# Cookie Policy

Canonical page: https://kapsulehost.com/en-nz/legal/cookies

Last updated: 8 October 2026

## About this Policy

This Cookie Policy explains how KapsuleHost (Kapsule Group Limited) uses cookies and similar tracking technologies on kapsulehost.com, kpanel.kapsulehost.com, our marketing sites, and any other site, application, or property that links to this Policy ("Sites"). It should be read together with our Privacy Policy.

We use several strictly necessary cookies automatically to sign you in, keep your session secure, and protect our forms against forgery; these are required for the Sites to function securely and cannot be disabled. Our own analytics sets no cookies, and we set no advertising cookies of our own; if you allow analytics or advertising, Google and Meta set their cookies (clauses 3.3 and 3.8). We also set functional cookies for your language, location, currency and appearance preference when you actively make that choice, a chat-continuity marker when you message the Kora AI widget, one attribution cookie that is set only if you arrive through a partner's referral link, and one campaign attribution cookie that is set only if a link carrying our campaign tags brings you to kapsulehost.com. Clause 3 below names every one of these cookies individually, with what it does and how long it lasts, so you can check this Policy against your own browser.

On your first visit to kapsulehost.com, a cookie banner at the bottom of the page offers Accept all, Reject all and Cookie settings, and you can change your choice at any time from the Cookie settings link at the bottom of every page of kapsulehost.com. The banner decides whether the campaign attribution cookie (clause 3.6), the Google Analytics cookies (clause 3.3) and the advertising cookies of Meta and Google (clause 3.8) are set; clause 3.7 describes how it works where you are. KPanel (kpanel.kapsulehost.com) is different: it sets only strictly necessary cookies, reads the cookies above rather than setting them, and has no banner of its own.

KPanel's cookies, in plain words. KPanel sets only cookies that are strictly necessary: session and sign-in cookies keep you signed in and your session secure, including social sign-in while you are completing it, and are cleared when you sign out or your session ends; a short-lived security check confirms that a request really comes from you (anti-forgery), and, if you tick "Trust this browser for 90 days" when you sign in, a device-trust token lasts 90 days; your language, location, currency and light or dark theme choice, set only after you make it, is shared across kapsulehost.com and KPanel so that a choice on one carries to the other, and lasts 1 year; your cart remembers the plan and add-ons you chose before you have an Account, for 30 days; and a Kora chat-continuity marker lets a conversation you started with our assistant before you had an Account carry into your Account once you sign up. KPanel sets no advertising, analytics, campaign-measurement or affiliate-referral cookie of its own, and no third party (Meta, Google or anyone else) sets a cookie through KPanel. The campaign attribution cookie (kh_ft, clause 3.6) is set on kapsulehost.com, and KPanel never sets the affiliate referral cookie (kc_affiliate, clause 3.5); KPanel only reads them when you open an Account, and reads the same details from your sign-up link when neither cookie exists yet. There is no cookie banner and no Cookie settings control on KPanel, because nothing there needs your choice.

## 1. What cookies are

Cookies are small text files placed on your device when you visit a website. They are widely used to make websites work, to remember preferences, to authenticate users, to measure usage, and to deliver advertising.

In this Policy, "cookies" includes traditional cookies as well as similar technologies that store or read data on your device, including: (a) HTML5 local storage and session storage (small data stores in your browser); (b) IndexedDB (a structured browser data store); (c) web beacons and pixels (tiny invisible images used to track that a page or email has loaded); (d) server-side and first-party fingerprinting signals (information about your browser and device used to identify you across sessions); (e) tags placed by us or by integration partners on the Sites; and (f) SDK identifiers in applications.

## 2. First-party and third-party cookies

We use first-party cookies set by us under the kapsulehost.com domain. We also rely on third-party services that may set their own cookies (see clauses 3 and 4).

## 3.1 Strictly necessary cookies

These are essential for the Sites to function. You cannot disable them without breaking core functionality. We do not require consent for strictly necessary cookies because they are required for the Sites to operate. Several distinct cookies fall in this category; each is named below with its real cookie name, where it is set, and how long it lasts.

Authentication and session (authjs.session-token, or __Secure-authjs.session-token on kapsulehost.com): set on kpanel.kapsulehost.com only, when you sign in. Up to 30 days from your last activity.

Form security / CSRF protection (authjs.csrf-token, or __Host-authjs.csrf-token on kapsulehost.com): set automatically on kpanel.kapsulehost.com whenever you visit, so that our forms can tell a genuine request on the Sites from one forged elsewhere. Session only.

Post-sign-in redirect (authjs.callback-url, or __Secure-authjs.callback-url on kapsulehost.com): set automatically alongside the two cookies above, to remember which page to return you to once you have signed in. Session only.

Two-factor authentication, trusted device (kap-device, or __Secure-kap-device on kapsulehost.com): set only when you choose "remember this device" after completing two-factor authentication. Up to 90 days; removing the device from your account security settings ends its trust immediately, whatever time is left on the cookie.

Sign-in flow security (kap-google-state, kap-apple-state, kap-gh-state, kap-dc-state, kap-passkey-challenge, kap-passkey-auth-challenge, kap-signin-bind, kap-google-return): short-lived markers used only for the few minutes it takes to complete sign-in with Google, Apple, GitHub, Discord, or a passkey, so the sign-in cannot be forged and you are returned to the right page afterwards. Cleared automatically once sign-in completes; any left over expire within 10 minutes.

Linking an extra sign-in method (kap-oauth-link-google, kap-oauth-link-apple, kap-oauth-link-github, kap-oauth-link-discord): set only when you are already signed in and choose, from your account settings, to add Google, Apple, GitHub or Discord as an additional way to sign in. Up to 10 minutes.

Reseller and affiliate partner sign-in (kap-reseller-sid, kap-aff-sid): set on kpanel.kapsulehost.com only, when a reseller or affiliate partner signs in to their partner account. Up to 30 days, refreshed while the partner stays active; a short-lived version (1 hour) is used for a one-time email sign-in link before the full session begins.

Active account selector (kc_account): where your sign-in has access to more than one account, remembers which one you are currently viewing. Session only.

Signed-in language marker (kc_locale_sid): a technical companion to the language cookie in clause 3.2, used only to stop your language being reset while you are signed in. Not readable by page scripts. 12 months, or until you change your language.

Browser integrity check (kap-bc): where this check is enabled, set on kpanel.kapsulehost.com after your browser passes an automated bot-detection check during sign-up or checkout, so you are not re-challenged partway through. Up to 2 hours.

Cookie choice (kh_consent): set when you make a choice in our cookie banner or in Cookie settings (clause 3.7), on kapsulehost.com or KPanel, so that your choice is respected across the Sites. It stores only whether Campaign measurement, Advertising and Analytics are on or off, and when you chose. It is set cross-subdomain (.kapsulehost.com), page scripts can read it so that the banner and the Sites know your choice, and it lasts 12 months.

## 3.2 Functional cookies

These remember choices you make. One of them, kc_locale, is also set on your first visit, to choose a language for you; apart from that, they are set only when you use a specific feature, not automatically on page load.

Language, location and currency preference (NEXT_LOCALE, kc_locale, kc_country, kc_currency): set when you use the language, location or currency switcher in the site header. kc_locale is also set on your first visit to kapsulehost.com without a language in the address, when we choose a language for you; your browser records it for 365 days. Stored as cookies for 12 months. These are set cross-subdomain (.kapsulehost.com) so your preference carries across KPanel, webmail, our Help Centre, our status page and the marketing site.

Light or dark appearance (kc_theme): set when you choose Light, Dark or System using the appearance control. It stores that one word and nothing else. It is set cross-subdomain (.kapsulehost.com), the same scope as above, so your choice carries across every one of those Sites. Stored for 12 months.

Kora AI chat widget (browser localStorage: kora-sales-conv, kora-sales-locale): your conversation history and last-used locale are stored in your browser's local storage when you open the Kora chat widget. Cleared when you reset the conversation or clear your browser storage.

Kora AI chat continuity (kc_kora_anon): set when you send your first message to the Kora chat widget. It is a random identifier for your browser and nothing else: it is not derived from your IP address, your device, or anything you tell Kora. It is set cross-subdomain (.kapsulehost.com) so that if you go on to open an account, the conversation you were already having comes with you instead of you having to explain it again. Kept for 30 days, after which the conversation is deleted; if you create an account the conversation becomes part of your account history, where you can see it and remove it like any other, and this cookie is retired.

## 3.3 Analytics cookies

We use Plausible, a privacy-focused analytics tool, on our marketing pages (kapsulehost.com) to understand aggregate traffic patterns. It is self-hosted on our own infrastructure (analytics.kapsulehost.com): no third party receives your visit data. It sets no cookies and stores no persistent identifier that could recognise your device on a return visit; it counts a unique visit using a value derived from your IP address and browser that is rotated daily and never stored. It is not used on kpanel.kapsulehost.com. We also analyse server-side logs (such as nginx access logs) in aggregate to understand traffic patterns and improve performance; this does not involve setting any cookies on your device. Plausible does not load at all if your browser sends a Global Privacy Control (GPC) signal (see clause 6).

Apart from Google Analytics, described in the next paragraph, we do not use any analytics tool that sets a cookie, builds a cross-site profile of you, or shares your visit data with a third party.

Google Analytics is used only once we switch it on, and then only if you allow Analytics (clause 3.7): in the European Union, the European Economic Area, the United Kingdom and Switzerland, or where we cannot tell your country, only after you choose Accept all or switch Analytics on in Cookie settings; elsewhere unless you choose Reject all, switch it off, or your browser sends a Global Privacy Control signal. It then loads on kapsulehost.com and on the KPanel sign-up, welcome, onboarding and checkout pages, after the page has shown, and sets two first-party cookies on .kapsulehost.com: _ga (a random identifier for your browser) and _ga_ followed by our property identifier (your session), each for 13 months. What it sends to Google is set out in clause 3 of our Privacy Policy. Switching Analytics off stops it and deletes both cookies.

PostHog heatmaps, also under Analytics, run only on the public pages of kapsulehost.com, set no cookie and store nothing in your browser; clause 3 of our Privacy Policy describes what they record.

## 3.4 Marketing cookies

Apart from what this clause describes, we do not run advertising or marketing cookies that track you across other websites or build an advertising profile of you. There are three exceptions. Two are first-party cookies that are never shared with an advertising network: the cookie described in clause 3.5, which credits a referring partner, and the cookie described in clause 3.6, which records which of our own posts, ads or links brought you to us. The third is advertising with Meta (Facebook and Instagram) and Google (clause 3.8): if it is switched on and you allow it, their tags load and set cookies, and Meta and Google use your visits and sign-ups to measure our ads, to show you our ads elsewhere (remarketing) and to build advertising audiences, including audiences of people similar to our customers. Nobody at KapsuleHost can see who is in an audience.

## 3.5 Affiliate attribution cookie

If you arrive at the Sites through a link shared by one of our reseller or affiliate partners, we set one first-party cookie (kc_affiliate) so that, if you go on to become a customer, the partner who referred you is credited. It is not set on an ordinary visit with no referral link. It is set, and your arrival through the referral link is recorded for the partner, whether or not your browser sends a Global Privacy Control (GPC) signal (see clause 6).

It does not track your browsing on any other website, does not build an advertising profile of you, and is never shared with or read by a third party: only we read it, to attribute a sale to the partner who sent you here. It lasts 30 days for most partners, or 60 days for a smaller number of senior partners; we may adjust this period from time to time.

KPanel (kpanel.kapsulehost.com) does not set kc_affiliate. Once our referral hand-off is live, it is set on kapsulehost.com and KPanel reads it when you open an Account; until then, the referral travels in the sign-up link itself and is read once, when you open an Account, with no cookie involved.

## 3.6 Campaign attribution cookie

If a link carrying our campaign tags brings you to kapsulehost.com, we set one first-party cookie (kh_ft) there, under the choice you make in our cookie banner (clause 3.7), so that, if you go on to open an Account on KPanel, we can count which of our own posts, ads and links brought you. KPanel itself never sets this cookie: it is set on kapsulehost.com, carried to KPanel because the cookie is shared across our subdomains, and read once, at the moment you open an Account. If a sign-up link brings you to KPanel directly, with no earlier visit to set the cookie, the same campaign tags travel as part of that link instead, and are read the same way, once, at sign-up. It holds only the four campaign tags on the link (utm_source, utm_medium, utm_campaign and utm_content), the path of the page you landed on without its query string, and the date and time of that visit. It holds no advertising click identifier, IP address, browser or device details, or referring page. It is not set on a visit without campaign tags, a later tagged visit never replaces it, and it is not set if your browser sends a Global Privacy Control (GPC) signal (see clause 6). It is set cross-subdomain (.kapsulehost.com), page scripts cannot read it, and it lasts 30 days.

It does not track your browsing on any other website, does not build an advertising profile of you, and is never shared with or read by a third party: only we read it, to keep the first tagged visit and, when you open an Account, to store those details with your Account, and we report on them only as counts. Clause 3 of our Privacy Policy describes how we use and keep them.

Campaign measurement is used only once we switch it on. Whether kh_ft is then set also depends on where you are and on your choice in our cookie banner (clause 3.7): in the European Union, the European Economic Area, the United Kingdom or Switzerland, or where we cannot tell your country, only after you choose Accept all or switch Campaign measurement on in Cookie settings; everywhere else by default, until you choose Reject all or switch it off. Choosing Reject all, or switching Campaign measurement off, deletes it, and a Global Privacy Control signal always overrides any choice made in the banner.

## 3.7 Your cookie choices

Our cookie banner appears at the bottom of the page and does not block it. It offers three choices of equal weight: Accept all, Reject all and Cookie settings. Cookie settings lists Strictly necessary cookies (clause 3.1), which are always on; Campaign measurement (the kh_ft cookie, clause 3.6); Advertising (Meta and Google, clause 3.8); and Analytics (Google Analytics, clause 3.3). You can switch the last three on or off separately. Your choice is stored in the kh_consent cookie (clause 3.1) for 12 months and applies on kapsulehost.com and KPanel alike, because the cookie is shared across every kapsulehost.com subdomain: KPanel reads your choice, it never asks you again. You can change it at any time from the Cookie settings link at the bottom of every page of kapsulehost.com; KPanel has no separate Cookie settings link, because that shared cookie already reaches it.

If you are in the European Union, the European Economic Area, the United Kingdom or Switzerland, or we cannot tell your country, the banner is shown until you make a choice, and Campaign measurement, Advertising and Analytics stay off until you choose Accept all or switch them on. Everywhere else the banner is shown once, as a notice: all three are on by default, closing the notice keeps them on, and Reject all and Cookie settings stay available from the link at the bottom of every page. We tell where you are from the country that our content delivery network reports for your connection, and we do not store it. If your browser sends a Global Privacy Control signal, the banner says so and all three stay off whatever you choose.

The banner also uses your browser storage, only for itself. kh_consent_notice (local storage) records that you closed the notice, so that it is not shown again, and holds nothing else. kh_utm (session storage) holds the four campaign tags from the link that brought you to kapsulehost.com, only while Campaign measurement is allowed and only for that browser session, so that our sign-up and sign-in links can pass them on to KPanel (clause 3.6). Choosing Reject all, or switching Campaign measurement off, deletes kh_utm.

## 3.8 Advertising cookies (Meta and Google)

Advertising is used only once we switch it on, and then only if you allow it (clause 3.7): in the European Union, the European Economic Area, the United Kingdom and Switzerland, or where we cannot tell your country, only after you choose Accept all or switch Advertising on in Cookie settings; elsewhere unless you choose Reject all, switch it off in Cookie settings, or your browser sends a Global Privacy Control signal. When it is allowed, the Meta Pixel and the Google tag for Google Ads load on kapsulehost.com and on the KPanel sign-up, welcome, onboarding and checkout pages, after the page has shown, and these cookies are set on .kapsulehost.com: _fbp (Meta, identifies your browser to Meta, 90 days), _fbc (Meta, holds the Facebook click identifier, fbclid, when you arrive from a Meta ad, 90 days), _gcl_au (Google, 90 days), _gcl_aw (Google, holds the Google click identifier, gclid, when you arrive from a Google ad, 90 days) and _gcl_gb (Google, holds the Google click identifiers gbraid or wbraid when you arrive from a Google ad, 90 days). Where Advertising is allowed, _fbc, _gcl_aw and _gcl_gb are kept from the first page you land on; where it stays off until you choose, nothing is kept in your browser before you accept. Meta and Google also read and set cookies on their own domains, including Meta's fr cookie (.facebook.com, 90 days) if you are signed in to Facebook or Instagram in that browser, and Google's IDE (.doubleclick.net, about 13 months) and test_cookie (15 minutes). Meta's automatic advanced matching and form scanning are switched off. Meta and Google use these visits and conversions to measure our ads, to show you our ads (remarketing) and to build audiences for us; clause 3 of our Privacy Policy describes this, what they receive and what we keep.

If you choose Reject all or switch Advertising off, the tags are no longer loaded, we delete _fbp, _fbc, _gcl_au, _gcl_aw and _gcl_gb from kapsulehost.com, and we send no further sign-up or purchase events to Meta or Google. Cookies that Meta or Google set on their own domains can be deleted in your browser settings.

## 4. Third-party services

Some pages of the Sites load third-party services that may set their own cookies and process data through your browser. We do not control those cookies; the third-party's own privacy and cookie policies apply.

Stripe, Inc: Payment processing and fraud prevention on checkout and billing pages only (stripe.com/privacy).

Sentry: Error monitoring on all pages, only when an error occurs (sentry.io/privacy/).

We do not permit third parties to use cookies on the Sites for their own marketing purposes.

## 5. Cookies set by content you load

Where you embed content into a page hosted on our Services (for example, YouTube videos, Google Maps, third-party fonts, or social-media share buttons), that content may set its own cookies on your visitors' devices. You are responsible, as the operator of the website, for disclosing those cookies in your own cookie policy and (where required) obtaining consent.

## 6. Managing cookies

We set strictly necessary cookies (clause 3.1), functional cookies and browser storage that remember your preferences and your Kora conversation (clause 3.2), one attribution cookie, kc_affiliate, when you arrive through a partner's referral link (clause 3.5), and one campaign attribution cookie, kh_ft, when a link carrying our campaign tags brings you to kapsulehost.com (clause 3.6). We set no advertising or cross-site tracking cookies of our own, and Plausible, our own analytics (clause 3.3), sets no cookies; if you allow them, Google Analytics (clause 3.3) and the Meta and Google advertising tags (clause 3.8) set their own. A Global Privacy Control signal stops our analytics loading and stops the campaign attribution cookie being set; it does not stop the affiliate attribution cookie being set (see below). You can manage cookies in the following ways.

Your browser settings: all major browsers allow you to block, delete, or limit cookies. Check your browser's help documentation. Note that blocking strictly necessary cookies will break the Sites.

Kora widget storage: to clear Kora conversation history, use the reset button in the widget or clear your browser's local storage for kapsulehost.com.

Global Privacy Control (GPC): where your browser sends a Global Privacy Control signal, we honour it as a request to minimise any data collection beyond what is strictly necessary. In practice, our analytics (clause 3.3) does not load; the affiliate attribution cookie (clause 3.5) is still set if you arrive through a partner's referral link. The campaign attribution cookie (clause 3.6) is not set.

Do Not Track (DNT): there is no widely agreed standard for DNT, and we do not respond to DNT signals. Our own analytics tool is Plausible, on our marketing pages (clause 3.3): it is self-hosted, sets no cookies, and reports visits only in aggregate. Google Analytics and the advertising tags (clauses 3.3 and 3.8) follow your choice in our cookie banner and a Global Privacy Control signal, not a DNT signal. Plausible does not read a DNT signal, so it loads whether or not your browser sends one; a Global Privacy Control signal does stop it loading (see above).

Our cookie banner (clause 3.7): choose Accept all, Reject all or Cookie settings when it appears, or use the Cookie settings link at the bottom of every page at any time. Reject all, or switching a category off, stops its tags and deletes its cookies on kapsulehost.com: the campaign attribution cookie (clause 3.6), the Google Analytics cookies (clause 3.3) or the Meta and Google advertising cookies (clause 3.8). A Global Privacy Control signal does the same whatever you choose. Strictly necessary cookies stay on because the Sites need them to work.

## 7. Children

The Sites are not directed at children under 18. We do not knowingly use cookies to collect personal information from children under 18.

## 8. Changes to this Cookie Policy

We may update this Cookie Policy from time to time to reflect changes in our use of cookies, our service providers, or the law. Material changes (such as adding analytics cookies) will be notified by email and posted here at least 30 days before taking effect. Adding or changing advertising cookies is not notified by email in advance: this Policy is updated before any such cookie is set. The "Last updated" date at the top of this Policy shows the most recent change.

## 9. Contact

Kapsule Group Limited, New Zealand.

Email: privacy@kapsulehost.com

---

This is the Markdown rendition of https://kapsulehost.com/en-nz/legal/cookies, published for AI readers and agents. For the full interactive page, visit the canonical URL above.
