1. Scope
This policy explains the cookies, local storage, and session storage used by Asteri LLC ("Asteri") on its public site, booking pages, and signed-in application. Browser storage can remember preferences and hold small records without sending them with every request; cookies may be sent to the relevant domain with a request.
2. Consent Categories
- Necessary: authentication, security, consent enforcement, and core booking operation.
- Functional: optional preferences, dismissed notices, and in-progress drafts.
- Analytics: first-party usage measurement that loads or persists only after analytics consent.
- Marketing: campaign attribution and measurement that load or persist only after the applicable marketing choice.
Declining optional categories does not prevent operational contact-form delivery or necessary account and booking functions.
3. Current Inventory
| Name | Type | Category | Purpose | Retention |
|---|---|---|---|---|
| asteri-cookie-consent | Cookie | Necessary | Stores the versioned cookie choices and decision time. | 180 days |
| asteri.session_token / __Secure-asteri.session_token (including legacy better-auth names) | Cookie | Necessary | Maintains a signed-in session and protects account access. | Session-managed; rotates and expires |
| asteri_active_organization_id | Cookie | Functional | Remembers the active organization for the signed-in workspace. | 30 days |
| asteri-booking-session | Cookie | Necessary | Protects and continues a public booking session. | 6 hours |
| asteri_booking_banner_* | Cookie / local storage | Functional | Remembers a dismissed booking-page announcement for one business. | Until the announcement ends, subject to a bounded maximum |
| sidebar_state | Cookie | Functional | Remembers whether the signed-in navigation sidebar is open. | 7 days |
| asteri-impersonation-* | Cookie | Necessary | Secures a time-bounded, audited administrator support session. | Until the administrator support session expires |
| asteri-theme / asteri-color-scheme | Local storage | Functional | Remembers display theme and color preferences. | Until changed or browser storage is cleared |
| asteri:site:v1:consent | Local storage | Necessary | Mirrors privacy choices so the first-party site runtime can enforce them. | Until replaced or browser storage is cleared |
| asteri:site:v1:attribution | Local storage | Analytics / Marketing | Stores consented first- and last-touch campaign attribution. | Up to 30 days; removed when applicable consent is withdrawn |
| asteri:site:v1:visitor | Local storage | Analytics | Stores random first-party visitor and session identifiers for consented analytics. | Visitor up to 400 days; session renews after 30 minutes inactivity |
| asteri:site:v1:event-queue | Local storage | Analytics / Marketing | Temporarily retries consented first-party measurement events after a delivery failure. | Up to 24 hours; removed when applicable consent is withdrawn |
| Booking drafts, referrer handoff, and ZIP progress | Session storage | Functional | Preserves in-progress booking inputs and safe navigation context in the current tab. | Current browser tab session or booking completion |
| proposal_session_id / proposal_scheduler_* / asteri:proposal-addons:* / proposal-theme | Local / session storage | Functional | Continues a public proposal review, selected add-ons, scheduling step, and theme. | Current tab for session records; saved selections until replaced or browser storage is cleared |
| asteri:project-share:guest_name / asteri:project-share:comment_secrets:* | Local storage | Functional | Remembers a guest display name and a device-bound secret used to manage shared-project comments. | Until replaced or browser storage is cleared |
| Signed-in interface preferences (asteri-* and workflow-builder-store:organization:*) | Local / session storage | Functional | Remembers selected views, panel sizes, audio devices, recent navigation, and tenant-scoped workspace drafts. | Until completed, changed, sign-out or organization cleanup, or browser storage is cleared |
| Short-lived handoffs and drafts (asteri:* / automation-workflow.* / chat:draft:*) | Session storage | Functional | Hands in-progress content between signed-in screens without publishing it. | Current browser tab, completion, or sign-out and organization cleanup |
4. Third-Party Payment Storage
Stripe may set its own cookies or browser storage when you open an embedded or hosted payment experience to process a transaction and prevent fraud. Stripe controls that storage under its Privacy Policy. Asteri does not load third-party advertising cookies in the signed-in application.
5. Managing Storage
Use the Asteri privacy banner to choose optional categories. You can also block or clear cookies and browser storage in your browser settings. Blocking necessary storage may prevent sign-in, booking continuity, payments, or security controls from working. Withdrawing optional consent causes the first-party site runtime to remove the applicable attribution, visitor, and retry-queue records.
6. Changes and Contact
We update this inventory when storage practices materially change. Questions may be sent to privacy@getasteri.com.