What cookies and tokens are
This Cookie Policy explains how Etsy Tracker uses cookies and similar browser-side tokens across the public website, the authenticated dashboard, the account and sign-in flow, the browser extension linking flow, and the Paddle billing redirects where they apply. It is written for customers of the service, not for internal operators.
Cookies and browser-side tokens are small values that a website or a web application stores in the browser so it can remember what belongs to the same visit, the same account, or the same linked browser extension. In this service, cookies and tokens are used strictly to keep the product working: to keep a user signed in, to link the dashboard to the correct account and workspace, to connect the browser extension install to that account, to protect forms against cross-site request forgery, to return safely from Paddle-hosted billing pages, and to detect abuse.
This policy covers only the first-party cookies and tokens set by Etsy Tracker itself and the third-party cookies that Paddle may set on Paddle-hosted checkout and billing-portal pages when a paid subscription is being processed. It does not cover cookies set by websites you visit outside of Etsy Tracker — including Etsy — because Etsy Tracker does not read those cookies and does not control them.
Strictly necessary cookies
The cookies and tokens described in the following sections are strictly necessary for the core functioning of Etsy Tracker. They are not optional add-ons for tracking, marketing, or advertising. They are what makes sign-in, account continuity, security, form protection, billing redirects, plan and access state, and the connection between the dashboard and the right account or workspace actually work.
Because these cookies are strictly necessary, the service does not present a consent banner asking the user to opt into them. The service still tries to keep them to the minimum needed to run the account, and it uses first-party cookies wherever possible instead of third-party trackers.
If you block or refuse strictly necessary cookies at the browser level, parts of the service will stop working. The Managing cookies and Consequences of clearing service cookies sections below explain what breaks and what to expect.
Account and session cookies
When you sign in to Etsy Tracker, an account session cookie is set on your browser so that the dashboard keeps you signed in between page loads and between visits during the lifetime of the session. This cookie carries the minimum authentication state needed to recognize your browser as belonging to the same signed-in account.
A small companion cookie may also carry your account email in a non-sensitive form so that the dashboard can show the correct account context in the header, on billing pages, and in support forms without a full round-trip to the server for every render.
- Sign-in and session continuity between pages and between visits during the session lifetime.
- Account identity, so the dashboard, the billing area, and the support form know which account you are using.
- Paid or free access state and current plan limits, so the dashboard reflects what your subscription actually includes.
- Referral or access state that affects what is unlocked for your account.
- Returning to the correct dashboard workspace after a redirect (for example, after Paddle checkout or after opening a link from an email).
Extension install token and service identity token
When you install the Etsy Tracker browser extension and link it to your account, a first-party service identity token and an extension install token are stored in the browser. These values are set by Etsy Tracker itself; they are not Etsy cookies and they do not contain any Etsy account data. Their only job is to link this specific browser install to your Etsy Tracker account and workspace.
The Extension install token and the service identity token together tell the dashboard that the extension running in this browser belongs to the account you signed in with. They keep the workspace context consistent as you move between the dashboard and the extension, they let the service enforce plan limits per linked install, they carry the small amount of state needed for referrals and support diagnostics, and they let the service detect anti-abuse patterns such as the same install token being reused across many unrelated accounts.
These tokens are first-party to the service. They are not shared with Etsy, they are not shared with advertisers, and they are not used for cross-site tracking. They only make sense inside this product.
Security and CSRF protection
Etsy Tracker sets a security token cookie used for CSRF protection. CSRF stands for cross-site request forgery, a class of attack where a malicious site tries to trick your browser into submitting a state-changing request to a service where you are already signed in.
The Security and CSRF protection cookie carries a value that is also embedded in forms and state-changing requests inside the product. When you submit a form, the value in the cookie and the value in the form are compared, and the request is only accepted if they match. This is a standard, defensive security measure and it applies to ordinary customer actions.
- Signing in and signing out of the account.
- Changing account details or preferences from the account area.
- Ordinary dashboard actions that change stored state, such as adding a tracked shop or saving a keyword.
- Submitting feedback or support requests through the in-product form.
- Starting a billing redirect toward Paddle-hosted checkout or the Paddle billing portal.
- Blocking scripted abuse and preventing state-changing requests from being replayed by third-party sites.
Billing and Paddle
Paid subscriptions to Etsy Tracker are processed by Paddle as Merchant of Record. When you start a Paddle checkout or open the Paddle-hosted billing portal from your account, you are temporarily redirected to a page hosted by Paddle to enter your payment details, confirm your subscription, download a receipt, or manage renewal.
On those Paddle-hosted pages, Paddle may set its own cookies, session storage entries, and payment-session identifiers so that the Paddle checkout works, so that receipts are generated correctly, and so that the transaction can be tied back to your subscription on return. Those cookies are set by Paddle, on Paddle's own pages, and are governed by Paddle's own cookie and privacy notices.
When you return from Paddle to Etsy Tracker, the service reads a small amount of return-state to confirm the subscription and to restore your session in the dashboard. The Paddle checkout redirect and the Paddle billing portal redirect both rely on the account session cookie described above so that you land back on the correct account.
Etsy Tracker does not store full payment card numbers, does not store CVV codes, and does not store bank credentials. Payment card data stays with Paddle and the underlying payment networks. Only the billing identifiers and subscription status that the service needs to grant and reflect access are stored on the Etsy Tracker side.
Analytics and monitoring
Etsy Tracker does not currently deploy third-party marketing analytics cookies on the public website or in the dashboard. No third-party advertising, cross-site tracking, or behavioral marketing analytics integration is loaded from this service today, and this policy therefore does not list any such vendor by name.
What the service does do is keep operational logs and monitoring signals on the server side so it can stay reliable. This includes recording that a request happened, which route it hit, whether it succeeded or failed, and enough diagnostic context to investigate errors, to rate-limit abuse, to protect against scripted attacks, and to understand aggregate service health. These operational signals are collected on the server, not through browser tracking cookies, and they are used to run the product, not to profile visitors for advertising.
If in the future the service adds a specific analytics or monitoring integration that sets cookies in the browser, this Cookie Policy will be updated to name that integration and describe what it does before the integration is turned on for customers.
What we do not use
To make the boundary of this policy explicit, the following list describes what Etsy Tracker does not do with cookies, browser storage, or browser identity. These statements apply to both the website and the browser extension.
- We do not use Etsy cookies. The service never reads cookies set by etsy.com or by any Etsy-owned domain in your browser.
- We do not read Etsy localStorage/sessionStorage. Etsy's own client-side storage stays with Etsy.
- We do not collect private Etsy account data such as order history, buyer messages, saved payment methods, seller finances, or shop admin pages. The extension only reads what is visible on public Etsy pages that you yourself open in your browser.
- We do not use browser fingerprinting as an identity mechanism. Identity in this product is anchored to the first-party service session cookie and the service identity/install token, not to fingerprint hashes derived from your device, fonts, canvas, or hardware.
- Backend does not scrape Etsy search pages server-side. There is no headless browser or backend crawler that opens Etsy pages on the service's own initiative, and the backend does not try to bypass Etsy captcha, Cloudflare, DataDome, or similar protections.
- We do not ask for or store Etsy passwords, two-factor codes, or any other Etsy authentication material.
Managing cookies
You control the cookies stored in your browser. All modern browsers let you view the cookies that a site has set, clear them individually or in bulk, and block cookies from specific sites through the browser's site settings. Browser extensions can also be used to block or restrict cookies.
You can use those browser controls at any time on the cookies and tokens that Etsy Tracker sets. Because the cookies and tokens described above are strictly necessary for the product, the service does not promise that it works fully when they are blocked or cleared. Some parts of the account, dashboard, extension link, or Paddle billing return flow will stop working until the necessary cookies and tokens are allowed and restored.
If you use Paddle checkout or the Paddle billing portal, the browser controls that apply on Paddle-hosted pages are governed by Paddle's own cookie notice on those pages.
Consequences of clearing service cookies
Clearing or blocking the service cookies and tokens described in this policy has direct, visible consequences inside Etsy Tracker. This section is deliberately explicit so that customers can decide with full information.
- It will sign you out of the account. The next visit to the dashboard will ask you to sign in again before any account data is shown.
- It will disconnect the dashboard from your account context, so plan, workspace, and access state are no longer restored until you sign in again.
- It will unlink the browser extension from your account and you will need to re-link the browser extension by signing in again from the extension so that a fresh service identity token and install token are issued.
- It will reset or refuse account continuity signals used for anti-abuse checks, which can temporarily add friction to re-linking or to unlocking access that depends on install-token continuity.
- It will affect how plan, access, and referral state are displayed in the account and dashboard until session and identity are restored.
- It will break CSRF-protected forms until a fresh security token cookie has been issued for the new session; state-changing actions submitted with a stale token will be rejected.
- It will interrupt Paddle checkout and Paddle billing-portal return flow, because the return step depends on the account session cookie to know which account to attach the subscription to.
- It will reduce support diagnostics, because part of what support uses to investigate an account is the account and identity context carried by these cookies and tokens.
Contact and questions
Questions about this Cookie Policy, about a specific cookie or token you see in your browser, or about how a cookie affects your account can be sent through the website chat widget or Feedback on the website. Please include the account email you use to sign in and a short description of what you observed so the request can be located and answered.
Etsy Tracker does not publish a public support email address in this policy. Using the website chat widget or Feedback on the website in the product is the fastest way to reach us, and it lets us attach account context automatically. Do not include full payment card numbers, CVV codes, Etsy account passwords, or other sensitive credentials in any support message; that information is never needed to answer a cookie or privacy question.