Privacy & Cookie Notes
Technical notes for privacy and cookie policy updates.
If you use Custom Auth Suite™, we recommend reviewing and updating your Privacy Policy and Cookie information so they accurately reflect the features active on your website.
Custom Auth Suite™ can affect authentication flows, verification emails, anti-bot checks, passkeys, account sessions and security-related access data. This page gives site owners a clear starting point for adapting their privacy and cookie documentation for their own website users.
Important boundary
These are technical notes, not legal advice.
The final privacy policy, cookie policy, consent model and legal basis for processing remain the responsibility of the website owner. Custom Auth Suite™ provides implementation notes and copy-ready technical descriptions that must be reviewed and adapted to the specific website, jurisdiction and data-processing setup.
Use this as a structured starting point. The downloadable files that will be made available here are intended to help explain what CAS does technically, which third-party services may be involved and which parts must be checked by the site owner or privacy professional.
Simple. Necessary. Like water.
What may need to be disclosed
CAS-related areas to review
The exact wording depends on the active edition, enabled features and site configuration. The following areas focus on what may affect the users of the website where Custom Auth Suite™ is installed.
Authentication flows
Login, registration, lost password recovery, protected redirects and account-related interactions may involve user identifiers such as email address, username, account state, timestamps and security-related metadata.
Email verification
When enabled, email verification may generate verification tokens, timestamps and delivery events. Transactional email delivery depends on the website’s configured email provider or SMTP service.
Anti-bot checks
If Google reCAPTCHA Enterprise is enabled, the site owner must configure the Google service, provide required notices and describe the relevant data handling in their privacy documentation. If a local Math Check or honeypot is used, the site owner should also describe the security purpose of those checks where appropriate.
WebAuthn authentication, passkeys and cookies
WebAuthn (Web Authentication API) is a W3C and FIDO2 standard that
enables secure passwordless authentication using public-key
cryptography. It can use hardware keys or built-in device authentication
such as Face ID, Touch ID or PINs, helping protect users against
phishing and password theft.
If passkeys are enabled, site owners
should explain what account, device and security data may be processed
while users access the website. Biometric data remains on the user’s
device and is not transmitted to the website.
Cookies, sessions and local storage
Authentication and account features may rely on WordPress session cookies, login cookies, security cookies, language preferences, WooCommerce account/session cookies where applicable, and local browser storage used for security or interface behavior.
Protected areas and redirects
If the website uses protected areas, custom login pages or post-login redirects, the site owner should explain that access to selected pages may depend on account status, authentication state, email verification or other security checks configured on the website.
Edition-aware files
The right text depends on the active package.
Free, Advanced and Premium may expose different user-facing capabilities. The request tool will help site owners identify the most appropriate technical Privacy & Cookie notes for the features active on their website.
Free
Basic branded authentication flows and initial setup notes. Useful for sites starting with the free package.
Advanced
Professional access-layer notes for sites using additional authentication, protection or verification features.
Premium
Full access-layer notes for sites using advanced authentication features, passkeys or additional user-facing protection flows where enabled.
Google reCAPTCHA Enterprise
A third-party service configured by the site owner.
Custom Auth Suite™ supports Google reCAPTCHA Enterprise integration only. CAS does not create the Google Cloud project, does not activate billing and does not issue reCAPTCHA Enterprise keys. The website owner must configure the Google service, obtain the required keys and comply with applicable Google terms, notices, privacy requirements and consent obligations.
CAS integration
CAS can use the keys/settings entered by the administrator to protect selected authentication or form flows.
Google service
The reCAPTCHA Enterprise service is provided by Google. The site owner is responsible for the Google Cloud/reCAPTCHA Enterprise configuration.
Website notice
The site owner must ensure that users receive appropriate information about the use of reCAPTCHA Enterprise and any related data handling.
Request file
Request the Privacy & Cookie file for your CAS installation.
Use the request flow to enter the domain where CAS is active, check the active license/edition and download the most appropriate Privacy & Cookie technical file for Free, Advanced or Premium. The file is intended as a technical starting point and should be reviewed before publication on your website.
Request the Privacy & Cookie file Back to product specifications