Cookie Policy
Last Updated: December 17, 2025
This Cookie Policy explains how CourseDeck (“we”, “us”, or “our”) uses cookies and similar technologies when you access or use our website and SaaS platform (the “Service”).
This policy should be read together with our Privacy Policy and Terms of Service.
1. What Are Cookies?
Cookies are small text files placed on your device (computer, tablet, or mobile device) when you visit a website. Cookies help websites function properly, improve security, remember user preferences, and provide insights into how services are used.
Cookies may be session cookies (deleted when you close your browser) or persistent cookies (stored for a defined period).
2. Categories of Cookies We Use
CourseDeck uses cookies strictly necessary to operate the Service, along with limited functional and analytics cookies. We do not use cookies for behavioral advertising or profiling, especially in connection with student or minor-related services.
3. Cookie Details Table
3.1 Strictly Necessary Cookies
These cookies are essential for the operation and security of the Service and cannot be disabled.
| Cookie Name | Purpose | Duration | Legal Basis |
|---|---|---|---|
| next-auth.session-token | User authentication and session security | Session / Persistent | Contractual Necessity |
| __Host-next-auth.csrf-token | CSRF protection | Session | Contractual Necessity |
| Platform security cookies | Fraud prevention and system integrity | Session | Contractual Necessity |
3.2 Functional Cookies
These cookies enhance usability and remember user preferences.
| Cookie Name | Purpose | Duration | Legal Basis |
|---|---|---|---|
| Preference cookies | Language, UI settings | Persistent | Legitimate Interest |
| Feature enablement cookies | Enable optional platform features | Session / Persistent | Legitimate Interest |
3.3 Analytics Cookies
Analytics cookies help us understand how the Service is used so we can improve performance and reliability.
| Provider | Purpose | Duration | Legal Basis |
|---|---|---|---|
| PostHog | Product usage analytics (event-based) | Persistent | Legitimate Interest / Consent |
| Google Analytics | Aggregated traffic and usage insights | Persistent | Legitimate Interest / Consent |
Important safeguards:
- IP anonymization is enabled where supported.
- Analytics data is aggregated and used for statistical purposes only.
- No analytics cookies are used for advertising or cross-site tracking.
4. Cookies Set by Paddle (Merchant of Record)
Our payment partner Paddle.com acts as an independent Merchant of Record and may place cookies on checkout or payment-related pages.
- These cookies are used for fraud prevention, payment security, and transaction processing.
- Paddle acts as an independent data controller for payment data.
- Paddle’s use of cookies is governed by its own privacy and cookie policies.
5. Legal Basis for Cookie Use
Under GDPR and UK GDPR, CourseDeck relies on the following legal bases:
- Strictly Necessary Cookies:
Used on the basis of Contractual Necessity to provide the Service. - Functional Cookies:
Used based on Legitimate Interest in improving usability. - Analytics Cookies:
Used based on Legitimate Interest or User Consent, where required by law.
Where required, users may be presented with a cookie consent mechanism.
6. Cookies and Protection of Minors
CourseDeck is a B2B SaaS platform serving educational institutions. While student portals may be used by minors:
- Cookies used in student-facing or minor-related contexts are strictly necessary or functional only.
- Analytics data, where collected, is anonymized and aggregated.
- Cookies are never used for behavioral advertising, profiling, or marketing to minors.
Responsibility for parental consent relating to student data remains with the educational institution.
7. How to Manage or Opt Out of Cookies
You can control cookies through the following methods:
7.1 Browser Controls
Most browsers allow you to:
- Block or delete cookies
- Receive alerts before cookies are stored
Please note that disabling strictly necessary cookies may affect Service functionality.
7.2 Google Analytics Opt-Out
You may opt out of Google Analytics tracking by installing the official browser add-on: https://tools.google.com/dlpage/gaoptout
7.3 PostHog Opt-Out
Where enabled, PostHog respects browser-level Do Not Track (DNT) signals and privacy controls.
8. Updates to This Cookie Policy
We may update this Cookie Policy from time to time to reflect legal, technical, or operational changes. The “Effective Date” at the top indicates the latest revision.
9. Contact Us
If you have questions about this Cookie Policy or our use of cookies, please contact:
Email: privacy@coursedeck.com