1. What are cookies
Cookies are small text files stored on your device when you visit a website. They allow the site to recognize your device, remember preferences, and provide functionality.
We also use similar technologies such as local storage, session storage, web beacons (pixels), and SDKs in mobile apps. For simplicity, this policy uses “cookies” to refer to all of them.
2. Categories we use
Strictly necessary
Required for core functionality (authentication, session management, security, load balancing, fraud prevention). These cannot be disabled.
- Session cookies (login state)
- CSRF tokens
- Consent preference (records your choices below)
Functional
Remember your preferences and enhance your experience (language, theme, region).
Analytics
Help us understand how users interact with the Service to improve it. We use aggregated, de-identified analytics where possible.
- PostHog (product analytics)
- Vercel Analytics (web vitals)
Marketing
Measure ad campaigns and personalize content. Active only with your consent.
- Meta Pixel (when running paid ads)
- Google Ads conversion tracking (when running paid ads)
- LinkedIn Insight Tag (when running paid ads)
3. Your choices
You can:
- Use our cookie consent banner (appears on first visit and may be re-opened from any page).
- Manage browser cookie settings (most browsers let you block or delete cookies).
- Opt out of marketing cookies via industry tools (e.g., youradchoices.com, youronlinechoices.com).
- Send a Global Privacy Control signal (we honor it).
Blocking strictly necessary cookies will prevent the Service from working.
4. Region-specific defaults
- European Economic Area / United Kingdom: non-essential cookies require explicit opt-in.
- Brazil: similar to EU; explicit opt-in for non-essential cookies.
- California: opt-out applies; we honor the “Do Not Sell or Share My Personal Information” choice (see /do-not-sell).
- Other regions: consent banner appears with manageable categories.
5. Third parties
Some cookies are set by third parties when they provide services on our behalf. See our Sub-processors list for details.
6. Retention
- Session cookies: deleted when you close your browser.
- Persistent cookies: typical retention 30 days to 13 months depending on purpose.
- Consent record: 13 months (then we re-ask).
7. Updates
We may update this policy. Material changes will be communicated via in-app banner or email.
8. Contact
Questions: privacy@shaartusa.com.