Last updated: August 13, 2026
The short version. We use a small number of cookies, and nearly all of them exist to keep you signed in and your account secure. We do not use advertising cookies, and we do not load third-party analytics or tracking pixels on this website.
A cookie is a small text file that a website stores on your device. It lets the site recognise your browser across requests — which is how you stay signed in as you move between pages. Cookies set by the site you are visiting are called first-party cookies; cookies set by another domain are third-party cookies.
Related technologies do the same job in different ways. Local storage keeps small amounts of data in your browser until it is explicitly cleared, and is never sent to a server automatically. This policy covers both.
This policy supplements our Privacy Policy, which explains how we handle personal information more generally.
| Cookie | Category | Purpose | Duration |
|---|---|---|---|
affid |
Functional | Records the affiliate or partner referral that brought you to our site, so the referral can be credited if you later subscribe. Set only when you arrive via a referral link, and never overwritten once present. | Persistent |
kc_cookie_consent |
Strictly necessary | Remembers that you have seen and responded to our cookie notice, so we don't show it again on every page. | 12 months |
__cf_bm and related Cloudflare cookies |
Strictly necessary | Set by Cloudflare Turnstile, which we use to tell humans from bots on our contact and sign-up forms. Helps prevent spam and automated abuse. | Up to 30 minutes |
These are set at portal.kickcatch.com when you sign in to your account. All of them are first-party.
| Cookie | Category | Purpose | Duration |
|---|---|---|---|
.AspNetCore.Cookies |
Strictly necessary | Your authenticated session. Identifies you to the portal after you sign in so you don't have to re-enter credentials on every page. | Session, or persistent if you select "remember me" |
.AspNetCore.Antiforgery.* |
Strictly necessary | Protects forms against cross-site request forgery by verifying that a submission came from a page we served. | Session |
mfa_pending |
Strictly necessary | Carries an in-progress multi-factor authentication challenge between the sign-in page and the code entry page. Deleted as soon as the challenge completes. | Minutes — expires with the challenge |
mfa_trusted_device |
Functional | Set only if you choose to trust the device you are using, so you are not asked for a verification code on every sign-in from it. | Until the trust period expires or you sign out of trusted devices |
affid |
Functional | As described above, where you reached the portal through a referral link. | Persistent |
The portal keeps a small amount of interface state in your browser's local storage rather than in a cookie. It stays on your device and is not transmitted to us automatically.
Clearing your browser's site data removes these entries. Doing so is harmless — the portal simply falls back to its defaults.
To be explicit about what is not here:
The only third-party domain that sets a cookie through our website is Cloudflare, for the bot-detection challenge described above.
The first time you visit our website we show a short notice explaining that we use
cookies and linking to this page. Acknowledging it records your choice in the
kc_cookie_consent cookie so the notice does not reappear on every page.
Because every cookie we currently set is either strictly necessary or functional, there is nothing to opt out of that would not also break sign-in or referral attribution. Should we ever introduce analytics or advertising cookies, we will ask for your consent first and provide granular controls here.
To clear a choice you have already made, delete the kc_cookie_consent
cookie for kickcatch.com in your browser and reload the page — the notice will appear
again.
Every major browser lets you view, delete, and block cookies. The relevant settings are usually under Privacy or Security:
Blocking all cookies will prevent you from signing in to the portal, because the session and anti-forgery cookies are required for authentication to work.
We will update this page when the cookies we use change, and will revise the "Last updated" date at the top. If we introduce a category that requires consent, we will ask you for it before setting those cookies.
Questions about our use of cookies can be sent to [email protected] or submitted through the contact form on our website.
KickCatch, LLC
[email protected]