Cookies and Local Storage
- Version
- 2.0
- Effective date
- August 23, 2026
1. Scope
This notice explains which cookies, Local Storage, Session Storage and comparable storage mechanisms AcrossEstate currently uses.
AcrossEstate is a platform operated by Black Coast Capital LLC. Privacy inquiries may be sent to privacy@acrossestate.com.
2. What are cookies and local storage technologies?
Cookies are small pieces of information that a browser may store in connection with a website. Modern web applications may also use Local Storage and Session Storage. These technologies store information in the browser or on the user's device and, depending on the function, may contain personal data or technical identifiers.
3. General principle
AcrossEstate currently does not use external web analytics or marketing tracking services such as Google Analytics, Meta Pixel or TikTok Pixel.
Technically necessary storage mechanisms are used where required for security, authentication, session management or a function expressly requested by the user. Optional storage mechanisms are activated only where permitted by applicable law and, where required, after valid consent has been obtained.
For users in the European Union and the European Economic Area, the requirements derived from Article 5(3) of the ePrivacy Directive and the respective national implementation are taken into account. Where personal data is involved, applicable data protection law, including the General Data Protection Regulation where applicable, applies in addition.
4. Consent decision
Key: acrossestate.cookies
Technology: Local Storage
Purpose: Store selected categories, consent version and decision timestamp
Category: Essential
Retention: Until browser storage is cleared or a new consent version requires a new decision
The consent manager can be reopened through the function provided on AcrossEstate. A previous decision can be changed there.
5. Language
Key: acrossestate.locale
Technology: Local Storage
Purpose: Store the selected language
Category: Preference
Retention: Until changed by the user or browser storage is cleared
6. Currency
Key: acrossestate.currency
Technology: Local Storage
Purpose: Store the preferred display currency
Category: Preference
Retention: Until changed by the user or browser storage is cleared
Additional key: acrossestate.currency.explicit
Purpose: Store whether the currency was explicitly selected by the user
Retention: Until changed or browser storage is cleared
7. Recent searches
Key: acrossestate.recentSearches
Technology: Local Storage
Purpose: Locally provide recent search queries for faster use
Category: Preference
Retention: Until overwritten, removed or browser storage is cleared
Under the current codebase, no more than five recent searches are stored locally. The existence of this local storage is not, by itself, used to create an advertising profile.
8. Search and results context
Key: acrossestate.resultsContext
Technology: Session Storage
Purpose: Restore the current search, map or results context within the same browser session
Category: Essential or expressly requested session function
Retention: Generally until the browser session ends
9. Return path after sign in
Key: acrossestate.returnTo
Technology: Session Storage
Purpose: Return the user to the previously requested internal page after successful sign in
Category: Essential authentication function
Retention: Until used successfully, removed or the browser session ends
10. Linking a previous inquiry
Key: acrossestate.pendingClaim
Technology: Local Storage
Purpose: Link a real estate inquiry previously submitted as a guest to an account that is subsequently created or signed in
Category: Account and inquiry function requested by the user
Retention: Until successfully linked, programmatically removed or browser storage is cleared
The corresponding server-side claim token is currently limited to 30 days.
11. Authentication session
AcrossEstate uses Supabase Auth within its current authentication infrastructure. For signed in users, a project-specific authentication session is stored in browser Local Storage.
Provider: Supabase and the authentication infrastructure integrated with Lovable Cloud
Technology: Local Storage
Purpose: Maintain sign in, manage sessions and automatically refresh valid authentication information
Category: Essential for signed in users
Retention: Depends on session, token lifetime, sign out, account security and authentication configuration
The exact technical key is generated by the authentication library and may change through technical updates.
12. External sign in
If a user voluntarily chooses sign in through Google or, where available, Apple, the relevant identity provider may use its own cookies or other technical identifiers as part of its sign in process. The provider's own privacy information and settings apply to that processing in addition.
13. Mapbox
AcrossEstate uses Mapbox for interactive maps. Loading maps sends technical requests to Mapbox and necessarily transmits the IP address. Mapbox may also process technical session or usage identifiers for the delivery, security and billing of its mapping services.
AcrossEstate does not use Mapbox for the purpose of creating an advertising profile within AcrossEstate. Further information on data flows is provided in the AcrossEstate Privacy Policy.
14. Local calculators and scenario functions
Where calculators, scenarios or comparison functions run exclusively in the browser, the calculation takes place on the user's device. The mere local calculation does not automatically result in the entered values being transmitted to AcrossEstate or stored on a server.
If server-side storage, synchronisation or account linking of such values is introduced later, this notice and the Privacy Policy will be updated before or when that functionality is introduced.
15. Analytics and engagement
AcrossEstate does not use Google Analytics, Meta Pixel, TikTok Pixel or any comparable external analytics or advertising service. There is no cross-site tracking, no session recording and no advertising identifier.
AcrossEstate operates its own first-party measurement, which is loaded and started only after the visitor has actively consented to the Analytics and engagement category. Before consent, no measurement identifier is created, no timer runs and no measurement request is sent.
What is recorded is factual only and limited to this closed list: that a project page or comparison was opened; that a project or unit was saved or unsaved; that a named project section remained meaningfully visible for about 1.2 seconds; that an item was actively viewed in the full media viewer; that a person explicitly opened a unit type's details, interiors or available units; and how long a page was genuinely visible in the active browser tab. Thumbnail impressions and fast scroll-bys do not count. No text entered by a user, search terms or free text are recorded as measurement data.
Key: acrossestate.analyticsReceipt
Technology: Local Storage
Purpose: Identify the current server-side consent record issued for this browser and allow the browser to prove its authority to withdraw that consent. It stores an opaque receipt identifier, the consent policy version and a random withdrawal capability. It contains no behavioural history and measures nothing. The plaintext withdrawal capability exists only in this browser; the server stores only its cryptographic hash.
Category: Consent administration
Retention: Until consent is withdrawn, a new consent version applies or browser storage is cleared
Key: acrossestate.analyticsWithdrawalPending
Technology: Local Storage
Purpose: Temporarily retains the receipt identifier, version and withdrawal capability when a withdrawal could not yet be confirmed by the server, so that the revocation can be retried later. This record never enables analytics: local measurement is already switched off while it exists, and the record is removed once the server confirms the withdrawal.
Category: Consent administration
Retention: Until the server confirms the withdrawal or browser storage is cleared
Key: ae.visitor.session
Technology: Session Storage
Purpose: Random, session-scoped identifier that allows events of one browsing session to be related to each other. It is created only after valid consent and a valid server-side receipt exist, and it is not derived from an account, an email address, an IP address or a device fingerprint.
Category: Analytics and engagement (only created after consent)
Retention: Removed on withdrawal; otherwise it ends with the browser session
For signed in users, measurement events are attributed to the account at the moment the event occurs, because the account is the identity the user has chosen, and authorised AcrossEstate staff can see that factual activity. The consent record itself carries no account identity. Withdrawing consent switches measurement off immediately and deletes the behavioural data recorded under the withdrawn consent.
Behavioural measurement data is retained for a maximum of 180 days.
16. Marketing technologies
AcrossEstate does not use marketing pixels from Meta, TikTok or comparable advertising networks, and the marketing category is not offered in the consent manager because no such technology is in use. Future marketing or retargeting technologies would be reviewed before activation and, where required, loaded only after consent.
17. Consent categories
The current consent manager offers:
- Essential. Always active.
- Preferences. Optional.
- Analytics and engagement. Optional, off by default.
Marketing exists technically in the consent model but is not offered as a choice, because no marketing technology is active.
Essential functions cannot be disabled where they are necessary to provide an expressly requested service or to ensure secure operation. Optional categories are disabled by default before a choice is made, and rejecting is as easy as accepting.
18. Changing settings and clearing browser storage
Users can reopen and change their consent settings through AcrossEstate. Cookies, Local Storage and Session Storage can also be deleted through the settings of the browser being used.
Deleting authentication or session data may sign the user out. Deleting preference data may require language, currency or other settings to be selected again.
19. Changes
This notice will be updated when new storage mechanisms, analytics tools, marketing technologies or other relevant technical functions are introduced or removed.