Legal
Cookie Policy
1. About this policy
This policy explains the cookies PlentyLabs uses, what each one is for, and how to change what you allow. It covers our marketing site at plentylabs.com and the product at app.plentylabs.com. Our cookies are scoped to .plentylabs.com, so a choice you make on one covers both.
PlentyLabs is operated by Plenty Labs AB, registered in Sweden (Org.nr: 559454-1855), Vastgotagatan 2, 118 27 Stockholm. We are the data controller for the cookies described here. Cookies are one part of a wider picture — what we collect, why, and the rights you hold over it are set out in our Privacy Policy.
The short version. We set a small number of cookies the site cannot work without. Everything else — analytics and marketing — is off until you turn it on, and you can change your mind at any time from the footer of any page or the button below.
2. What a cookie is
A cookie is a small piece of text a site asks your browser to keep and send back on later requests. It is how a site remembers anything at all between page loads — that you are signed in, that you prefer a currency, that you have already answered a question like this one.
A first-party cookie is set by plentylabs.com itself. A third-party cookie is set through our pages by another company, from its own domain. A session cookie is deleted when you close the browser; a persistent one stays for the period given in the tables below. The Domain column in those tables tells you which is which.
This policy also covers the two nearby technologies we use, because treating them differently would be a distinction without a difference:
- Local storage. A larger store in your browser, read only by the site that wrote it. We mirror your cookie choices and our analytics identifiers there, so they survive being cleared in one place but not the other.
- Pixels and tags. A small script or image loaded from another company, which can set its own cookies. Ours load through Google Tag Manager and are named in section 5.
3. The three categories
We sort every cookie into one of three categories, and only the first is set without asking you. These are the same three the consent dialog offers — there is no category described here that you cannot actually switch.
- Strictly necessary — always on. Signing you in, keeping you signed in, letting your own media load, taking a payment safely, and remembering the choice you make here. There is no working version of the product without these, so they are set under our legitimate interest and cannot be switched off. They are not used to learn anything about you.
- Analytics — your choice. Which pages are read, which features are used, where people get stuck. This is how we decide what to fix. Nothing here is shared with advertisers.
- Marketing — your choice. Which campaign brought you to us, and reporting a sign-up back to the ad platform that earned it. We use this to measure our own advertising.
We do not sell your data, and we do not use cookies to profile you for other advertisers. We also do not use behavioural advertising or personalised ad targeting against our own users. The marketing cookies above measure campaigns we paid for; they do not build an audience profile to be traded.
4. Cookies we set
Lifetimes are maximums. A cookie can disappear sooner — you clear it, you log out, your browser expires it on its own schedule. A name written with … is a pattern: the full name ends in an identifier for our account with that provider.
4.1 Strictly necessary
| Cookie | Domain | Set by | What it does | How long it lasts |
|---|---|---|---|---|
| plenty.session_token | .plentylabs.com | PlentyLabs | Keeps you signed in to your workspace. Set when you log in and deleted when you log out. | 7 days, extended while you keep using the product |
| plenty.session_data | .plentylabs.com | PlentyLabs | A short-lived signed copy of your session, so an ordinary page load does not need a database read to know who you are. | 60 seconds |
| plenty.oauth_stateand plenty.account_data | .plentylabs.com | PlentyLabs | Written for the few seconds you are away at Google, Meta or Epidemic Sound signing in, and checked when you come back. They are what stops someone else's sign-in being completed in your browser. | Deleted as soon as the sign-in finishes |
| plenty.dont_remember | .plentylabs.com | PlentyLabs | Records that you asked not to be remembered, so your session ends when you close the browser. | Until the browser closes |
| CDN-Cookie | cdn.plentylabs.com | PlentyLabs | A signed credential that authorises your browser to load your own images, video and audio from our CDN. Your media does not render without it. | Expires with your session, or after 1 hour on a shared review link |
| plenty_cookie_consent | .plentylabs.com | PlentyLabs | Remembers the choices you make on this page, so we do not ask you again on every visit. | 1 year |
| plenty_consent_source | .plentylabs.com | PlentyLabs | Records whether those choices were made by you explicitly or implied by your region, so an explicit choice is never quietly overwritten by a later region lookup. | 1 year |
| plenty_geo | .plentylabs.com | Fastly (our CDN) | Tells the page which region your request came from, so we apply the right consent rules and show prices in a sensible currency. It holds a region — eu or row — and nothing narrower. | Refreshed at our CDN edge on each region lookup |
| __stripe_mid | .plentylabs.com | Stripe | Set by Stripe's payment form when you reach the plan step, to detect card fraud. We never see your card details; they go straight to Stripe. | 1 year |
| __stripe_sid | .plentylabs.com | Stripe | The same fraud check, scoped to the single checkout you are completing. | 30 minutes |
4.2 Analytics — set only with your consent
| Cookie | Domain | Set by | What it does | How long it lasts |
|---|---|---|---|---|
| ph_…_posthogone cookie, named after our PostHog project | .plentylabs.com | PostHog | Groups your page views into a single visit, so we can see which pages are read and where people get stuck. Inside the product it also carries the identifier for session replay — a reconstruction of how the interface behaved, which we use to diagnose bugs. | 1 year |
| _gaand _ga_… | .plentylabs.com | Google Analytics, via Google Tag Manager | Tells one visitor from another and one visit from the next, for traffic reporting. | 2 years |
4.3 Marketing — set only with your consent
| Cookie | Domain | Set by | What it does | How long it lasts |
|---|---|---|---|---|
| plenty_attribution | .plentylabs.com | PlentyLabs | Remembers the campaign, referrer and landing page of your first visit — the utm_ parameters plus gclid, fbclid, msclkid and ttclid — so that if you sign up later we can tell which campaign brought you. Deleted the moment you withdraw marketing consent. | 90 days |
| _gcl_au | .plentylabs.com | Connects an ad click to a later sign-up, so Google Ads can report the conversion. | 90 days | |
| _fbp | .plentylabs.com | Meta | The same measurement for the ads we run on Facebook and Instagram. | 90 days |
| _zitok | .plentylabs.com | ZoomInfo | Holds an opaque identifier for your visit, which ZoomInfo's WebSights tag uses alongside your IP address to work out which company you are visiting from. It identifies an organisation, not you. | 1 year |
5. Third parties
5.1 Companies that set cookies through our pages
Five, and every one except Stripe only after you allow the matching category. Each handles that data under its own policy, which we cannot change on your behalf:
- Stripe (payments and card-fraud detection, strictly necessary) — stripe.com/privacy. Loaded only on the plan step, not on ordinary pages.
- PostHog (analytics and session replay) — posthog.com/privacy. We run PostHog on its EU cloud.
- Google (Google Tag Manager, Google Analytics, Google Ads) — policies.google.com/technologies/cookies.
- Meta (advertising measurement for Facebook and Instagram) — facebook.com/policies/cookies.
- ZoomInfo (company identification) — zoominfo.com/about/privacy-center.
Stripe, Google, Meta and ZoomInfo are in the United States, so allowing marketing cookies — or reaching the payment step — involves a transfer of personal data outside the EEA. Those transfers rely on the European Commission's Standard Contractual Clauses and, where the recipient is certified, the EU–US Data Privacy Framework. Our Privacy Policy covers international transfers in full.
Separately from cookies, the companies that process customer data on our behalf to run the product are listed in our subprocessor register, which we will send you on request from privacy@plentylabs.com.
5.2 Embedded video
One of our campaign pages embeds a video. It loads from youtube-nocookie.com, YouTube's privacy-enhanced player, and only once you click play — until then the page shows a still image and YouTube has set nothing. Pressing play lets Google set cookies on its own domain, under the policy linked above. No other page embeds third-party content.
5.3 Sites we link to
This policy covers our own pages. It does not cover other sites we link to — a social profile, a booking page, a provider's documentation — and we are not responsible for their cookies or their privacy practices. Read their policies on their own terms.
6. How we ask, and what we do with silence
On your first visit you get a dialog with two real options — accept everything, or choose category by category. Nothing optional is set before you answer it.
- In the EU and the UK, the dialog must be answered before anything optional is set. We do not treat scrolling, dismissing, or carrying on browsing as consent.
- Outside the EU and the UK, where local law allows it, analytics and marketing start enabled and the dialog tells you so. You can turn either off at any time, and doing so takes effect immediately.
- If your browser sends Do Not Track, we honour it: we do not show the dialog and we set nothing optional.
- We never read the policy page itself as an answer. Arriving here does not consent to anything, and the dialog will not block the page while you read it.
7. Changing your mind
Your choices are not final. Cookie preferences in the footer of every page reopens the dialog, as does this button:
Withdrawing consent stops the relevant cookies being set from that moment, and we delete the first-party ones we control — the attribution cookie goes immediately. A third-party script already loaded into the open page cannot be unloaded until you navigate or reload, and cookies a third party has already set are cleared through your browser, as below.
8. Controlling cookies in your browser
Your browser can block or delete cookies for any site, including ours, independently of anything on this page:
Be aware of what that costs: blocking all cookies will sign you out of PlentyLabs and stop your own media loading, because the cookies in section 4.1 are how both of those work. Clearing cookies also erases the record of your choices here, so you will be asked again.
9. Changes to this policy
When we add, remove or repurpose a cookie, we update the tables above and raise the version at the top of this page in the same change. If a change widens what we collect or what we use it for, we will ask for your consent again rather than rely on the answer you gave to a narrower question.
10. Contact
Questions about this policy, or about a cookie you have found that is not listed here, go to privacy@plentylabs.com. For your GDPR rights — access, erasure, objection — and how to complain to a supervisory authority, see our Privacy Policy. Ours is the Swedish Authority for Privacy Protection (IMY).