Cookie Policy

Effective February 19, 2026

What Are Cookies?

Cookies are small text files stored on your device by a web browser. They allow websites to remember information about your visit, such as your login session or preferences. Cookies can be “session cookies” (deleted when you close your browser) or “persistent cookies” (stored until they expire or you delete them).

Cookies We Use

RefStack uses a minimal set of cookies, each with a specific purpose. We do not use advertising cookies or track you across third-party websites.

sb-*Essential7 days · Supabase

Set by Supabase to maintain your login session. Required for the Platform to function. Cannot be disabled without losing access to your account.

ref_affFunctional30 days · RefStack

Set server-side (httpOnly) when a visitor clicks an affiliate tracking link. Stores the affiliate ID and click timestamp to attribute conversions within the 30-day attribution window. Only set when you click an affiliate link, not on standard site visits.

ph_*Analytics1 year · PostHog

Set by PostHog to collect anonymized usage data (page views, feature interactions, session information). Helps us understand how the Platform is used.

Cookieless Analytics

We also use Plausible Analytics for website traffic measurement. Plausible is cookieless and does not store any personal data or IP addresses. It cannot identify or track individual visitors across sessions. No cookie consent is required for Plausible. See our Sub-Processors page for more detail.

What We Do Not Use Cookies For

  • Advertising or ad targeting
  • Cross-site tracking
  • Selling data to third parties
  • Fingerprinting or device profiling

How to Control Cookies

You can control cookies in the following ways:

  • Browser settings: Most browsers allow you to block or delete cookies. Note that blocking essential cookies (sb-*) will prevent you from logging in to the Platform.
  • Do Not Track: PostHog analytics respects the Do Not Track (DNT) browser signal. Enabling DNT in your browser will opt you out of analytics tracking.
  • Affiliate tracking: The ref_aff cookie is only set when you click an affiliate tracking link. It expires after 30 days and can be deleted at any time via your browser’s cookie settings.

Contact

For questions about our use of cookies, contact us at privacy@refstack.io.