Cookie Policy
- Version
- 1.2
- Effective
- July 28, 2026
- Last updated
- August 24, 2026
1. About this Policy
This Cookie Policy explains how TraIDCred uses cookies and similar technologies (such as browser local storage) on the Services. It supplements the Privacy Policy. TraIDCred's use of these technologies is deliberately minimal. The cookies currently used by the Services are described in §3.
2. The four categories
We group cookies and similar technologies into four categories.
| Category | What it means | In use today |
|---|---|---|
| Essential | Required for the Services to work at all — signing in and keeping your session secure. Blocking these prevents you from using the Services. | Yes |
| Functional | Remembers a choice or a context so a feature behaves correctly. Blocking these degrades a feature rather than the Services. | Yes |
| Analytics | Measures how the Services are used and how visitors arrived, in aggregate. First-party only. Never used to build an advertising profile or to follow you across other websites. | Yes |
| Advertising / Marketing | Third-party technologies that measure advertising campaigns or build advertising audiences — for example an advertising pixel, tag, or conversion script. | Yes — but only if you accept them. See §5. |
3. The cookies we currently use
All cookies below are first-party — set on the TraIDCred domain. Who sets each one, and what it is set with, differs, so the table says so for each:
- The cookies TraIDCred sets itself —
traidcred_vid,traidcred_from_qr,traidcred_ref,
traidcred_ref_src, traidcred_attr_first, traidcred_attr_last — are set by our servers as HttpOnly (page scripts cannot read them), SameSite=Lax, Secure in production, scoped to the whole site.
- The consent cookie (
traidcred_consent) is set by the page and is deliberately readable by page
scripts — that is how your choice is applied before anything else loads. SameSite=Lax, Secure in production.
- The sign-in cookie is set by our authentication provider, Supabase, using its own settings. It
is SameSite=Lax and scoped to the whole site, and it is readable by page scripts because Supabase's client library requires that to keep your session current. Its lifetime is controlled by Supabase, not by us.
- The Meta cookies (
_fbp,_fbc) are set by Meta's script running on our domain, with
settings and lifetimes controlled by Meta, not by us. They are readable by page scripts, and they appear only if you accept advertising cookies.
| Cookie | Category | Purpose | Duration | What it contains |
|---|---|---|---|---|
sb-<project>-auth-token (and its numbered parts) | Essential | Keeps you signed in and secures your session. Set by our authentication provider, Supabase, on our domain, using Supabase's own cookie settings. | Controlled by Supabase; the session inside it is short-lived and refreshes, while the cookie itself may persist for up to approximately 400 days | Yes — it identifies your signed-in account. |
traidcred_consent | Essential | Records whether you accepted or declined optional advertising and measurement cookies, so we apply your choice and do not ask you again. Readable by page scripts — that is how your choice is applied. | 1 year | A choice and a timestamp. |
traidcred_vid | Analytics | Its value feeds a salted, per-day, one-way hash used only to avoid double-counting a profile view or QR scan within a short window. Because the salt changes every day, the resulting hash cannot be used to follow you over time. | 1 year | A random value with no meaning outside TraIDCred; we store only the daily hash, never the value itself. |
traidcred_from_qr | Functional | A one-time marker so a QR scan is counted once and not double-counted as a separate profile view. | 30 seconds | A single marker value with no meaning outside TraIDCred. |
traidcred_ref | Functional | Records the referral code you arrived through, so the business that referred you is credited if you create an account. First touch only — a later referral link does not replace it. | 90 days | A referral code only. |
traidcred_ref_src | Functional | Records how that referral link was shared (for example, a printed flyer), so we can tell which sharing methods work. | 90 days | A sharing-method label only. |
traidcred_attr_first | Analytics | First-touch attribution. Records the campaign details of the _first_ visit that brought you to TraIDCred: the utm_source, utm_medium, utm_campaign, utm_term and utm_content values in the link you followed, the website you came from (reduced to its domain only), the page you landed on, and the time. If you accepted advertising cookies, it also records the fbclid advertising click identifier from a Meta ad you clicked. Written once and never overwritten. | 90 days | Campaign and referral information — see §4. |
traidcred_attr_last | Analytics | Latest-touch attribution. The same campaign details for your _most recent_ visit, so we can tell which channel first found you apart from which one you most recently returned through. Updated only when the channel changes. | 90 days | Campaign and referral information — see §4. |
_fbp | Advertising / Marketing | Only if you accept. Set by the Meta Pixel. A browser identifier Meta uses to measure our advertising and to show our ads to people who have visited TraIDCred. Set by Meta's script on the TraIDCred domain. | Set by Meta; Meta currently documents about 90 days | May constitute personal information, or become associated with other information, including by Meta. See §§4–5. |
_fbc | Advertising / Marketing | Only if you accept, and only if you arrived by clicking one of our Meta ads. Records that ad click so we can tell which ad brought you. | Set by Meta; Meta currently documents about 90 days | May constitute personal information, or become associated with other information, including by Meta. See §§4–5. |
4. What the attribution cookies do and do not contain
The two attribution cookies exist so TraIDCred can answer one question: which of our own efforts actually reach tradespeople. They are worth being precise about.
They contain campaign labels from the link you clicked, the domain of the referring website, the page you landed on, and a timestamp.
They do not contain your name, email address, TraIDCred account identifier, IP address, or a TraIDCred-generated device identifier.
Advertising click identifiers. If you accepted advertising cookies, the first-touch cookie also holds the fbclid identifier from a Meta ad you clicked, so we can tell which ad reached you — and that identifier, together with the Meta cookies in §3, is the only thing from this set that is ever shared with Meta. If you declined, or have not chosen, no advertising click identifier is recorded at all. We do not record Google's gclid or LinkedIn's li_fat_id in any case.
The campaign labels are not sent to any advertising platform. The utm_* values, the referring domain and the landing page stay with TraIDCred.
What information do they contain? These cookies contain campaign and referral information, not your name, email address, TraIDCred account identifier, IP address, or a TraIDCred-generated device identifier. If you create an account, these attribution values are associated with your account and treated as personal information under this Policy and the Privacy Policy, including for applicable access and deletion requests.
5. Advertising and measurement — only with your consent
TraIDCred uses two Meta (Facebook and Instagram) advertising technologies, and only if you accept them.
- Meta Pixel — a script that runs in your browser on our marketing and sign-up pages. It records
that a page was viewed and sets the _fbp and _fbc cookies described in §3. It lets us measure whether our ads bring tradespeople to TraIDCred, and lets us show our ads to people who have visited.
- Meta Conversions API — the same measurement, sent from our servers rather than from your browser,
when a meaningful step happens: an account is created, a business profile is created, identity verification completes, or a membership is paid for.
Neither runs until you press Accept. If you decline, or simply never choose, no Meta script loads, no Meta cookie is created, no browser event is sent, no advertising click identifier is recorded, and no server-side advertising event is sent for you. Declining does not affect how TraIDCred works.
Changing your mind. Use Cookie preferences in the footer at any time. Withdrawing stops the Pixel from loading again, stops all future advertising events including the server-side ones, and expires the Meta cookies on that browser where we are technically able to. It does not delete information Meta already received — for that, use Meta's own settings.
Where these do NOT run. The Meta Pixel never loads on a public Trust Profile (/verify/…) — the pages homeowners use to check a contractor — nor on our legal and privacy pages, nor on any signed-in dashboard, representative or administrative page. Those pages carry no advertising technology regardless of your choice.
If your browser sends a Global Privacy Control signal, we treat that as your answer: we do not show you the banner and we activate nothing. You can still choose to opt in deliberately using Cookie preferences in the footer.
What Meta receives is listed in Privacy Policy §2.2 and §5. It never includes your name, email address, phone number, or anything from a credential, document, identity verification, or homeowner request.
6. What we do not do
We do not sell your personal information. We do not use device fingerprinting. We place no advertising technology on public Trust Profiles or on our legal and privacy pages. With your consent we use the Meta technologies described in §5, which involve sharing the limited information described in Privacy Policy §2.2 with Meta for advertising measurement and retargeting — that is the only such sharing we do, and declining or withdrawing stops it entirely.
7. Managing cookies
Most browsers let you block or delete cookies through their settings. Blocking Essential cookies may prevent you from signing in or using core features. Blocking the Functional or Analytics cookies will not prevent you from using the Services — a referral may go uncredited and a visit may be counted twice, but nothing stops working. The Advertising / Marketing cookies are off unless you accept them, and you can withdraw at any time through Cookie preferences in the footer.
8. Changes
We may update this Policy; material changes will be versioned and, where appropriate, notified consistent with the Electronic Communications & E-Sign Consent.
9. Contact
Questions about this Cookie Policy: privacy@traidcred.com.