Cookie Policy
Controller: CORE FLIGHT TECHNOLOGIES LLC Last updated: September 30, 2026
This Cookie Policy explains how CORE FLIGHT TECHNOLOGIES LLC (“Core Flight Technologies,” “we,” “us,” or “our”) uses cookies, pixels, local storage, software development kits, server-side event technologies, and similar technologies on coreflighttech.com (the “Website”). It should be read together with our Privacy Policy.
1. What These Technologies Are
A cookie is a small text file stored on a browser or device. Similar technologies include pixels, tags, scripts, local or session storage, device identifiers, and server-side event connections. They may remember a cart or preference, keep an account secure, measure Website activity, support chat and forms, attribute a referral, or measure advertising results.
Some technologies are set directly by the Website (“first-party”), while others are provided by third parties whose services appear on or connect to the Website (“third-party”). Some are deleted when the browser session ends, while others remain for a defined period or until deleted.
2. How We Classify Technologies
Strictly Necessary
These technologies are required to provide a service requested by the user or to operate essential functions such as cart and checkout, account login, security, fraud prevention, load balancing, network transmission, and recording privacy choices. Where the law permits, they operate without optional consent. Blocking them may prevent the Website, account, cart, checkout, payment, or security functions from working correctly.
Preferences and Functionality
These technologies remember optional choices or enable features such as recently viewed products, chat, embedded forms, or display preferences. They are not always essential to purchase a product. Where required by law, they operate only after consent.
Analytics and Performance
These technologies help us understand visits, navigation, product views, searches, cart and checkout activity, campaign attribution, errors, and Website performance. Where required by law, they operate only after consent.
Advertising and Measurement
These technologies measure advertising activity, attribute conversions, limit or personalise advertising, or create advertising audiences. They may connect activity across websites or services. Where required by law, they operate only after consent and are also subject to applicable sale, sharing, or targeted-advertising opt-out rights.
3. Technologies Used on the Website
The inventory below reflects technologies observed or embedded during the latest Website audit. Exact names, durations, and provider behaviour can change when providers, plugins, or configurations are updated. The live consent-management panel should show the current service-level inventory.
A. Essential Commerce, Account, Security, and Payment
| Provider or service | Examples observed or expected | Purpose | Typical category |
|---|---|---|---|
| WordPress / WooCommerce | WooCommerce cart, session, account, checkout, and fragment storage; WordPress login or settings cookies where applicable | Maintain cart contents, customer session, checkout, account access, and core Website functions | Strictly necessary; settings features may be functional |
| Stripe | __stripe_mid and other Stripe payment, authentication, or fraud-prevention technologies |
Process and secure payment attempts, detect fraud, and support payment authentication | Strictly necessary when used for payment/security |
| Google reCAPTCHA | reCAPTCHA scripts, device or browser storage, and related security signals | Protect forms and the Website against spam, bots, and abuse | Strictly necessary only on protected forms where proportionate |
| Consent-management technology | Consent record and preference storage | Remember whether optional categories were accepted or rejected | Strictly necessary for privacy-choice management |
B. Preferences, Forms, Chat, and Customer Features
| Provider or service | Examples observed or expected | Purpose | Typical category |
|---|---|---|---|
| Woodmart / WooCommerce | Recently viewed products and interface or cart-related browser storage | Remember product or interface activity requested by the user | Preferences/functionality; essential where directly required for cart operation |
| HubSpot | messagesUtk and related chat, form, or browser storage |
Provide chat, remember chat sessions, and support form or customer-service interactions | Preferences/functionality; may also involve analytics |
| Sender | Newsletter form and popup preference storage | Display subscription forms, remember popup interaction, and process an optional subscription | Preferences/functionality and marketing |
| Review or feedback features | Review session or submission technologies where enabled | Submit, display, or verify product feedback | Preferences/functionality |
C. Analytics, Attribution, and Performance
| Provider or service | Examples observed or expected | Purpose | Typical category |
|---|---|---|---|
| Automattic / Jetpack / WooCommerce Analytics | tk_ai, tk_lr, tk_or, tk_r3d and related analytics storage |
Measure visits, referrers, commerce interactions, and Website performance | Analytics/performance |
| Burst Statistics | burst_uid and related first-party analytics storage |
Measure visits and Website usage | Analytics/performance |
| HubSpot analytics | hubspotutk, __hstc, __hssc, __hssrc and related storage |
Measure sessions, page activity, form interactions, and customer journeys | Analytics/performance |
| WooCommerce Sourcebuster / attribution | sbjs_* values and related browser storage |
Record referral source, campaign, and first or current visit attribution | Analytics/attribution |
| GoAffPro | Affiliate or referral identifiers and related storage | Attribute visits, leads, or orders to an affiliate | Analytics/attribution; may also be advertising depending on configuration |
D. Advertising and Conversion Measurement
| Provider or service | Examples observed or expected | Purpose | Typical category |
|---|---|---|---|
| Meta Pixel | _fbp, browser event identifiers, pixels, and related storage |
Measure page, product, cart, checkout, lead, and purchase-related events; attribute advertising; support audiences where enabled | Advertising and measurement |
| Meta Conversions API | Server-side event data, event identifiers, and matching information | Measure and attribute conversions, improve event reliability, and deduplicate browser/server events | Advertising and measurement; server-side processing may continue to require privacy controls even when no browser cookie is set |
4. Duration
Session technologies expire when the browser session ends. Persistent technologies remain for a defined period or until deleted. Duration is determined by the purpose, our configuration, and the provider’s settings.
The live consent-management panel states the current duration for each individual cookie or storage item. We will review durations periodically and use a shorter period where reasonably sufficient for the stated purpose.
5. Consent and Your Choices
Where consent is required, non-essential preferences, analytics, advertising, and measurement technologies must remain disabled until the user makes an informed, affirmative choice.
The Website’s consent mechanism provides:
- Accept all and Reject non-essential choices with comparable prominence and ease;
- category-level controls for optional technologies;
- no preselected optional categories;
- access to the Website even when optional technologies are refused, except where an optional feature itself cannot operate without its associated technology;
- a persistent link or control allowing preferences to be changed or consent to be withdrawn; and
- a record of the choice, version, categories, date/time, and relevant consent configuration.
Withdrawing consent does not make earlier processing unlawful, but it should stop future optional storage or access covered by that consent. Previously stored technologies may remain until they expire or are deleted, unless the consent tool removes them.
Browser settings can also block or delete cookies. Doing so may affect account, cart, checkout, payment, form, chat, or preference functions. Browser “Do Not Track” signals are not interpreted uniformly. We will process legally recognised opt-out preference signals where required and supported by the final privacy configuration.
6. U.S. Sale, Sharing, and Targeted-Advertising Choices
We do not sell personal data for money. However, advertising identifiers, browsing activity, and conversion events disclosed to advertising or measurement providers may be treated as a “sale,” “sharing,” or targeted-advertising processing under some U.S. state privacy laws.
Where applicable, users may opt out through the Website’s privacy or cookie controls or by emailing info@coreflighttech.com with the subject “Privacy Request.” We will honour recognised browser-based opt-out preference signals where legally required and technically supported.
7. Third-Party Services
Third-party providers may receive device, browser, network, event, account, form, payment, or interaction information according to the service used. Depending on the service and law, a provider may act as our processor, an independent controller, or another participant in processing. Its own privacy and cookie documentation may also apply.
The presence of a provider in this Policy does not mean every service operates on every page or for every user. Availability may depend on page, country, consent choice, login status, cart or checkout activity, and provider configuration.
8. Server-Side Events
Some measurement or security activity can occur through server-to-server connections rather than a browser cookie. This includes Meta Conversions API event processing and may include payment, fraud, commerce, or security events. Server-side processing is described in the Privacy Policy and must follow applicable consent, opt-out, data-minimisation, and legal-basis requirements even when it does not store information directly on the user’s device.
9. Updates to This Policy
We may update this Policy when technologies, providers, laws, or business practices change. The “Last updated” date identifies the current version. Material changes will be communicated or renewed consent will be requested where required.
10. Contact
Questions or requests concerning cookies and similar technologies may be sent to:
CORE FLIGHT TECHNOLOGIES LLC 8 The Green, Ste 14197 Dover, Delaware 19901 United States Email: info@coreflighttech.com Phone: +1 740-990-2090