment resumes or completes. Scoped to the browser tab; gone when the tab closes.

When embedded via <iframe> on a merchant’s own site, the widget communicates size/state to the parent page via postMessage, not cookies. Because it sets nothing, it is unaffected by browser third-party-cookie blocking.

3

Third-Party Resources

  • static.cloudflareinsights.com — Cloudflare’s performance/bot-mitigation beacon, allowlisted in the CSP of the Manager Dashboard. Cookieless, aggregate-only.
  • Checkout iframe — the Manager Dashboard allows embedding checkout.karrabo-development.com for in-app payment flows. Any cookies the checkout widget’s own page sets (currently none, see §2) would be scoped to checkout.karrabo-development.com, not the embedding app.

Neither property loads third-party analytics, advertising, or social-media trackers (e.g. Google Analytics, Meta Pixel, Hotjar).

4

Why We Use These Cookies

Strictly necessary
refreshToken and invitation_data are required to log in, stay logged in, and complete onboarding. There is no consent banner for these because the app cannot function without them.
Preference
sidebar_state improves usability by remembering a UI choice; deleting it just resets the sidebar to its default on next visit.
5

Managing Cookies

  • Strictly necessary cookies cannot be disabled without breaking login (and, on Manager Dashboard, onboarding). Clearing them via your browser’s site data settings will sign you out.
  • sidebar_state is safe to delete at any time; it’s recreated with default values next time you toggle the sidebar.
  • Most browsers let you block or delete cookies globally via Settings → Privacy → Cookies and site data, per-domain if you want to allow one Karrabo property but not another.
6

Changes to This Policy

We may update this policy as our cookies or storage change. Material changes (e.g. a new tracker or a new purpose for an existing cookie) will be reflected here with an updated “Last updated” date.

7

Contact

For questions about this policy, contact Karrabo Financial Solutions Limited through your normal account/support channel.

Questions about this policy?

Reach out and we’ll help you understand how it applies to you.

Contact us