TenderLock uses only the cookies needed to run the website and platform securely. We do not use advertising or cross-site tracking cookies.
| Cookie | Purpose | Duration |
|---|---|---|
| tenderlock_session | Keeps you signed in and remembers your session | Session, or 2 hours idle |
| XSRF-TOKEN | Protects forms against cross-site request forgery | 2 hours |
| Stripe cookies | Set by Stripe on checkout pages to prevent card fraud | Up to 1 year |
Email tracking: emails sent through TenderLock may contain a small image and tracked links. These show the sender whether an email was opened or a link clicked. They are not cookies and are not used for advertising.
Because these cookies are strictly necessary, they do not need consent. If we add analytics in future, we will ask for your consent first and update this policy.
