PluginChatBot
Home
Integrations
HubSpot Integration WhatsApp Integration Messenger & Instagram Live Chat Handoff Explore All Integrations
Installation Pricing
Contact Us Login Start Free Trial→
Dashboard
Home
Integrations HubSpot Integration WhatsApp Integration Messenger & Instagram Live Chat Handoff Explore All Integrations
Installation Pricing Contact Login Start Free Trial→
Dashboard

Legal document

Cookie Policy

How PluginChatBot uses cookies, local storage, session storage and related technologies across its websites and application.

Version 1.0 | Effective 21 September 2026

1. About this policy

This policy explains cookies and similar browser technologies used in connection with pluginchatbot.com, app.pluginchatbot.com and PluginChatBot widgets. It should be read with the Privacy Policy. PluginChatBot is provided by NAFCORP PTY LTD. Questions may be sent to sales@pluginchatbot.com.

A cookie is a small item stored by a browser and returned with applicable requests. Local storage and session storage are separate browser mechanisms used to remember information on a site. Tags, pixels and network requests can transfer information even when no conventional cookie is set. Clearing a browser cookie does not, by itself, delete information already held in an account, conversation database or connected service.

2. Necessary service functions

We use browser technologies to maintain authenticated sessions, remember an appropriate workspace or interface state, protect the service and support a conversation requested by a visitor. These functions must not be reused for unrelated advertising merely because the same identifier is available. Some optional convenience storage may be disabled or cleared at the cost of losing that preference.

The following inventory describes the reviewed source implementation. Environment-specific names, active tracking tags and production lifetimes must be checked before the publication version is approved.

Login session - pluginchatbot_session

This cookie maintains an authenticated PluginChatBot account session. The reviewed implementation sets host-scoped and shared-domain variants where configured, with HttpOnly, SameSite=Lax and Secure on HTTPS. The source lifetime is seven days and can be refreshed by activity. Logging out clears the relevant cookies and invalidates the associated session. Production or test environments may use a different configured cookie name.

Privacy choice - pluginchatbot_consent_v1

This local-storage item records an accepted or rejected non-essential tracking choice. The reviewed implementation stores the value until browser storage is cleared; it does not currently attach its own time-based expiry. It is used to remember a choice, not to store a conversation. The publication inventory must be updated if the choice system is changed to use a timed or more detailed record.

Workspace, builder and interface preferences

The application uses browser storage for the selected workspace, bot-builder drafts, editing identifiers and some interface or tour preferences. Keys may be scoped to a workspace, user or view. Persistent local-storage items generally remain until removed by the application or browser. A draft stored in session storage normally lasts for the page session, subject to browser behaviour.

Drafts may contain business configuration or text you have entered. Avoid a shared or untrusted browser for confidential configuration. The developer must verify whether any legacy API-key draft is still held in session storage and remove unnecessary credential persistence. Browser preference storage must not be described as anonymous where it is linked to an account.

Widget visitor and conversation continuity

An embedded widget may use a bot-specific visitor identifier in the browser to associate messages with an ongoing or returning conversation. The reviewed implementation uses long-lived local storage rather than a universal fixed cookie expiry. The exact key depends on the widget implementation. It must not be treated as proof of a person's identity or permission to disclose another person's conversation.

A business installing the widget must explain relevant storage and collection in its own website notice. A visitor's request to chat is not permission for unrelated advertising or cross-website profiling. Clearing widget storage may remove continuity on that browser without erasing records already held by the business or PluginChatBot.

3. Optional analytics and advertising

The marketing site contains code for Google consent signalling and conversion events. Where optional analytics or advertising services are enabled, they may process page interactions, device and browser information, online identifiers and campaign information according to the relevant configuration and choice.

The reviewed choice interface offers acceptance or rejection of non-essential tracking. It initially sends denied consent signals unless a prior acceptance has been stored. A denied Google consent signal is not, by itself, a promise that no request reaches Google: some configurations permit cookieless measurement. The final implementation and published description must match the verified network behaviour.

We must not send message bodies, uploaded customer documents, passwords, payment secrets or sensitive health information to advertising tags. We must also avoid sending email addresses or other unnecessary identifiers through page addresses or analytics event properties. Optional analytics and advertising must be assessed separately from essential authentication and service-security processing.

The precise cookie names, recipients and lifetimes for active Google Analytics, advertising or other tags depend on the deployed container and vendor configuration. They are not asserted here from a generic list. The approved publication inventory must identify the actual optional technologies in use and the controls that apply to them.

4. Third-party payment and security interfaces

Stripe may use cookies and similar technologies when you open its hosted payment or billing interface. Cloudflare may use necessary security technologies for a configured protection or challenge. The technology used depends on the service and settings; not every vendor cookie is placed on every visit. Their relevant notices apply to their own handling, alongside any responsibility we have for selecting and configuring the service.

Customer-selected messaging or CRM services may have their own browser technologies and notices. Connecting one of those services does not make all its tracking essential to PluginChatBot.

5. Managing and withdrawing choices

Use the available tracking-choice interface to accept or reject non-essential tracking. A rejection should not prevent access to ordinary product information or necessary account functions. Where separate preference categories are available, you may choose them independently. A choice about cookies is separate from agreement to the Terms and separate from an email-marketing subscription.

Until a persistent "Privacy choices" control is available throughout the site, you can clear PluginChatBot's site storage in your browser and revisit the marketing site to make a new choice. This may also sign you out or remove local drafts and preferences. Contact us for assistance without sending your password. The developer must replace this interim instruction with the tested preference-control instructions when that control is released.

Browser settings can also restrict or remove cookies and site storage. Blocking necessary session cookies may prevent login. Third-party sites such as a hosted payment page may require their own settings. Withdrawing a choice affects future optional handling; we will separately consider a request about information already collected under the Privacy Policy.

6. Keeping this policy accurate

We will update the inventory and choice information when relevant technology changes. A change in tracking purpose may require a fresh choice rather than reliance on a previous acceptance. We will not state that browsing the site alone provides unlimited consent to tracking.

This policy is not a claim that every Australian website is legally required to display the same cookie banner. Our obligations depend on the information collected, its use and disclosure, applicable laws and the commitments we make. We use notices and controls appropriate to those activities and must honour the choices we offer.

Legal documents

Privacy Policy Terms of Service Acceptable Use Policy Data Processing Addendum Subprocessors Cookie Policy AI Usage & Safety
PluginChatBot

Build a free chatbot for your business in minutes, no code or technical expertise needed. Capture HubSpot leads and manage Messenger, Instagram, and WhatsApp conversations in one place with ease.

Start your free PluginChatBot trial Start Free Trial

Platforms

WordPress ChatbotWooCommerce ChatbotShopify ChatbotWix ChatbotWebflow ChatbotSquarespace ChatbotCustom Website Chatbot

Solutions

Customer Support AI ChatbotEcommerce AI ChatbotSales AI ChatbotMarketing AI ChatbotHealthcare AI ChatbotLead Generation ChatbotLocal Business AI ChatbotSmall Business AI Chatbot

Features

AI ChatbotLead CaptureKnowledge BaseIntegrations

Integration

WhatsAppHubSpotMessenger & InstagramLive Chat handoff

Company

AboutContactPricingLegal

Resource

Chatbot TrainingSecurity and control24/7 supportBlogFAQsBook a Demo
© 2026 PluginChatBot · A product of NAFCORP TECHNOLOGIES