Cookie Policy
Last updated September 30, 2026
Zdue uses first-party cookies and browser storage only when they are needed to run the site. We do not use advertising cookies, analytics pixels, or third-party tracking embeds. A first visit to the public waitlist does not set cookies.
Do you need to accept cookies?
There is no cookie banner because we do not set non-essential cookies on page load. The cookies below are strictly necessary for authentication, invite gates, or a security handshake you start. You can still refuse them by not signing in, not unlocking gated pages, or blocking cookies in your browser. Blocking them will sign you out or prevent those flows from working.
Cookies we set
| Cookie | Purpose | How long | When it is set |
|---|---|---|---|
| sb-*-auth-token (and .0 / .1 chunks if needed) | Keeps you signed in to the product. | Session / refresh cycle | After you sign in |
| sb-*-auth-token-code-verifier | Completes the sign-in security handshake (PKCE). | Short-lived during sign-in | During email or OAuth sign-in |
| zdue_signup_access | Remembers that you unlocked invite-only signup. | 7 days | After you enter the signup password |
| zdue_waitlist_inbox | Remembers that you unlocked the waitlist inbox. | 7 days | After you unlock the inbox |
| client_session | Keeps a customer signed in to the invoice portal. | 30 days | After client-portal sign-in |
| qbo_oauth_state | Stops Cross-Site Request Forgery while connecting QuickBooks. | 10 minutes | When you start a QuickBooks connection |
Local storage (signed-in product only)
- onboarding_completed — Skips the onboarding redirect after you finish setup.
- user_has_setup — Routes you past setup if your account is already configured.
- zdue:invoices-sort — Remembers how you sorted the invoice list.
Waitlist campaign data (not a cookie)
If you arrive with UTM parameters or a referrer and then submit the waitlist form, we store those values with your signup so we know which campaign brought you. They are not written as browser cookies.
How to clear them
Use your browser settings to delete cookies and site data for Zdue. That signs you out of the product, client portal, signup gate, and waitlist inbox. Questions: subs@zdue.net. See also the Privacy Policy.
Operator details
Zdue is operated at zdue.net for US businesses. These pages are governed by the laws of the State of California.
Contact: subs@zdue.net.
A US mailing address is used on commercial email when configured. Until then, subs@zdue.net is the notice address for these pages.