COOKIE POLICY
Last updated: 2026-05-21
Cookies are small files stored on your device that help web applications remember session state and security settings. Gather uses essential cookies to keep sign-in, account protection, and core portal workflows working correctly. Under Canadian PIPEDA expectations and GDPR guidance, strictly necessary cookies can be used without opt-in consent. If Gather introduces analytics or marketing cookies, we will request explicit consent before enabling them.
Essential cookies
| Name | Purpose | Duration | Party |
|---|---|---|---|
| gather_session | Keeps signed-in vendors authenticated across page loads. | 6 hours | First-party |
| gather_csrf | Protects state-changing requests from cross-site request forgery attacks. | 6 hours | First-party |
| gather_role | Stores the signed-in role so vendor routes can enforce portal access. | 6 hours | First-party |
| gather_session_issued_at | Stores session issue time for expiry and clock-skew validation. | 6 hours | First-party |
| gather_vendor_msg_pending | Tracks whether vendor messaging onboarding still needs completion. | 6 hours | First-party |
| gather_vendor_sched_pending | Tracks whether vendor scheduling onboarding still needs completion. | 6 hours | First-party |
| gather_vendor_stripe_skipped | Stores whether Stripe onboarding was explicitly skipped for now. | 6 hours | First-party |
| gather_vendor_login_email | Temporarily keeps entered login email between login flow steps. | 15 minutes | First-party |
| gather_vendor_signup_email | Temporarily keeps entered signup email across signup and verification screens. | 15 minutes | First-party |
| gather_vendor_verify_email_pending | Stores pending vendor email address for verify-email and resend actions. | 1 hour | First-party |
| gather_vendor_forgot_password_pending | Stores pending email for forgot-password and reset support flows. | 1 hour | First-party |
| gather_vendor_url_mask_path | Maintains masked vendor route path while hidden query data is preserved server-side. | 30 minutes | First-party |
| gather_vendor_url_mask_real_path | Stores canonical unmasked path paired with vendor URL masking. | 30 minutes | First-party |
| gather_vendor_url_mask_query | Stores hidden query parameters for masked vendor URLs. | 30 minutes | First-party |
| gather_vendor_url_mask_visible_query | Stores visible query parameters while URL masking is active. | 30 minutes | First-party |
| gather_vendor_reset_token | Temporarily stores reset-password token between reset pages. | Transient | First-party |
| gather_vendor_verify_token | Temporarily stores email-verification token before explicit verification submit. | Transient | First-party |
| gather.cookie-consent.v1 | Stores your cookie preferences so we don't re-ask on every visit. | 180 days | First-party |
Analytics cookies
| Name | Purpose | Duration | Party |
|---|---|---|---|
Gather does not currently set analytics cookies. | |||
Marketing cookies
| Name | Purpose | Duration | Party |
|---|---|---|---|
Gather does not currently set marketing cookies. | |||
Contact
If you have questions about this Cookie Policy, contact Gather Events at privacy@gatherevents.ca.