Cookie policy
Lot Radar keeps cookies deliberately boring: account access, security, preferences, and optional product analytics. Your subscription tier changes the App features you can use, not your cookie choices.
Last updated: May 7, 2026
Login, CSRF protection, locale, theme, and consent state work without analytics consent.
GA4, Vercel Analytics, and Speed Insights load only after you allow analytics.
We do not use retargeting pixels, behavioral advertising cookies, or sell cookie-derived data.
Where this applies
The same consent choice follows the public site, auth pages, and signed-in App. Session cookies are separate from analytics and are needed for account access.
Before sign-in
You can browse public lot, VIN, pricing, help, and legal pages with analytics off.
Signed-in workspace
Free, Pro, Max, and bundle users keep the same cookie controls. App features stay governed by account entitlements.
API customers
API keys and server-side API usage do not depend on browser analytics cookies. Account pages still use session and CSRF cookies.
Plan level does not change consent
Reading as a visitor
These pages cover the public site, account creation, share links, and the parts of Lot Radar you can inspect before signing in.
Public pages
Only necessary and preference cookies are required; analytics waits for consent.
Authenticated App
Session and CSRF cookies keep account and billing actions tied to the first-party Lot Radar domain.
Necessary and preference cookies
| Name | Type | Purpose | Duration |
|---|---|---|---|
| lr_session | First-party authentication | Keeps you signed in to the App. The value is HttpOnly and is not readable by browser JavaScript. | Up to 30 days, refreshed by the server while the session is active. |
| lr_csrf | First-party security | Pairs with the session cookie to protect account actions, forms, and realtime handshakes. | Matches the active session. |
| lr_oauth_state, lr_oauth_nonce, lr_oauth_pkce | First-party OAuth security | Protects the Google sign-in redirect while the OAuth flow is in progress. | Up to 10 minutes. |
| lr_theme | First-party preference | Stores light, dark, or system theme preference to avoid visual flicker. | Up to 1 year. |
| NEXT_LOCALE | First-party preference | Stores the selected interface language when the locale switcher is used. | Controlled by next-intl, typically up to 1 year. |
| lr_consent | First-party consent preference | Stores a versioned analytics choice with marketing fixed off. | Up to 1 year. |
Optional analytics storage
| Name | Type | Purpose | Duration |
|---|---|---|---|
| _ga, _ga_* | Google Analytics 4 | Measures aggregate page and product usage after consent so we can improve the site and App. | Set by Google Analytics, commonly up to 2 years. |
| Vercel Analytics / Speed Insights | Performance and usage measurement | Measures page performance and aggregate usage after consent. We do not use this for advertising. | Controlled by Vercel's analytics implementation. |
Managing cookies
Open cookie settings to change analytics at any time. You can also clear Lot Radar cookies in your browser; required cookies will be recreated only when needed for sign-in, security, language, theme, or consent state.