Cookie Policy
Last updated: July 25, 2026
1. What Cookies Are
Cookies are small files stored on your browser or device. Similar technologies include local storage, session storage, pixels, SDKs, and server logs.
2. How Ruunly Uses Cookies
Ruunly uses cookies and similar technologies for:
- authentication and session management;
- security and fraud prevention;
- CSRF protection;
- remembering preferences;
- routing users to the correct tenant or workspace;
- product analytics and error diagnostics;
- email unsubscribe and preference links;
- advertising/conversion measurement, only when you give explicit consent (Google Ads and/or the Meta advertising pixel, and only where Ruunly has that integration configured).
3. Categories
Ruunly uses only the following categories of cookies. Section 4 lists the individual cookies Ruunly itself sets.
| Category | Required? | Examples |
|---|---|---|
| Essential cookies | Yes | Login sessions, CSRF tokens, tenant routing, security |
| Preference cookies | Optional where used | UI preferences, dismissed notices |
| Analytics cookies | On by default — you can decline | First-party product analytics (PostHog, routed through our own domain) and Google Analytics |
| Advertising cookies | Off by default — requires your explicit consent | Google Ads conversion pixel and the Meta (Facebook) advertising pixel, used to measure whether an ad led to a signup. Each loads only if you click “OK” on the cookie banner AND Ruunly has that specific integration configured |
4. Cookies Ruunly Sets
These are the cookies Ruunly itself sets on ruunly.com. All of them are first-party (set by Ruunly, readable only by Ruunly), and none of them are sold or used for cross-site advertising. Your browser may also hold cookies set by the third parties in section 5.
| Cookie | Purpose | Category | Lifetime |
|---|---|---|---|
sb-…-auth-token | Your logged-in session, issued by our authentication provider (Supabase). Without it you cannot stay signed in. | Essential | Session / until sign-out or expiry |
ruunly_consent | Remembers your cookie-banner choice so we do not ask again and so a decline is honored on every later visit. | Essential | 1 year |
ruunly_aid | A random, signed visitor ID with no name, email, or profile attached. It lets a partly finished signup be resumed and lets us count unique visits without accounts. Set on our marketing pages when you first arrive — before the banner is answered — because it is how the site works, not an advertising identifier. It is HTTP-only, so page scripts cannot read it. | Essential | Up to 180 days |
ruunly_aff_code | Records which affiliate referral link you arrived through, so the referring partner is credited if you later sign up. Signed and HTTP-only, so page scripts cannot read or forge it. Set only when you follow a referral link. | Essential (referral attribution) | 45 days |
ruunly_slb_dismissed_v1 | Remembers that you closed the launch notice banner so it stays closed. | Preference | 1 year |
ruunly_internal | Flags a browser as Ruunly staff or QA so our own visits are excluded from product analytics. Set only by visiting a Ruunly page with ?internal=1; ordinary visitors never receive it. | Essential (internal testing) | 1 year |
ruunly_utm | Briefly holds the campaign parameters already present in the URL you arrived on (utm_source, utm_medium, utm_campaign, utm_content, utm_term, gclid, fbclid, rdt_cid) so that if you sign up we can record which campaign brought you. Written only when the URL carries those parameters, and set before the banner is answered. | Essential (short-lived attribution) | 5 minutes |
ruunly_qa | Marks a browser session as an internal Ruunly test run so test activity is excluded from real data and test pages are not indexed. Not set for ordinary visitors. | Essential (internal testing) | 4 hours |
Analytics and advertising technologies are loaded by the providers named in section 5 and set their own cookies or storage under their own names, subject to the consent rules in section 5 and your choices in section 6.
5. Third-Party Technologies
Ruunly may use service providers such as Supabase, Cloudflare, Stripe, Resend, Twilio, Inngest, and analytics/error monitoring providers. These providers may process request metadata, device data, or cookies as needed to provide their services.
Stripe may use cookies or similar technologies during checkout, payment, fraud prevention, and connected-account onboarding.
6. Your Choices
Analytics cookies run by default on the Ruunly marketing site. The cookie banner shown on your first visit lets you decline them immediately using the “Decline analytics” control; once stored, that decline is always honored. To change your choice later, clear cookies for this site in your browser settings — the banner will reappear so you can choose again. Blocking essential cookies may prevent login, checkout, account security, customer portals, or other features from working.
Advertising cookies (a Google Ads conversion pixel and/or the Meta advertising pixel) are off by default and only load if you click “OK” on the cookie banner — the same action that keeps analytics on — and only where Ruunly has that integration configured. Clicking “Decline analytics” keeps both analytics and every advertising cookie off. If Ruunly later adds targeted advertising or cross-context behavioral advertising beyond ad-performance measurement, Ruunly will update this Policy and provide any additional legally required choices.
7. Contact
Cookie questions: [email protected]
Ruunly LLC
7901 4th St N #33392
St. Petersburg, FL 33702