Scope
This Cookie Policy explains how Lansum International Corp. uses cookies and similar technologies in iMaster. It should be read with the Privacy Policy.
A cookie is a small text value stored by a browser. Similar technologies include local browser storage, OAuth state, service-worker caches, and push-subscription records. Some of these technologies do not use a traditional cookie but serve related security or functionality purposes.
Current use: necessary technologies only
iMaster currently uses cookies and similar technologies needed for authentication, security, account connection flows, PWA operation, offline support, push notifications, and essential preferences. We do not currently use advertising cookies, cross-context behavioral advertising pixels, or third-party advertising profiles.
Because these technologies are necessary to provide a feature you request or protect the Service, disabling them can prevent login, brokerage authorization, session continuity, offline behavior, or notifications from working.
Technologies we use
Authentication and session cookies
NextAuth/Auth.js session cookies maintain a signed-in iMaster session. Depending on HTTPS configuration, names may include next-auth.session-token, __Secure-next-auth.session-token, authjs.session-token, or an equivalent secure name. The configured maximum session period is approximately 30 days, but a cookie may end earlier when you sign out, reset local state, clear browser data, or when security controls invalidate it.
Security and OAuth cookies
Short-lived CSRF, state, nonce, PKCE, callback, and authorization-attempt values help prevent request forgery, replay, account confusion, and redirect attacks during login or connection flows. These usually expire after the flow or within a short security window.
Essential preferences and browser state
The browser may retain language, installation, update, interface, or necessary feature state. The exact duration depends on the feature and browser settings and lasts no longer than reasonably necessary for the feature.
Service worker and cache storage
The iMaster PWA service worker caches the offline shell and public or versioned static assets, such as icons and application code. Authentication responses, APIs, navigations containing account data, portfolio information, holdings, transactions, and OAuth callbacks are not intentionally cached for offline use.
Push subscriptions
If you affirmatively enable push notifications, your browser creates a push endpoint and cryptographic delivery keys. These are transmitted to the notification service so requested notifications can be delivered. You can revoke permission through iMaster settings or browser/device controls.
Operational events and logs
When signed in, the Service may record limited PWA events—such as installation availability, installation, standalone launch, offline state, or an available update—together with a platform label and account identifier. These events are used for service operation and reliability, not advertising.
Third-party domains
When you choose to sign in, connect a brokerage, or follow an external link, you may be redirected to a domain operated by Lansum Auth, SnapTrade, Plaid, Webull, a brokerage, or another provider. That provider may set cookies under its own domain and privacy policy. iMaster does not control cookies set entirely on a third-party domain.
We do not currently embed third-party advertising networks in iMaster pages. Cloud hosting and security providers may process ordinary request information needed to deliver and protect the Service.
Your choices
- Browser controls: most browsers allow you to view, delete, or block cookies and site data. Blocking necessary cookies may prevent login and secure connection flows.
- Sign out or reset: signing out clears or invalidates the active iMaster session. Browser site-data controls can remove remaining local storage and caches.
- Push controls: disable push through iMaster notification settings or your browser/device notification permissions. Removing a subscription stops future browser push delivery after the revocation is processed.
- PWA removal: uninstalling the PWA removes the installed app entry; depending on the browser, you may separately need to clear site data or notification permissions.
- Brokerage providers: provider or institution cookies are managed through that provider’s site or browser controls.
Do Not Track and Global Privacy Control
“Do Not Track” is not a uniform technical or legal standard, so iMaster does not respond to ordinary DNT signals. We recognize legally applicable opt-out preference signals such as Global Privacy Control for sale or sharing of personal information. Because iMaster does not currently sell personal information or share it for cross-context behavioral advertising, receiving such a signal does not change our current cookie behavior.
Retention
Session and security technologies persist only for their configured security or functionality period. Cached public assets remain until updated, expired, evicted by the browser, or cleared by you. Push subscriptions remain until revoked, expired, replaced, or removed. Operational logs are retained only as long as reasonably needed for security, reliability, audit, and legal purposes, as described in the Privacy Policy.
Changes and contact
If we introduce optional analytics, advertising, or other nonessential technologies, we will update this Policy and provide consent or opt-out controls where required before using them.
Questions may be submitted through the Contact page or by email to security@lansum.com.


