Cookie Policy
Effective and last updated: August 31, 2026
This Cookie Policy explains how Foray Business Consulting (“Foray,” “we,” “us,” or “our”) uses cookies and similar browser technologies on our main website, client portal, and hosted local-business websites (collectively, the “Services”). It should be read with our Privacy Policy.
1. What these technologies are
Cookies are small text files a website stores in your browser. Local storage can retain a value after the browser closes, while session storage normally lasts only for the open browser tab or session. We use these technologies for authentication, security, preferences, and limited first-party measurement. We do not currently use advertising cookies or cross-site behavioral tracking pixels.
2. Technologies we use
| Name or type | Purpose | Typical duration |
|---|---|---|
| session_token | Strictly necessary, HTTP-only account authentication and session security. | Up to 7 days, or until logout, revocation, or deletion. |
| csrf_token | Strictly necessary protection against forged form submissions. | Up to 4 hours. |
| theme | Local storage that remembers your light, dark, or system display preference. | Until changed or browser data is cleared. |
| google_maps_consent | Local storage that remembers when you choose to load embedded Google Maps on hosted business websites. | Until browser data is cleared. |
| tracked_visit_* | Session storage that prevents duplicate first-party page-view counts for a hosted business website. | Browser tab or session. |
| tracked_click_* | Session storage that prevents duplicate attribution of a website-draft or outreach link click. | Browser tab or session. |
Names ending in an asterisk include a site or outreach identifier. The browser value records only that the event was already counted in that session. Related server-side analytics may include the page path, referrer path, campaign source, date, and hashed device or network-derived values, as described in our Privacy Policy.
3. Third-party services
Some pages may load or link to third-party services. For example, a hosted business website may offer a Google Maps frame, checkout may redirect to Stripe, and links may open WhatsApp or other external services. Google Maps frames remain blocked until you choose to load them. Once loaded, Google and other providers whose content you request may set or access their own cookies and receive device, browser, IP address, and interaction information under their own policies. Merely linking to an external service does not allow it to set cookies on our page; this generally occurs only when embedded content loads or when you visit the provider.
Available business integrations may also include Google Business Profile and Yelp review synchronization, Resend email, Twilio messaging, and hosting or object-storage providers. Server-to-server integrations do not necessarily place a cookie in your browser.
4. Your controls
You can delete or block cookies and clear local or session storage through your browser settings. You can also use private-browsing controls or block third-party cookies. Blocking the authentication or security cookies may prevent login, portal access, protected forms, checkout, or other requested functions. Clearing preference or measurement storage may reset your theme or cause a visit to be counted again.
Browser “Do Not Track” signals do not have a single agreed technical meaning. Because we do not sell personal information or use cross-site behavioral advertising, we do not currently change operation in response to that signal. Where applicable law requires recognition of a valid opt-out preference signal, we will honor it for covered processing.
5. Changes and contact
We may update this policy when technologies, providers, or legal requirements change. The date above identifies the latest version. Material changes will receive additional notice where required.
Questions about cookies or browser storage may be sent to support@foraybusinessconsulting.com.