Controller: CORE FLIGHT TECHNOLOGIES LLC Last updated: September 30, 2026

This Cookie Policy explains how CORE FLIGHT TECHNOLOGIES LLC (“Core Flight Technologies,” “we,” “us,” or “our”) uses cookies, pixels, local storage, software development kits, server-side event technologies, and similar technologies on coreflighttech.com (the “Website”). It should be read together with our Privacy Policy.

1. What These Technologies Are

A cookie is a small text file stored on a browser or device. Similar technologies include pixels, tags, scripts, local or session storage, device identifiers, and server-side event connections. They may remember a cart or preference, keep an account secure, measure Website activity, support chat and forms, attribute a referral, or measure advertising results.

Some technologies are set directly by the Website (“first-party”), while others are provided by third parties whose services appear on or connect to the Website (“third-party”). Some are deleted when the browser session ends, while others remain for a defined period or until deleted.

2. How We Classify Technologies

Strictly Necessary

These technologies are required to provide a service requested by the user or to operate essential functions such as cart and checkout, account login, security, fraud prevention, load balancing, network transmission, and recording privacy choices. Where the law permits, they operate without optional consent. Blocking them may prevent the Website, account, cart, checkout, payment, or security functions from working correctly.

Preferences and Functionality

These technologies remember optional choices or enable features such as recently viewed products, chat, embedded forms, or display preferences. They are not always essential to purchase a product. Where required by law, they operate only after consent.

Analytics and Performance

These technologies help us understand visits, navigation, product views, searches, cart and checkout activity, campaign attribution, errors, and Website performance. Where required by law, they operate only after consent.

Advertising and Measurement

These technologies measure advertising activity, attribute conversions, limit or personalise advertising, or create advertising audiences. They may connect activity across websites or services. Where required by law, they operate only after consent and are also subject to applicable sale, sharing, or targeted-advertising opt-out rights.

3. Technologies Used on the Website

The inventory below reflects technologies observed or embedded during the latest Website audit. Exact names, durations, and provider behaviour can change when providers, plugins, or configurations are updated. The live consent-management panel should show the current service-level inventory.

A. Essential Commerce, Account, Security, and Payment

Provider or service Examples observed or expected Purpose Typical category
WordPress / WooCommerce WooCommerce cart, session, account, checkout, and fragment storage; WordPress login or settings cookies where applicable Maintain cart contents, customer session, checkout, account access, and core Website functions Strictly necessary; settings features may be functional
Stripe __stripe_mid and other Stripe payment, authentication, or fraud-prevention technologies Process and secure payment attempts, detect fraud, and support payment authentication Strictly necessary when used for payment/security
Google reCAPTCHA reCAPTCHA scripts, device or browser storage, and related security signals Protect forms and the Website against spam, bots, and abuse Strictly necessary only on protected forms where proportionate
Consent-management technology Consent record and preference storage Remember whether optional categories were accepted or rejected Strictly necessary for privacy-choice management

B. Preferences, Forms, Chat, and Customer Features

Provider or service Examples observed or expected Purpose Typical category
Woodmart / WooCommerce Recently viewed products and interface or cart-related browser storage Remember product or interface activity requested by the user Preferences/functionality; essential where directly required for cart operation
HubSpot messagesUtk and related chat, form, or browser storage Provide chat, remember chat sessions, and support form or customer-service interactions Preferences/functionality; may also involve analytics
Sender Newsletter form and popup preference storage Display subscription forms, remember popup interaction, and process an optional subscription Preferences/functionality and marketing
Review or feedback features Review session or submission technologies where enabled Submit, display, or verify product feedback Preferences/functionality

C. Analytics, Attribution, and Performance

Provider or service Examples observed or expected Purpose Typical category
Automattic / Jetpack / WooCommerce Analytics tk_ai, tk_lr, tk_or, tk_r3d and related analytics storage Measure visits, referrers, commerce interactions, and Website performance Analytics/performance
Burst Statistics burst_uid and related first-party analytics storage Measure visits and Website usage Analytics/performance
HubSpot analytics hubspotutk, __hstc, __hssc, __hssrc and related storage Measure sessions, page activity, form interactions, and customer journeys Analytics/performance
WooCommerce Sourcebuster / attribution sbjs_* values and related browser storage Record referral source, campaign, and first or current visit attribution Analytics/attribution
GoAffPro Affiliate or referral identifiers and related storage Attribute visits, leads, or orders to an affiliate Analytics/attribution; may also be advertising depending on configuration

D. Advertising and Conversion Measurement

Provider or service Examples observed or expected Purpose Typical category
Meta Pixel _fbp, browser event identifiers, pixels, and related storage Measure page, product, cart, checkout, lead, and purchase-related events; attribute advertising; support audiences where enabled Advertising and measurement
Meta Conversions API Server-side event data, event identifiers, and matching information Measure and attribute conversions, improve event reliability, and deduplicate browser/server events Advertising and measurement; server-side processing may continue to require privacy controls even when no browser cookie is set

4. Duration

Session technologies expire when the browser session ends. Persistent technologies remain for a defined period or until deleted. Duration is determined by the purpose, our configuration, and the provider’s settings.

The live consent-management panel states the current duration for each individual cookie or storage item. We will review durations periodically and use a shorter period where reasonably sufficient for the stated purpose.

5. Consent and Your Choices

Where consent is required, non-essential preferences, analytics, advertising, and measurement technologies must remain disabled until the user makes an informed, affirmative choice.

The Website’s consent mechanism provides:

  • Accept all and Reject non-essential choices with comparable prominence and ease;
  • category-level controls for optional technologies;
  • no preselected optional categories;
  • access to the Website even when optional technologies are refused, except where an optional feature itself cannot operate without its associated technology;
  • a persistent link or control allowing preferences to be changed or consent to be withdrawn; and
  • a record of the choice, version, categories, date/time, and relevant consent configuration.

Withdrawing consent does not make earlier processing unlawful, but it should stop future optional storage or access covered by that consent. Previously stored technologies may remain until they expire or are deleted, unless the consent tool removes them.

Browser settings can also block or delete cookies. Doing so may affect account, cart, checkout, payment, form, chat, or preference functions. Browser “Do Not Track” signals are not interpreted uniformly. We will process legally recognised opt-out preference signals where required and supported by the final privacy configuration.

6. U.S. Sale, Sharing, and Targeted-Advertising Choices

We do not sell personal data for money. However, advertising identifiers, browsing activity, and conversion events disclosed to advertising or measurement providers may be treated as a “sale,” “sharing,” or targeted-advertising processing under some U.S. state privacy laws.

Where applicable, users may opt out through the Website’s privacy or cookie controls or by emailing info@coreflighttech.com with the subject “Privacy Request.” We will honour recognised browser-based opt-out preference signals where legally required and technically supported.

7. Third-Party Services

Third-party providers may receive device, browser, network, event, account, form, payment, or interaction information according to the service used. Depending on the service and law, a provider may act as our processor, an independent controller, or another participant in processing. Its own privacy and cookie documentation may also apply.

The presence of a provider in this Policy does not mean every service operates on every page or for every user. Availability may depend on page, country, consent choice, login status, cart or checkout activity, and provider configuration.

8. Server-Side Events

Some measurement or security activity can occur through server-to-server connections rather than a browser cookie. This includes Meta Conversions API event processing and may include payment, fraud, commerce, or security events. Server-side processing is described in the Privacy Policy and must follow applicable consent, opt-out, data-minimisation, and legal-basis requirements even when it does not store information directly on the user’s device.

9. Updates to This Policy

We may update this Policy when technologies, providers, laws, or business practices change. The “Last updated” date identifies the current version. Material changes will be communicated or renewed consent will be requested where required.

10. Contact

Questions or requests concerning cookies and similar technologies may be sent to:

CORE FLIGHT TECHNOLOGIES LLC 8 The Green, Ste 14197 Dover, Delaware 19901 United States Email: info@coreflighttech.com Phone: +1 740-990-2090