Cookie Policy
Last updated: 2026-10-02
This page describes the cookies and similar technologies used by our website and dashboard. We use the cookies needed to operate the Service plus minimal analytics, and—only if you consent via the cookie banner—advertising cookies that measure which ad campaigns lead to sign-ups. If you dismiss the banner, no advertising cookies are set.
Categories
Strictly necessary cookies are required for the site to function (sign-in sessions, security tokens). They cannot be disabled while using the dashboard.
Functional cookies remember preferences you set (e.g., active client when you belong to more than one).
Analytics cookies help us understand how the site is used in aggregate.
Advertising cookies (the Meta Pixel and Google Ads conversion linker) measure which ad campaigns lead to sign-ups. These load only if you click “OK” on the cookie banner; dismissing the banner keeps you free of them. California law may treat these tools as a “sale” or “sharing”; you can opt out at any time on our Do Not Sell or Share page, and we honour your browser’s Global Privacy Control signal as an opt-out.
Cookies we set
| Category | Name | Purpose | Duration | Source |
|---|---|---|---|---|
| Strictly necessary | sb-access-token, sb-refresh-token | Supabase Auth session (signed-in users only). Without these, the dashboard cannot identify you. | Session + 30 days | Supabase |
| Strictly necessary | rre_active_client | Remembers which client a multi-membership user is viewing in the dashboard, so the active tenant stays the same across page loads. | 1 year | Revenue Recovery Engine |
| Strictly necessary | rre_oauth_state | CSRF nonce during the Google Calendar OAuth flow. Set briefly during a connect attempt; deleted on completion. | 10 minutes | Revenue Recovery Engine |
| Strictly necessary | rre_cookie_consent | Records your cookie-banner choice so we don't re-prompt on every page load. | 1 year | Revenue Recovery Engine |
| Analytics | rre_sid (sessionStorage), rre_seen, rre_analytics_optout (localStorage) | Our own page counts: a random id for one browser tab (deleted when the tab closes), a first-visit flag, and an opt-out flag for our staff. No IP address and no cross-site tracking. | Tab session / until cleared | Revenue Recovery Engine |
| Analytics | hc_* and related identifiers | HeyCatch website and dashboard usage analytics (pages viewed, interactions). | Up to 1 year | HeyCatch |
| Analytics | _ga, _ga_* | Google Analytics — which pages and campaigns bring visitors. Loaded ONLY after you click “OK”; not set if you dismiss. | Up to 2 years | |
| Advertising | _fbp, _fbc | Meta (Facebook) Pixel — measures which ad campaigns lead to sign-ups. Loaded ONLY after you click “OK” on the cookie banner; not set if you dismiss it. | Up to 90 days | Meta Platforms |
| Advertising | _gcl_au | Google Ads conversion linker — attributes sign-ups to Google ad clicks. Loaded ONLY after you click “OK”; not set if you dismiss. | Up to 90 days | |
| Advertising | rre_first_touch, rre_last_touch (localStorage) | First/last marketing touch (UTM tags, referrer). Advertising click identifiers (e.g. gclid, fbclid) are stored here ONLY after you click “OK”; UTM/referrer are kept as first-party analytics regardless. | Until cleared | Revenue Recovery Engine |
Your choices
You control advertising cookies through the cookie banner: click “OK” to allow them, or “Dismiss” to decline. To change your choice, clear the rre_cookie_consent key (or all cookies) in your browser settings and reload — the banner will reappear. Clearing cookies will also sign you out and remove preferences.