Loading

Legal

Cookie Policy

Effective date: January 1, 2025  ·  Last updated: January 1, 2025

This Cookie Policy explains how RepuFix, Inc. ("RepuFix," "we," "us," or "our") uses cookies and similar tracking technologies when you visit our website or use the RepuFix platform ("Service"). It describes what these technologies are, why we use them, and what choices you have regarding their use.

1. What Are Cookies

Cookies are small text files placed on your device (computer, tablet, or mobile phone) by a website or application when you visit it. Cookies are widely used to make websites function correctly, work more efficiently, and provide information to website operators.

In addition to cookies, we may use similar technologies such as:

  • Local storage and session storage — browser-based storage mechanisms used to retain data between page loads or within a single session
  • Pixel tags and web beacons — small image files embedded in web pages or emails that notify us when content has been viewed
  • Device fingerprinting — technical signals used to identify a device for fraud prevention and security purposes

References to "cookies" in this policy include all of these technologies unless otherwise specified.

2. Categories of Cookies We Use

2.1 Strictly Necessary Cookies

These cookies are required for the Service to function. They cannot be disabled without breaking core functionality. They do not track you for advertising purposes and do not require your consent under applicable law.

Cookie / KeyPurposeDuration
auth-sessionMaintains your authenticated session after loginSession
csrf-tokenPrevents cross-site request forgery attacksSession
ls-account-idIdentifies the active account for API requestsSession
ls-plan-cacheCaches plan entitlements to avoid repeated API calls1 hour

2.2 Functional Cookies

Functional cookies remember your preferences and settings to provide a more personalized experience. Disabling these cookies will not prevent you from using the Service but may reset certain preferences.

Cookie / KeyPurposeDuration
ls-ui-prefsStores UI preferences such as column visibility and sort order30 days
ls-last-listRemembers the last active list view for quick return7 days
ls-themeStores your selected display theme (dark/light if applicable)12 months
ls-onboardingTracks onboarding step completion to avoid repeated prompts90 days

2.3 Analytics Cookies

Analytics cookies help us understand how users interact with the Service — which features are used, how often, and where users encounter friction. This data is used exclusively to improve the Service. We do not sell analytics data to third parties.

ProviderCookie / KeyPurposeDuration
PostHog_ph_*Product analytics — anonymized feature-usage events only. Session recording, session replay, and autocapture are disabled. Loaded only where analytics are enabled for your region.12 months

Analytics cookies are not strictly necessary. Where required by law, we will request your consent before placing analytics cookies. You may opt out of analytics tracking through your cookie preferences or by using browser-level controls.

2.4 Security and Fraud Prevention Cookies

These cookies and signals support fraud detection, abuse prevention, and account security. They are classified as strictly necessary under most applicable frameworks because their purpose is to protect users and the integrity of the Service.

Cookie / KeyPurposeDuration
ls-device-idIdentifies trusted devices for suspicious login detection12 months
ls-rate-sigRate-limiting signal to prevent automated abuseSession

3. Third-Party Cookies

Some cookies used in connection with the Service are set by third-party providers whose services we integrate with. These include:

  • Stripe — payment processing. Stripe may set cookies to facilitate secure transactions and detect fraud. These cookies are governed by Stripe's own privacy and cookie policies.
  • PostHog — product analytics. PostHog may set cookies to track session and event data for usage analysis. Analytics are configured to minimize PII collection.
  • Vercel — hosting and edge infrastructure. Vercel may set minimal cookies related to request routing and performance.

We do not use third-party advertising cookies, retargeting pixels, or cookies that track your activity across unrelated third-party websites for marketing purposes. RepuFix does not participate in behavioral advertising networks.

4. How We Use Cookie Data

Information collected through cookies and similar technologies is used for the following purposes:

  • Authenticating your identity and maintaining your logged-in session across page loads
  • Remembering your preferences and settings to avoid requiring re-configuration on each visit
  • Detecting and preventing fraudulent activity, unauthorized access, and abuse of the credit system
  • Measuring aggregate usage patterns, feature adoption, and performance metrics to guide product development
  • Diagnosing errors, performance bottlenecks, and service reliability issues
  • Supporting rate limiting and fair-use enforcement to maintain service quality for all users

We do not use cookie data to build advertising profiles, track users across unaffiliated websites, infer sensitive personal characteristics, or sell data to third parties.

5. Your Cookie Choices

5.1 Analytics and Consent

Non-essential analytics (PostHog) are off by default and start only after you accept them. On your first visit we present a consent banner with equal “Accept analytics” and “Reject analytics” options and no preselected choice; nothing is treated as consent until you choose. If you reject, no analytics cookies are placed and no analytics events are sent. You can change your decision at any time — including withdrawing a previous acceptance, which stops further collection and clears PostHog’s client-side storage. Essential authentication, billing, and product features work regardless of your choice.

5.2 Browser Controls

Most browsers allow you to control cookies through browser settings. Common options include:

  • Blocking all cookies — note that blocking strictly necessary cookies will prevent you from logging in or using the Service
  • Deleting cookies already stored on your device
  • Configuring your browser to notify you when cookies are being set
  • Enabling private/incognito browsing mode, which prevents persistent cookies from being stored after the session ends

Browser cookie settings vary by browser version. Refer to your browser's help documentation for instructions.

5.3 Opting Out of Analytics

Non-essential analytics are off until you accept. You may decline or later withdraw consent via the consent banner and the “Manage analytics preferences” control in 5.1; you may also block or delete analytics cookies using the browser controls in 5.2. PostHog is configured with session recording, session replay, heatmaps, surveys, and autocapture disabled, and is never used to identify you personally. Error and security monitoring (Sentry) is separate from analytics, subject to the personal-data scrubbing described in our Privacy Policy, and is not used for product analytics.

Note that opting out of analytics does not affect your ability to use the Service and does not prevent the placement of strictly necessary cookies.

6. Cookie Retention

Cookies fall into two duration categories:

  • Session cookies — exist only for the duration of your browser session and are deleted when you close your browser
  • Persistent cookies — remain on your device for a set period (as described in the tables in Section 2) or until you delete them manually

Persistent cookies are retained only as long as necessary for their stated purpose. We regularly review cookie retention periods to ensure they are proportionate and aligned with data minimization principles.

7. Updates to This Policy

We may update this Cookie Policy from time to time to reflect changes in the cookies we use, changes to applicable law, or changes to our service infrastructure. When we make material updates, we will revise the "Last updated" date at the top of this page and, where appropriate, notify you via email or in-app notice. We encourage you to review this policy periodically. Continued use of the Service after an update constitutes acceptance of the revised policy.

Questions About Cookies

If you have questions about our use of cookies or wish to exercise your rights, contact us at privacy@repufix.io.
RepuFix, Inc. · Privacy Team · Delaware, United States