COOKIES & STORAGE
Essential storage, explained
Effective September 27, 2026. PhotonSells LLC uses cookies and browser storage to operate ShipCove and remember this notice. The current site does not install advertising pixels or optional analytics cookies. There are no optional tracking categories to accept or reject.
Sign-in and security cookies
__Host-ship-access holds the access token used to authenticate requests. Its browser lifetime is up to one hour. __Host-ship-refresh supports session renewal and is set for up to seven days; renewal may replace it. __Host-ship-flow protects the Google sign-in flow and lasts up to ten minutes or until the flow completes. Signing out clears ShipCove’s authentication cookies in that browser.
These cookies use Secure, HttpOnly, and SameSite protections. They are necessary for account features and cannot be switched off within ShipCove while keeping those features working. You can block or delete cookies in your browser, but sign-in and shipping features may stop working.
Browser storage
Purchase recovery: local storage holds an opaque purchase identifier so an interrupted request can be checked before you buy again. It does not contain a recipient address or label price. It is removed when the purchase outcome is resolved; otherwise it remains until resolved or browser storage is cleared.
Checkout navigation: session storage holds an opaque checkout identifier so you can return to your label checkout after signing in. It contains no address, price, or payment credentials. The app removes the return identifier when it opens the checkout; session storage also normally ends when that browser tab is closed.
Support navigation: session storage temporarily remembers a support-ticket or shipment-tracking link while you sign in. The app removes it when it opens the conversation; session storage also normally ends when that browser tab is closed.
Referral attribution: if you open a referral link, shipcove:referral in session storage remembers the first valid referral code in the current tab so it can be included when you create your account, including after Google sign-in. The code is eligible for use for up to 30 days and is removed after account creation; session storage normally ends when that tab closes. Later referral links do not replace an unexpired saved code. Expired data may remain in tab storage until replaced or the tab is closed, but is not used for attribution. This storage is not shared across unrelated websites.
Notice preference: shipcove:cookie-notice:v1 in local storage remembers that you dismissed this notice. It remains until you clear it or we change the notice version. This records a display preference, not marketing consent or acceptance of our Terms. If storage is blocked, the notice may appear again.
Display and motion: ShipCove uses its standard dark appearance and spacing. It respects your device’s reduced-motion setting without saving a display preference. Any display choices saved by an older version are ignored and removed when you open the workspace or demo.
Bot verification: where enabled, the Cloudflare Turnstile widget performs a security check during selected account requests. Verification tokens are short-lived and validated by the server; they are not used for advertising. This setup does not enable Turnstile pre-clearance cookies.
Services you choose to use
Google sign-in opens the authentication provider’s service. Choosing PayPal opens its hosted checkout, where PayPal may use its own cookies and storage under its policies. Address suggestions contact Google Places when you type into the shipping address form, and ZIP lookup contacts Zippopotam.us. Those requests provide the requested feature; dismissing this notice does not enable or disable them. Providers’ own websites may use their own cookies under their policies. See our Privacy notice for the information shared.
Your controls
Use Cookie settings to review this notice again or reset its saved dismissal. Resetting the notice does not sign you out, clear purchase-recovery records, or delete your shipping account. Use your browser’s storage controls for that browser’s cookies and stored data; check any unresolved purchase before clearing recovery records. Contact salesmanager@photonsells.com for account or data requests.
If we introduce optional analytics or advertising tools, we will update this notice and add appropriate choices before enabling tools that require consent. The current notice is not a substitute for those future controls.