Idaho Pro Gear

Cookies and browser storage

litecheckout hosts checkout and customer-account pages for Idaho Pro Gear on a *.litecheckout.io subdomain. This technical notice describes the cookies and browser storage used by litecheckout and Stripe on those pages.

Current inventory

Name and locationPurpose and audienceWhen it appearsLifetime
__stripe_midStripe machine identifier; first-party on this origin, not iframe-confinedHelps Stripe prevent fraud on payment-bearing checkout surfaces.May be set for a visitor when a surface loads Stripe.js, before the visitor interacts with payment fields.1 year, according to Stripe on 24 Aug 2026.
__stripe_sidStripe session identifier; first-party on this origin, not iframe-confinedHelps Stripe prevent fraud on payment-bearing checkout surfaces.May be set for a visitor when a surface loads Stripe.js, before the visitor interacts with payment fields.30 minutes, according to Stripe on 24 Aug 2026.
__Host-lc_customer_sessionHttpOnly litecheckout cookieAuthenticates a signed-in customer account. It is not set for a guest shopper.After the customer completes email-link or emailed-code sign-in.Stored for up to 24 hours by default, or up to 365 days only when persistent sign-in is affirmatively requested. The session can become unusable earlier after 6 hours of inactivity by default, after 30 days of inactivity for persistent sign-in, or after server-side revocation. Logout clears the cookie.
__Host-lc_booking_group_resume_<publicRef>HttpOnly litecheckout cookieLets a guest or signed-in shopper resume the booking group represented by the public reference.After a valid booking-group recovery action is used.Up to 24 hours, or until logout.
__Host-lc_subscription_recovery_<handle>HttpOnly litecheckout cookieLets a guest or signed-in customer continue a specific subscription-payment recovery.After a valid subscription recovery action is used.Up to 1 hour, or until logout.
litecheckout:fields:<opaqueCheckoutToken>Browser sessionStorageRestores a checkout draft containing entered name, email, phone, company, delivery address, country, and marketing choice after a refresh. It never contains card details.Written in the shopper's current tab while checkout fields are edited.Cleared after a completed order when possible; otherwise it ends with that tab's browser session.
litecommerce.checkout-account-selection.v1: <opaqueCheckoutToken>Browser sessionStorageRemembers the account email the shopper explicitly selected while checkout was open, so the same tab can present the permitted pending-payment account recovery after a refresh.Written when the shopper explicitly continues with the signed-in account during checkout.Cleared after a completed switch to another account when possible; otherwise it ends with that tab's browser session.
litecommerce.checkout-account-switch.v1: <opaqueCheckoutToken>Browser sessionStorageHolds the random retry identifier and opaque switch-epoch recovery state for one pending-payment account change. It contains the selected and branch email, but no payment or sign-in credential.Created before the current tab asks litecommerce to pause the prepared payment, then updated as the recovery branch is admitted and identified.Cleared after the switched checkout is rebound and its new payment is prepared when possible; otherwise it ends with that tab's browser session.
lc:booking-group:<publicRef>:initial-checkoutBrowser sessionStorageHolds a random retry key so an uncertain booking checkout response can be retried without creating another attempt or charge.Created in the current tab when booking-group payment is prepared, then sent to litecommerce with that request.Reused after an uncertain response and retained until that tab's browser session ends.
localStorageNo litecheckout application entrylitecheckout application code does not write localStorage, IndexedDB, or Cache Storage. If you completed a checkout here while this merchant had Google Analytics configured, your browser may still hold Google's _ga cookies and a litecheckout lc:ga4:purchase:<orderNumber> marker from that time until they expire or you clear site data; nothing reads or renews them now. Storage used inside Stripe's cross-origin payment iframe is outside this application inventory.

In production, the three __Host-lc_* cookies above are Secure, HttpOnly, SameSite=Lax, and restricted to the host-wide / path. Local development uses equivalent cookie names without the __Host- prefix so HTTP localhost works.

What the inventory means

  • Keeping the checkout field draft in sessionStorage does not itself upload the draft. litecommerce receives the current delivery address while loading or updating shipping options, which can happen before the shopper continues or submits. When checkout is bound, litecommerce also receives the entered contact values and, when enabled, the marketing choice.
  • Card details are entered in Stripe-hosted fields and sent directly to Stripe. litecommerce does not receive or store card details.
  • Closing the tab ends the sessionStorage entries above, not the cookies. In particular, __stripe_mid can persist for up to 1 year.
  • This notice does not ask for or record cookie consent. litecheckout currently has no cookie-consent banner or preference control.
  • A tenant-enabled marketing checkbox is unchecked by default and starts a newsletter double opt-in. It is not cookie consent.

Storage inside Stripe's cross-origin payment iframe cannot be read or enumerated by litecheckout and is not included here. Stripe controls that technology and may change it. See Stripe's Privacy Center for how Stripe.js works and Stripe's Cookie Settings for its current cookie list.

How this inventory was checked

A guest-browser inspection on 19 Aug 2026 recorded names and presence only; no cookie or storage values were captured. On 24 Aug 2026, the litecheckout source was checked for application-set cookies, storage keys, purposes, audiences, and upper lifetimes, and the Stripe lifetimes above were checked against Stripe's published Cookie Settings.

Those dates identify observations, current application behavior, and current provider documentation. They are not promises that retention or provider behavior will never change.