Effective September 11, 2026. This notice covers cookies and similar storage used by Turnstile and enabled services.
What browser storage does
Cookies are small values your browser stores and sends with relevant requests. Similar technologies include session storage, which keeps information for a browser tab, and caches that help load files such as fonts, images, and styles. This notice covers Turnstile’s uses and distinguishes them from providers involved in a feature you choose.
Turnstile’s marketing site currently has no advertising-pixel or third-party audience-analytics integration. Loading the website still involves requests to its hosting and delivery systems. Technical delivery and security information is described in the Privacy Notice.
Account and security cookies
Customer account cookies use the turnstile name prefix, with secure naming on HTTPS deployments. They support sign-in and security steps such as MFA and passkey verification. Access still depends on the current account, session, and permissions; a stored cookie does not override an account lock or session revocation.
The configured customer session lasts up to 24 hours and may be renewed or ended earlier by expiry, sign-out, or revocation. MFA continuation normally lasts up to ten minutes. Passkey challenges are temporary. These are feature durations, not promises that a browser will preserve a session until a particular time.
Internal Turnstile Control sign-in uses a separate __Host-turnstile-control cookie family for operator sessions, request protection, and sign-in continuity. Its configured session and sign-in state windows are 15 minutes. These operator cookies are separate from ordinary customer sign-in.
Keeping an invitation through sign-in
When you open an organization invitation, Turnstile removes the invitation secret from the visible URL and keeps the proof in tab-scoped session storage while you sign in. Entries use the turnstile:invitation prefix. This supports the invitation you opened; it is not advertising storage.
The supported flow clears its stored proof when acceptance completes or the proof is rejected. Your browser controls tab-storage restoration and clearing, and closing a tab may affect whether you can continue. If the proof is unavailable, the invitation experience may offer a fresh email link.
Storage used by other providers
An enabled Stripe checkout, embedded DocuSeal signing experience, or wallet provider may use its own cookies or storage when you use that feature. Their purposes, duration, and controls depend on the provider and the actual feature. Review the provider’s notice and any choices shown in that experience.
Choosing Gravatar import or an event-address check involves a provider request described in the Privacy Notice. Those server-side requests do not, by themselves, mean Turnstile loads a Gravatar or Mapbox tracking script into every visitor’s browser.
Your browser controls
Your browser settings let you inspect, block, or remove cookies and site storage. You can also use a private browsing session. Clearing or blocking sign-in and invitation storage may sign you out or prevent the requested flow from completing. Clearing storage does not delete the corresponding account or transaction records held by Turnstile or an organizer.
No marketing advertising or audience-analytics settings are currently offered because those integrations are not configured. If we introduce optional tracking that requires a choice, we will explain the purpose and provide that choice before using it as required by applicable law. The fact that a technology is useful does not make every use essential.
Updates and questions
We will identify the version and effective date when this notice changes and provide additional notice or choices where required. For a question about Turnstile storage or a privacy request, email legal@turnstileos.com or write to Doorstop, Inc., 1111b South Governors Ave, Ste 96313, Dover, DE 19904.