Cookies
Cookie Policy
This policy explains what we store in your browser when you use FlamePages, what is strictly necessary for the site to work, and what is only activated with your permission.
Updated on
Essentials always on
Session, language, signup and interface preferences. Without them login and navigation do not work.
Analytics and advertising only with permission
Google Analytics and PropellerAds attribution do not run before you accept. Declining limits no feature.
You can change it anytime
The “Cookie preferences” button in the footer reopens the notice at any moment.
What we store in your browser
We use four technologies: cookies, sent with every request; local storage (localStorage), which stays on your device and is never sent to the server automatically; session storage (sessionStorage), cleared when you close the tab; and IndexedDB, a local browser database the Builder uses for drafts.
The tables below include every name that FlamePages code writes to your browser, on the site, in the dashboard and on published pages. Third-party services may write their own, described under “Third parties involved”, and scripts that the owner of a published page adds are that owner’s responsibility as the controller of that site.
Essential (no consent required)
Required for authentication, security, signup and basic preferences. The legal basis is performance of the contract and the legitimate interest in keeping the service secure. They cannot be turned off without preventing use of the account.
| Name | Type | Purpose | Duration |
|---|---|---|---|
| __Host-leadsaas_token | Cookie (HttpOnly) | Keeps the authenticated session. | 15 minutes |
| __Host-leadsaas_refresh | Cookie (HttpOnly) | Renews the session without a new login. | 30 days |
| __Host-flamepages_google_oauth_state | Cookie (HttpOnly) | Protects Sign in with Google against forged requests. It only exists during that sign-in. | 10 minutes |
| fp_lang | Cookie | Carries the language you picked to the server, so each page opens in your language. | 1 year |
| flamepages_locale | localStorage | Stores the language you picked. | Until you clear it |
| flamepages_cookie_consent | localStorage | Stores your choice in the cookie notice, per category (analytics and advertising). | Until you clear it |
| flamepages_onboarding_token | localStorage | Stores the temporary signup code until you choose a plan and pay. | Until payment is completed or you clear it |
| leadsaas_pending_verification_email | localStorage | Stores the email awaiting confirmation, to resend the link. | Until you sign out, the session expires or you clear it |
The __Host- prefix makes the browser accept the cookie only from the FlamePages site itself, never from a subdomain. If you signed in before this change, you may still have the old names, leadsaas_token and leadsaas_refresh: they are accepted until November 30, 2026 and deleted when you sign out. The old name of the Sign in with Google cookie, flamepages_google_oauth_state, is no longer written and expires within 10 minutes.
Dashboard and Builder (no consent required)
Used only after you sign in, so the dashboard and the Builder work. They stay in your browser and are not sent to the server automatically.
| Name | Type | Purpose | Duration |
|---|---|---|---|
| flamepages_settings_branding | localStorage | Dashboard display preferences. | Until you clear it |
| flamepages_settings_notifications | localStorage | Notification preferences shown in the dashboard. | Until you clear it |
| client_leads_filters | localStorage | Filters for the leads list. | Until you clear it |
| admin_accounts_filters | localStorage | Filters for the accounts list, for FlamePages administrators only. | Until you clear it |
| flamepages.activeAiPageGeneration | localStorage | Resumes tracking of an AI generation in progress. | Until the generation ends |
| flamepages:builder:device-id | localStorage | Random identifier of this browser in the Builder, to tell edits from different tabs and devices apart. | Until you clear it |
| flamepages:builder:page-lock:<id> | localStorage | Records which tab is editing each page, so two tabs do not overwrite each other. | While the tab edits the page |
| flamepages:builder:palette-recents | localStorage | Recent commands used in the Builder palette. | Until you clear it |
| flamepages:builder:editor-session-id | sessionStorage | Identifies the editing session of this tab. | Until the tab is closed |
| flamepages:builder:viewport-height:<id> | sessionStorage | Stores the height of the editing area, so the screen does not jump. | Until the tab is closed |
| flamepages:ai:handoff-notice | sessionStorage | Carries a notice from the AI generation to the Builder. | Until it is read |
| flamepages_subscription_start_<id> | sessionStorage | Prevents recording the start of the same subscription twice. | Until the tab is closed |
| fp:chunk-reload | sessionStorage | Prevents reload loops when the site is updated while you are using it. | Until the tab is closed |
| flamepages-builder | IndexedDB | Local Builder draft, so edits are not lost if the connection drops. | Up to 7 days |
Analytics (only with your consent)
We use Google Analytics to understand which pages are visited and where people drop off. These cookies are only created after you accept analytics. If you decline or do not answer, no Google script is loaded.
| Name | Type | Purpose | Duration |
|---|---|---|---|
| _ga | Cookie | Distinguishes visitors. | Up to 2 years |
| _ga_<id> | Cookie | Keeps analytics session state. | Up to 2 years |
IP anonymization is enabled in our Google Analytics configuration.
Advertising (only with your consent)
With your advertising permission, we use PropellerAds attribution to learn which ad brought you here. People who arrive from an ad carry a click id in the address (the utm_prid, subid or click_id parameter).
| Name | Type | Purpose | Duration |
|---|---|---|---|
| fp_propeller_subid | Cookie | Stores the ad click id. | 30 days |
| flamepages_propeller_subid | localStorage | Stores the same id. | Until payment is completed, you withdraw permission or clear it |
With permission, the id goes along with signup, checkout start and paid subscription. Our server notifies PropellerAds of each of these events by sending only that id, and the id is also stored in the checkout metadata at Stripe. Name and email are not sent to PropellerAds.
Without permission, the id stays only in the memory of the open page: it is not stored or sent, and it disappears when you close the tab or reload the page. Declining or withdrawing permission deletes the stored cookie and item.
Cookies on published pages
Pages that customers publish run on the customer’s address (subdomain or custom domain). The FlamePages site cookie notice does not appear there, and the FlamePages Google Analytics and PropellerAds do not load there. These are the items FlamePages writes on those pages:
| Name | Type | Purpose | Duration |
|---|---|---|---|
| fp_vid | Cookie (HttpOnly) | Random identifier that keeps the visitor in the same A/B test group. It is created on the first visit to any published page, without asking for consent, even when the page has no active test. It contains no personal data. | 180 days |
| fp_analytics_consent | Cookie | Stores the visitor’s answer to the page’s analytics notice. | 1 year |
| fp_av | Cookie | Random visitor identifier, created only after acceptance. The server stores only a hash of it. | 1 year |
| fp_as | Cookie | Random session identifier, created only after acceptance. | 30 minutes of inactivity |
| fp_alp | sessionStorage | First page seen in the session, only after acceptance. | Until the tab is closed |
| flamepages:popup-seen | sessionStorage | Prevents showing a popup that was already shown. | Until the tab is closed |
| flamepages:popup-seen:<id> | sessionStorage | The same, for each popup. | Until the tab is closed |
| flamepages:form-submitted | sessionStorage | Records that a form was submitted, for the page’s display rules. | Until the tab is closed |
| flamepages:data:<key> | sessionStorage | Briefly stores data the page fetches, when the owner sets up that cache. | Until the tab is closed or the configured period ends |
| flamepages:interaction:<id> | localStorage / sessionStorage | Stores the state of page interactions, when the owner sets it to persist. | Until cleared (localStorage) or the tab is closed (sessionStorage) |
Scripts the page owner adds (Google Analytics, Google Tag Manager, Meta Pixel or custom code) may write their own cookies. Those are the page owner’s responsibility.
The visitor’s answer applies to that page and can be removed by clearing the site data in the browser. If the browser sends Global Privacy Control or Do Not Track, the page analytics does not run.
What we do not use
The FlamePages site does not use remarketing, heatmaps or session recording. The only advertising technology is the PropellerAds attribution described above, which only works with your permission. We do not sell browsing data and do not share it with data brokers.
How to change or withdraw your choice
Use the “Cookie preferences” button in the footer of any site page to reopen the notice and turn analytics and advertising on or off. Withdrawing advertising deletes fp_propeller_subid and flamepages_propeller_subid immediately. Withdrawing analytics stops Google Analytics from loading from the next page load; _ga cookies already created stay in the browser until they expire or you delete them.
You can also block or delete cookies and site data in your browser. Blocking the essential ones prevents login.
Third parties involved
Google (Analytics, only with consent, and Sign in with Google), Stripe (payment pages when you subscribe), PropellerAds (only with consent; it receives the click id through our server and loads no script on the FlamePages site) and Cloudflare (delivery and protection network in front of the site). Google, Stripe and Cloudflare may set their own cookies on the screens and services they operate, under their own policies.
Contact
Questions or requests about cookies and personal data: support@flamepages.com.
Questions about cookies
Write to our privacy contact if you want details about any item on this list.