Legal

Cookie Policy

What we set, why, and your choices.

Updated 2026-09-17

1. Your choices

On your first visit we show a consent banner with three categories. You can accept all, reject all (which keeps only Essential cookies running), or customize per category. You can change your decision anytime via the Manage cookies link in the site footer. Each decision is recorded server-side in our append-only consent log so we can demonstrate compliance and respond to data-subject requests.

This policy covers rekomi.com, app.rekomi.com, andapi.rekomi.com. Section 4 covers the cookies our tracking script sets on customer sites, on our neutral rekomi.link redirect domain, and on brand campaign signup pages (branded subdomains and brand custom domains). Where we say “localStorage” or “sessionStorage” we mean browser storage that behaves like a cookie: localStorage stays until you clear your browser data, sessionStorage is discarded when the tab closes.

2. Cookie categories

Essential (always on)

Required for the site to function. These cannot be rejected because the product does not work without them. All of them are first-party.

  • Clerk session cookies (__session, __client_uat, __client, and the short-lived sign-in handshake cookies __clerk_handshake, __clerk_handshake_nonce, __clerk_redirect_count). Your authenticated session. __session is set on the host you signed in on, __client_uat on rekomi.com and its subdomains, and __client by our sign-in service at clerk.rekomi.com. Lifetimes are set by Clerk; see Clerk's cookie documentation.
  • Sign-in and connection flow cookies. rekomi_connect_resume (1 hour, app.rekomi.com) remembers where to send you back after signing in from a WordPress connect link. __rekomi_oauth_bridge (2 minutes, rekomi.com and subdomains, not readable by scripts) carries your session to api.rekomi.com while you authorize a third-party app such as Zapier. rekomi_admin_recent_imp_limit (1 year) is a display preference on the staff admin console only.
  • Theme preference (localStorage rekomi-theme). Remembers your light/dark choice.
  • Consent record (localStorage rekomi-cookie-consent-v2 plus an anonymous session id rekomi-anon-session, a random UUID). Stores your choice so we do not re-prompt, and lets us find your decision in the consent log. Both stay until you clear browser data; the consent record is discarded automatically when this policy's version changes.
  • Interface preferences (localStorage and sessionStorage keys starting with rekomi-, rekomi:, rkmi:, or rkm_). Remembered tabs, collapsed panels, snoozed banners, and setup-guide progress inside the dashboard, for example rekomi-campaigns-view, rekomi-tips-collapsed-v1, rekomi-tracking-banner-snoozed-at-v2, rekomi-recipe-progress:*, and rekomi-trial-banner-dismissed-v2. They hold only on/off flags, dates, and view names, never personal data.
  • Stripe Checkout cookies (set on stripe.com during a checkout session). Required for billing flows; only set when you initiate a checkout. We do not load Stripe scripts on our own pages.
  • Affiliate attribution (_rkmi, legacy _rekomi_aff). Records which affiliate referred a visit so a resulting sale, lead, or click is credited. Set by api.rekomi.com (or a brand's own tracking domain) when our tracking script reports a referred visit, including from our own marketing site where we run the same script on our own affiliate program. The value is only the public affiliate slug, no personal data. Lifetime is the campaign's configured cookie window (60 days by default, 1 to 365 days). Details in section 4.

Analytics (opt-in)

Helps us see which product features are useful. Disabled until you accept this category.

  • PostHog (cookie and localStorage ph_*_posthog, sessionStorage ph_*_window_id and ph_*_primary_window_exists). Anonymous product analytics. Nothing is loaded or stored until you accept; the cookie is set on rekomi.com and its subdomains with a 365-day lifetime. If you later withdraw consent we opt out and reset the PostHog identity, which leaves an opt-out marker (__ph_opt_in_out_*) in its place. We do not enable session replay in PostHog.
  • Google Analytics 4 (_ga, _ga_*, 2 years, set on rekomi.com and its subdomains). Aggregate traffic and marketing attribution across rekomi.com and app.rekomi.com. The Google tag itself loads on every visit in Consent Mode with all storage denied, which means no cookies are written and only anonymous, cookieless pings are sent until you accept this category. IP addresses are anonymized by GA before storage. Lifetimes per Google's cookie documentation.

Marketing (opt-in)

Powers our support chat and identification. Disabled until you accept this category.

  • Intercom Messenger (intercom-id-*, intercom-session-*, intercom-device-id-*). Lets us answer your chat without you re-introducing yourself on every page. The Messenger only loads on rekomi.com and app.rekomi.com after you accept; it never loads on brand campaign pages, deal rooms, or public creator pages. Set by Intercom on the page's own domain; we never see the cookie values directly. Lifetimes per Intercom's cookie documentation (the id and device cookies persist for months, the session cookie for about a week).
  • Accepting this category also tells Google Consent Mode that ad storage is allowed. We do not run Google Ads tags, so this sets no additional cookies today.

3. Always-on with no consent requirement

Sentry error monitoring runs on every page to catch crashes and broken flows. Sentry sets no cookies. When an error occurs it can send a short replay of the moments before the error with all text masked and all media blocked; to stitch that replay together it keeps a replay session id in sessionStorage (sentryReplaySession) that is discarded when the tab closes. We treat this as a legitimate-interest processing activity under GDPR Article 6(1)(f), consistent with how application monitoring is commonly handled.

Fraud device signals. To detect fake clicks, leads, and signups, we load a device-fingerprinting tag from our fraud-detection provider, IPQualityScore, on our public lead forms, campaign apply forms, and creator proposal forms, and alongside the tracking script on cost-per-click links. The tag is served from a rekomi.com subdomain and reads browser and device characteristics (for example, screen, language, and user-agent details) to produce an opaque request id that we attach to the submission or click; Rekomi itself sets no cookie or storage for this. Any storage the tag keeps for its own operation is described in IPQualityScore's privacy policy. The signals are used only to score fraud risk, never for advertising or cross-site tracking, and we treat this as legitimate-interest processing under GDPR Article 6(1)(f).

4. On customer affiliate-tracking domains

When a Rekomi customer uses our tracking script on their site, the script records the referring affiliate in two places so attribution survives blocked third-party cookies:

  • Cookie _rkmi (and the legacy alias _rekomi_aff, both carrying the same affiliate slug). Set by api.rekomi.com, or by the brand's own custom tracking domain when one is configured, in which case it is a first-party cookie on the brand's site. It persists for the campaign's configured cookie window (60 days by default, configurable per campaign from 1 to 365 days) and is readable by the brand's checkout so the sale can be credited.
  • localStorage on the brand's site (rkmi:{campaign id} with an expiry entry rkmi:{campaign id}:exp, legacy rekomi:aff:*). Holds the same slug for up to 90 days as a backup. The commission window itself is enforced by our servers using the campaign's configured cookie window, so a stored slug older than that window earns no commission.
  • sessionStorage rkmi_cv_*: a once-per-session marker the script writes when it records a referred visitor's email (from the brand's own Rekomi.convert call or the tag's email capture), so the same email is not reported twice. Discarded when the tab closes.
  • Shopify stores using our Shopify app: the web pixel keeps the click reference in the pixel's own storage (rkm_click) until the order completes. Brands following our manual Shopify recipe set a rekomi_via cookie (60 days) from their own custom pixel.

For cost-per-click and cost-per-lead links, the visitor first passes through our neutral rekomi.link domain, which records the click and sets the same _rkmicookie there for the campaign's cookie window before redirecting to the brand's site.

Cookie handling on customer domains is governed by the customer's own privacy and cookie policies, not this one. rekomi.link, brand campaign pages, and custom domains are served through Cloudflare, which may set its own security cookies (for example __cf_bm) when it screens suspicious traffic; see Cloudflare's cookie documentation.

Brand campaign signup pages and affiliate portals

A brand's campaign signup page lives on {handle}.rekomi.com or the brand's custom domain. Rekomi's own consent banner, Intercom, our Google Analytics and PostHog tags, and our marketing-site tracking script never run there. The page stores the anonymous consent id (rekomi-anon-session) in localStorage, a rekomi:recruited_by:*localStorage entry when you arrive through an affiliate's recruit link (so the referral survives a sign-in round trip), and, if the brand has enabled the affiliate portal, a sign-in cookie __Host-rk_portal_rt (30 days, that host only, not readable by scripts) after you log in to it.

A brand can add its own Google Analytics 4, Google Ads, Meta, TikTok, or LinkedIn tag IDs to its campaign signup page. When it does, that page shows its own cookie banner in the brand's name. The pixel scripts are not loaded, and set no cookies, until you accept: GA4 falls under Analytics, and Google Ads, Meta, TikTok, and LinkedIn fall under Marketing; declining loads nothing. Rekomi's own Google Analytics and PostHog never load on brand portal hosts, so accepting the brand's banner grants consent to the brand's pixels only. The brand is the controller of its pixels and of the data they collect, and its own privacy policy governs them. A signup page with no pixels configured shows no banner and loads no trackers.

Embedded admin apps

Inside the Shopify, Wix, and BigCommerce admin apps, Rekomi sets no cookies of its own: the platform's session token is held in memory and refreshed by the platform SDK. We keep a few interface flags in browser storage (for example rekomi-embedded-pending-plan andrekomi-shopify-charge-approved-at in sessionStorage, andrekomi:embedded:onboarding-dismissedin localStorage). The platform's own admin cookies are governed by that platform's policy.

5. Do Not Track

We honor the Do Not Track signal where reasonable. PostHog is configured to respect DNT when initialized.

6. Audit + data subject access

Each consent decision is recorded with an anonymous session id, a hash of your IP address, your browser user agent, and the policy version you consented to. Records are retained as part of the append-only audit log. On a Data Subject Access Request we can produce the full consent timeline for any session.

7. Changes

Material changes (adding a third-party cookie, changing a category mapping) trigger a re-prompt and are reflected in the policy version and the “Last updated” date above.