Effective date: October 2, 2026
EventSage uses only the cookies and browser storage needed to sign you in, keep your account secure, take payments and remember your settings. We don't use advertising cookies, tracking pixels or third-party analytics in the app, and we don't track you across other websites. Because everything we use is essential, there's nothing to accept or reject.
This policy is part of our Privacy Policy and applies to eventsage.io, app.eventsage.io and the client pages Operators send (proposals, contracts, invoices, forms and payment pages).
What cookies and browser storage are
Cookies are small text files a website saves in your browser. Browser storage (local storage and session storage) works similarly but stays on your device and isn't sent with every request. We use both.
Cookies we use
| Cookie | Set by | Purpose | How long |
|---|---|---|---|
| authjs.session-token | EventSage | Keeps you signed in to your account | Ends after 7 days of inactivity, and no more than 30 days (12 hours for administrators) |
| authjs.csrf-token | EventSage | Protects sign-in forms from forged requests | Browser session |
| authjs.callback-url | EventSage | Returns you to the right page after you sign in | Browser session |
| esp_[event ID] | EventSage | Keeps a client signed in to the client portal for one event | 14 days |
| espc_[event ID] | EventSage | Holds a one-time sign-in code challenge for the client portal | 1 hour |
| sidebar:state | EventSage | Remembers whether you collapsed the app sidebar | 7 days |
| Stripe cookies | Stripe | Fraud prevention and secure payments on payment and payout screens | Set by Stripe. See Stripe's cookie policy |
In production, our sign-in cookies may carry a __Secure- or __Host- prefix. That's a browser security feature, not a different cookie.
Browser storage we use
The app saves preferences in your browser so it looks the way you left it. That includes which business you're working in, your calendar view, list and filter choices, panel widths, banners you've dismissed, and drafts in progress during onboarding and email composing. None of it is used for tracking, and you can clear it anytime in your browser settings.
The app also installs a service worker so it can work like an installed app and deliver push notifications you turn on.
Other things that load from third parties
- Google Fonts. Some pages load fonts from Google's servers, which means Google receives your IP address and browser information. Google says it doesn't use this to profile you. See Google's privacy policy.
- Embedded scheduling pages. If an Operator adds a booking link from a scheduling service (like Calendly or Cal.com) to a proposal, that service may set its own cookies when the page loads. Its own cookie policy applies.
- Inquiry forms on Operators' websites. When an Operator embeds an EventSage form on their own site, that site may use its own cookies and analytics. That's governed by the Operator's policies, not ours.
Emails sent through EventSage can include a small image that tells the sender whether the email was opened. Many email apps let you block images to prevent this.
How to control cookies
You can block or delete cookies in your browser settings. If you block the essential cookies above, you won't be able to sign in, use the client portal or make payments.
Changes
If we ever add cookies that aren't essential, such as analytics, we'll update this policy first and ask for your consent where the law requires it.
Contact
Questions? Email support@eventsage.io.