Cookies currently used
| Cookie | Purpose | Typical duration |
|---|---|---|
session_id | Signed identifier for the authenticated, server-side login session. | Up to 30 days, or earlier sign-out/revocation. |
_bay_ledger_session | Signed Rails session state used for security-sensitive navigation, such as returning to the intended page and maintaining verified application flow. | Up to 30 days. |
_ga and _ga_* | Used by Google Analytics on public BayLedger pages to distinguish visits and connect generic funnel events. | Up to two years, subject to Google’s configuration and browser controls. |
The BayLedger authentication cookies are first-party and necessary for core application operation. In production BayLedger-managed cookies are marked HttpOnly and SameSite=Lax, and are transmitted only over HTTPS. Signed means tampering can be detected; it does not mean cookie contents should be treated as public. Google Analytics cookies are set by Google's analytics library and are not authentication cookies.
Public-site analytics
BayLedger uses Google Analytics on its public marketing, legal, sign-in, and registration pages to understand page visits, campaign/referral sources, trial interest, signup, onboarding, first-document creation, and paid-subscription activation. Analytics is not loaded on authenticated shop screens or customer-facing quote or invoice links and does not receive automotive-customer or shop-document information.
A short-lived session-storage flag prevents repeated signup_started events within one browser tab. It contains no form values or identity information and closes with the tab session.
What is not used
BayLedger does not use advertising pixels, behavioural-advertising cookies, session replay, or ad-platform tracking pixels. Google advertising signals and ad-personalization signals are disabled in BayLedger’s Google tag configuration.
When an organization owner follows a billing link, the owner leaves BayLedger for a Stripe-hosted checkout or billing page. Stripe may use cookies or similar technologies on its own domain under Stripe’s disclosures; those are not BayLedger first-party cookies.
Browser controls
Browsers can block or delete analytics cookies without preventing BayLedger's core public pages from working. Blocking the necessary authentication cookies will prevent sign-in and may interrupt protected workflows. Signing out revokes the current authenticated session and asks the browser to remove its login cookie. A password reset revokes existing login sessions for that account.
Future changes
If additional analytics, advertising, or similar technologies are introduced later, this disclosure and the applicable privacy requirements must be reviewed before those technologies are enabled.