Cookie Policy
Contents
15 sections, 0 numbered clauses
Contents
Last updated 24 September 2026
Version 3, effective September 23, 2026
This version takes effect thirty (30) days after we notify customers by email. That notice has not been sent yet; until this version takes effect, the previous version applies.
About this Policy
This Cookie Policy explains how KapsuleHost (Kapsule Group Limited) uses cookies and similar tracking technologies on kapsulehost.com, kpanel.kapsulehost.com, our marketing sites, and any other site, application, or property that links to this Policy ("Sites"). It should be read together with our Privacy Policy.
We use several strictly necessary cookies automatically to sign you in, keep your session secure, and protect our forms against forgery; these are required for the Sites to function securely and cannot be disabled. We do not use analytics or advertising cookies. We also set functional cookies for your language, location, currency and appearance preference when you actively make that choice, a chat-continuity marker when you message the Kora AI widget, and one attribution cookie that is set only if you arrive through a partner's referral link. Clause 3 below names every one of these cookies individually, with what it does and how long it lasts, so you can check this Policy against your own browser.
2. First-party and third-party cookies
We use first-party cookies set by us under the kapsulehost.com domain. We also rely on third-party services that may set their own cookies (see clauses 3 and 4).
3.1 Strictly necessary cookies
These are essential for the Sites to function. You cannot disable them without breaking core functionality. We do not require consent for strictly necessary cookies because they are required for the Sites to operate. Several distinct cookies fall in this category; each is named below with its real cookie name, where it is set, and how long it lasts.
Authentication and session (authjs.session-token, or __Secure-authjs.session-token on kapsulehost.com): set on kpanel.kapsulehost.com only, when you sign in. Up to 30 days from your last activity.
Form security / CSRF protection (authjs.csrf-token, or __Host-authjs.csrf-token on kapsulehost.com): set automatically on kpanel.kapsulehost.com whenever you visit, so that our forms can tell a genuine request on the Sites from one forged elsewhere. Session only.
Post-sign-in redirect (authjs.callback-url, or __Secure-authjs.callback-url on kapsulehost.com): set automatically alongside the two cookies above, to remember which page to return you to once you have signed in. Session only.
Two-factor authentication, trusted device (kap-device, or __Secure-kap-device on kapsulehost.com): set only when you choose "remember this device" after completing two-factor authentication. Up to 90 days; removing the device from your account security settings ends its trust immediately, whatever time is left on the cookie.
Sign-in flow security (kap-google-state, kap-apple-state, kap-gh-state, kap-dc-state, kap-gl-state, kap-bb-state, kap-passkey-challenge, kap-passkey-auth-challenge, kap-signin-bind, kap-google-return): short-lived markers used only for the few minutes it takes to complete sign-in with Google, Apple, GitHub, Discord, GitLab, Bitbucket, or a passkey, so the sign-in cannot be forged and you are returned to the right page afterwards. Cleared automatically once sign-in completes; any left over expire within 10 minutes.
Linking an extra sign-in method (kap-oauth-link-google, kap-oauth-link-apple, kap-oauth-link-github, kap-oauth-link-discord): set only when you are already signed in and choose, from your account settings, to add Google, Apple, GitHub or Discord as an additional way to sign in. Up to 10 minutes.
Reseller and affiliate partner sign-in (kap-reseller-sid, kap-aff-sid): set on kpanel.kapsulehost.com only, when a reseller or affiliate partner signs in to their partner account. Up to 30 days, refreshed while the partner stays active; a short-lived version (1 hour) is used for a one-time email sign-in link before the full session begins.
Active account selector (kc_account): where your sign-in has access to more than one account, remembers which one you are currently viewing. Session only.
Signed-in language marker (kc_locale_sid): a technical companion to the language cookie in clause 3.2, used only to stop your language being reset while you are signed in. Not readable by page scripts. 12 months, or until you change your language.
Browser integrity check (kap-bc): where this check is enabled, set on kpanel.kapsulehost.com after your browser passes an automated bot-detection check during sign-up or checkout, so you are not re-challenged partway through. Up to 2 hours.
3.2 Functional cookies
These remember choices you make. One of them, kc_locale, is also set on your first visit, to choose a language for you; apart from that, they are set only when you use a specific feature, not automatically on page load.
Language, location and currency preference (NEXT_LOCALE, kc_locale, kc_country, kc_currency): set when you use the language, location or currency switcher in the site header. kc_locale is also set on your first visit to kapsulehost.com without a language in the address, when we choose a language for you; your browser records it for 365 days. Stored as cookies for 12 months. These are set cross-subdomain (.kapsulehost.com) so your preference carries across KPanel, webmail, our Help Centre, our status page and the marketing site.
Light or dark appearance (kc_theme): set when you choose Light, Dark or System using the appearance control. It stores that one word and nothing else. It is set cross-subdomain (.kapsulehost.com), the same scope as above, so your choice carries across every one of those Sites. Stored for 12 months.
Kora AI chat widget (browser localStorage: kora-sales-conv, kora-sales-locale): your conversation history and last-used locale are stored in your browser's local storage when you open the Kora chat widget. Cleared when you reset the conversation or clear your browser storage.
Kora AI chat continuity (kc_kora_anon): set when you send your first message to the Kora chat widget. It is a random identifier for your browser and nothing else: it is not derived from your IP address, your device, or anything you tell Kora. It is set cross-subdomain (.kapsulehost.com) so that if you go on to open an account, the conversation you were already having comes with you instead of you having to explain it again. Kept for 30 days, after which the conversation is deleted; if you create an account the conversation becomes part of your account history, where you can see it and remove it like any other, and this cookie is retired.
3.3 Analytics cookies
We use Plausible, a privacy-focused analytics tool, on our marketing pages (kapsulehost.com) to understand aggregate traffic patterns. It is self-hosted on our own infrastructure (analytics.kapsulehost.com): no third party receives your visit data. It sets no cookies and stores no persistent identifier that could recognise your device on a return visit; it counts a unique visit using a value derived from your IP address and browser that is rotated daily and never stored. It is not used on kpanel.kapsulehost.com. We also analyse server-side logs (such as nginx access logs) in aggregate to understand traffic patterns and improve performance; this does not involve setting any cookies on your device. Plausible does not load at all if your browser sends a Global Privacy Control (GPC) signal (see clause 6).
We do not use any analytics tool that sets a cookie, builds a cross-site profile of you, or shares your visit data with a third party. If that changes, we will update this Policy and, where required by applicable law, implement a consent mechanism first.
3.4 Marketing cookies
We do not run advertising or marketing cookies that track you across other websites, build an advertising profile of you, or are shared with any advertising network. The one exception is described in clause 3.5: a first-party cookie that credits a referring partner, which does none of those things. If we begin to run advertising or cross-site tracking cookies, this Policy will be updated and we will implement a consent mechanism and obtain your consent before setting any such cookies.
3.5 Affiliate attribution cookie
If you arrive at the Sites through a link shared by one of our reseller or affiliate partners, we set one first-party cookie (kc_affiliate) so that, if you go on to become a customer, the partner who referred you is credited. It is not set on an ordinary visit with no referral link. It is set, and your arrival through the referral link is recorded for the partner, whether or not your browser sends a Global Privacy Control (GPC) signal (see clause 6).
It does not track your browsing on any other website, does not build an advertising profile of you, and is never shared with or read by a third party: only we read it, to attribute a sale to the partner who sent you here. It lasts 30 days for most partners, or 60 days for a smaller number of senior partners; we may adjust this period from time to time.
4. Third-party services
Some pages of the Sites load third-party services that may set their own cookies and process data through your browser. We do not control those cookies; the third-party's own privacy and cookie policies apply.
Stripe, Inc: Payment processing and fraud prevention on checkout and billing pages only (stripe.com/privacy).
Sentry: Error monitoring on all pages, only when an error occurs (sentry.io/privacy/).
We do not permit third parties to use cookies on the Sites for their own marketing purposes.
5. Cookies set by content you load
Where you embed content into a page hosted on our Services (for example, YouTube videos, Google Maps, third-party fonts, or social-media share buttons), that content may set its own cookies on your visitors' devices. You are responsible, as the operator of the website, for disclosing those cookies in your own cookie policy and (where required) obtaining consent.
6. Managing cookies
We set strictly necessary cookies (clause 3.1), functional cookies and browser storage that remember your preferences and your Kora conversation (clause 3.2), and one attribution cookie, kc_affiliate, when you arrive through a partner's referral link (clause 3.5). We set no advertising or cross-site tracking cookies, and our analytics (clause 3.3) sets no cookies. A Global Privacy Control signal stops our analytics loading; it does not stop the attribution cookie being set (see below). You can manage cookies in the following ways.
Your browser settings: all major browsers allow you to block, delete, or limit cookies. Check your browser's help documentation. Note that blocking strictly necessary cookies will break the Sites.
Kora widget storage: to clear Kora conversation history, use the reset button in the widget or clear your browser's local storage for kapsulehost.com.
Global Privacy Control (GPC): where your browser sends a Global Privacy Control signal, we honour it as a request to minimise any data collection beyond what is strictly necessary. In practice, our analytics (clause 3.3) does not load; the affiliate attribution cookie (clause 3.5) is still set if you arrive through a partner's referral link.
Do Not Track (DNT): there is no widely agreed standard for DNT, and we do not respond to DNT signals. The analytics tool we use today is Plausible, on our marketing pages (clause 3.3): it is self-hosted, sets no cookies, and reports visits only in aggregate. Plausible does not read a DNT signal, so it loads whether or not your browser sends one; a Global Privacy Control signal does stop it loading (see above).
7. Children
The Sites are not directed at children under 18. We do not knowingly use cookies to collect personal information from children under 18.
8. Changes to this Cookie Policy
We may update this Cookie Policy from time to time to reflect changes in our use of cookies, our service providers, or the law. Material changes (such as adding analytics or advertising cookies) will be notified by email and posted here at least 30 days before taking effect. The "Last updated" date at the top of this Policy shows the most recent change.
9. Contact
Kapsule Group Limited, New Zealand.
Email: privacy@kapsulehost.com
Eleven documents, and none of them is behind a login.
Every one is indexed, searchable by word, and deep linkable by clause. Six of them are not in the footer and this is how you reach them.