1. What Kiweely uses
| Technology | Purpose | Duration |
|---|---|---|
| __Host-kiweely_session | Opaque signed-in website session. Secure, HttpOnly, SameSite=Lax; the server stores only its hash. | Rotating session lifetime or sign-out/revocation. |
| CSRF state | Binds authentication and sensitive browser actions to the initiating session/origin. | One attempt or short security lifetime. |
| Identity-provider session | Google Identity Platform sign-in and security, with Auth0 retained only as the migration fallback. | Under the active provider's settings and notice. |
| Email-link continuation | Temporarily keeps the entered email address in this browser so the returning secure link can be completed, including after a new tab opens. | Until link completion or browser-site data is cleared. |
| Stripe Checkout/Portal | Payment, tax, fraud, invoice, and billing session on Stripe-hosted pages. | Under Stripe settings and notice. |
2. What is not used today
The Kiweely website does not currently place advertising, cross-site tracking, social-media, or optional behavioral analytics cookies. It does not fingerprint visitors for advertising. Necessary security rate limits may process network signals, but IP alone never decides trial denial.
3. Your controls
You can block/delete cookies in browser settings, but necessary account or hosted payment flows may stop working. Sign out to revoke the current Kiweely browser session or use Security to revoke another session/all sessions. If optional technologies are introduced, we will update this Notice and provide consent controls where required before using them.