This Cookie Policy explains how Dual Login uses cookies and similar technologies on https://duallogin.com. It should be read together with our Privacy Policy.
In plain English
A policy has to be precise, which makes it hard to read. Here is the same document answered as the questions people usually arrive with. It is a summary: where the two could be read differently, the numbered sections below govern.
Does this page mean the site is tracking me?
Not in the sense most people mean. The cookies this site sets are the ones that make a website work at all: keeping you signed in as you move between pages, remembering the region you chose, and holding the security token that stops somebody else submitting a form as you. Nothing here builds an advertising profile of you across the web.
Which cookies are actually essential?
Your session cookie and the security tokens that go with it. Delete them and you are signed out — that is the whole extent of their power. They carry a reference to a session on our side, not your name, your email or your billing details.
What about third-party cookies?
Section 3 covers them. Where a third party is involved, it is because they are doing a specific job — processing a payment, or telling us which pages are read — and not because we sold access to you. Our payment provider sets cookies on its own checkout to protect the transaction, which is also why we never see or store your full card number.
How do I get rid of them?
Every browser can block or clear cookies per site, and section 4 links to the instructions. Blocking the essential ones will sign you out and keep you out, which is a limitation of how the web works rather than a position we have taken. If you are reading this on the Dual Login product rather than the website, note that each browser profile keeps its own cookie jar — clearing one does not touch the others.
Is there an irony here, given what the product does?
There is, and it is worth naming. Dual Login exists because sites can recognise a device across accounts, and it gives each profile its own jar so they cannot. That is precisely why we keep our own cookie use to the minimum a site needs to function: it would be a strange company that sold isolation and then quietly tracked the people buying it.
How is this different from what the product does to cookies?
Completely different scopes, and the collision of vocabulary is unfortunate. This page is about cookies duallogin.com sets in the browser you are reading it with. Inside the Dual Login application, every profile gets its own isolated cookie jar, and nothing in that jar is visible to another profile or to us -- that is the product's whole purpose. Clearing site cookies here has no effect on those, and clearing those has no effect on this.
Do you use advertising or cross-site tracking cookies?
No. The cookies here keep you signed in, remember a preference, and carry the token that stops somebody submitting a form as you. There is no ad network reading this site, and no profile of you being assembled for resale -- if there were, it would be listed in section 2, because a cookie policy that omits the interesting cookies is worthless.
What is the security token cookie actually doing?
Stopping cross-site request forgery. Without it, a page on another site could quietly submit a request to ours using your logged-in session -- changing a setting or making a purchase as you, without you clicking anything. The token is a value only our forms know, so a request that lacks it is rejected. It is one of the least glamorous and most necessary cookies on any site that has a login.
Will blocking cookies here break anything I care about?
Only the parts that need to know who you are. The marketing pages, the blog, the documentation and the community read perfectly well with cookies blocked entirely. Signing in does not, and no amount of engineering changes that: a session that cannot be remembered is a session that ends on the next page load.
5. Changes
We may update this Cookie Policy as our practices or the law change. The 'Last updated' date shows when it last changed. Questions? Email privacy@duallogin.com.