Cookie Policy
Last updated: June 14, 2026
This Cookie Policy explains how OfferTrackr LLC ("OfferTrackr," "we," "us") uses cookies and similar tracking technologies on offertrackr.com, including the seller, collection, and item pages we serve at offertrackr.com/{seller}. It identifies each cookie we set or allow, what it does, how long it lasts, and how you can control it. Read it alongside our Privacy Policy, which explains the broader personal data we collect.
1. What are cookies and similar technologies?
Cookies are small text files placed on your device by a website. We also use closely related technologies — first-party local storage, session storage, and pixel-free analytics beacons sent via navigator.sendBeacon. For brevity we refer to all of these as "cookies" in this policy and call out where the technology is something other than a cookie.
Cookies can be first-party (set by offertrackr.com) or third-party (set by a service we embed, such as PostHog or Stripe). They can be session cookies (deleted when you close your browser) or persistent (kept until they expire or you delete them).
2. The categories of cookies we use
We group cookies into three categories. You can accept or reject each category in the consent banner shown on your first visit, or at any time by selecting Cookie Preferences in the page footer.
2.1 Strictly necessary (always on)
These are required for the site to function and are exempt from prior consent under EU/UK ePrivacy rules and applicable US state law. You cannot opt out of these and still use the affected feature.
ot_cart— first-party, HttpOnly, encrypted, expires after 1 hour. Holds the items you've added to your offer cart on a seller's page. Set only after you add something to a cart.ot_session— first-party, HttpOnly, expires after 30 minutes of inactivity. A random identifier used during AI-assisted negotiation sessions so the assistant can follow your side of the conversation. Not linked to any account.- Stripe payment cookies — set by Stripe only on the checkout page when you place a reservation. Required for fraud prevention and to complete the payment you initiated. Typical names include
__stripe_mid,__stripe_sid, andm. Governed by Stripe's own privacy and cookie policies. - Load balancing and security — short-lived session cookies set by AWS for request routing and integrity.
Similar technology — Strictly Necessary: we store your cookie preferences in first-party local storage under the key ot_consent. It contains your category choices and the policy version you accepted. It is not a cookie and is never sent to our servers on regular requests; we send a one-time audit record of your decision separately (see Section 6).
2.2 Functional (opt-in)
ot_viewer— first-party persistent cookie (30 days) containing a randomly generated UUID. We use it to dedupe view counts on items and collections so the same anonymous viewer isn't counted multiple times within a 15-minute window. Not linked to any account.
2.3 Analytics (opt-in)
- PostHog — third-party analytics from PostHog Inc., served from
us.i.posthog.com. Sets cookies and local storage entries (typicallyph_*_posthog) holding a pseudonymous device identifier, session identifier, and feature- flag state. Persistent up to 12 months. We use it for product analytics, feature-flag rollout, A/B testing, and, on signed-in app pages only, session replay. We do not load any PostHog code on your device until you accept this category. PostHog acts as our processor under a data processing agreement. See PostHog's privacy policy for details on its sub-processors. - Web Vitals telemetry — performance metrics (LCP, INP, CLS) collected via the open-source
web-vitalslibrary and sent to PostHog as events. No additional cookies are set.
3. Full cookie inventory
| Name | Set by | Category | Duration | Purpose |
|---|---|---|---|---|
ot_cart | OfferTrackr (first-party, HttpOnly) | Strictly necessary | 1 hour | Encrypted shopping cart contents |
ot_session | OfferTrackr (first-party, HttpOnly) | Strictly necessary | 30 minutes | Guest negotiation session identifier |
__stripe_mid, __stripe_sid, m | Stripe (third-party, checkout only) | Strictly necessary | Session – 12 months | Fraud prevention; payment session |
ot_viewer | OfferTrackr (first-party) | Functional | 30 days | Anonymous view-count dedupe |
ph_*_posthog, ph_*_window_id | PostHog (third-party) | Analytics | Session – 12 months | Product analytics, feature flags, session replay (signed-in app pages only) |
4. Your choices
4.1 The consent banner and Cookie Preferences
On your first visit we show a non-blocking consent banner with three equally available options: Accept all, Reject all, or open Manage preferences to toggle Functional and Analytics independently. You can change your choice at any time by selecting Cookie Preferences in the page footer. Changes take effect immediately.
If you do not interact with the banner, we treat that as a rejection of non-essential cookies. We never assume consent from continued browsing.
4.2 Global Privacy Control (GPC)
If your browser sends a Global Privacy Control signal, we treat it as a valid opt-out of analytics cookies and of any "sharing" of personal information under the California Consumer Privacy Act / California Privacy Rights Act. We disable PostHog and Web Vitals analytics for the duration of your visit and do not show the consent banner. We re-check GPC on every page load, so if you turn it on after previously accepting analytics, we will respect the new signal automatically. Read more about GPC at globalprivacycontrol.org.
4.3 Do Not Track (DNT)
The DNT header is not a recognized standard and many browsers send it by default. We do not act on DNT alone, but we do honor GPC, which has superseded DNT as the recognized opt-out signal under US state privacy laws.
4.4 In-app browsers
When you open offertrackr.com inside an in-app browser (for example, by tapping a link in Instagram, Facebook, X, LinkedIn, TikTok, or Snapchat), we suppress the consent banner and disable all non-essential cookies for that session. Open the page in your system browser to manage analytics.
4.5 Browser-level controls
You can also block or delete cookies in your browser settings. Doing so may break parts of the site, especially checkout. See:
5. Your legal rights
5.1 EU and UK (GDPR / UK GDPR / ePrivacy)
If you are in the European Economic Area, the United Kingdom, or Switzerland, our lawful basis for setting non-essential cookies is your consent, which you provide via the consent banner. You can withdraw consent at any time through Cookie Preferences. Withdrawal does not affect the lawfulness of processing before withdrawal. You have the rights of access, rectification, erasure, restriction, portability, and objection described in our Privacy Policy.
5.2 California (CCPA / CPRA)
We do not "sell" personal information in the everyday sense. Some analytics processing involving third-party cookies may qualify as "sharing" under the CPRA. We treat both the GPC signal and a rejection of Analytics cookies as a valid opt-out of sale and sharing. California residents may also exercise the rights to know, delete, correct, and limit use of sensitive personal information by emailing privacy@offertrackr.com.
5.3 Other US state privacy laws
If you are a resident of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Tennessee, Iowa, Indiana, Delaware, New Jersey, New Hampshire, Minnesota, or any other US state with a comprehensive privacy law in force, you may have similar rights to access, delete, correct, and opt out of targeted advertising or profiling. We honor the GPC signal as a universal opt-out under each of these statutes that recognize it. To exercise any other right, email privacy@offertrackr.com.
6. How we record your consent decision
When you make a choice in the consent banner or preferences modal, we store your choice in first-party local storage on your device and send a one-time record to our backend containing: the categories you chose, the policy version you saw, your user-agent string, whether GPC was active, and a one-way salted hash of your IP address. We keep this record solely for audit purposes — to demonstrate, if challenged by a regulator, that consent was obtained. We never use it for advertising or analytics.
7. International transfers
PostHog (US-hosted region us.i.posthog.com) and Stripe process data in the United States. For users in the EEA, UK, or Switzerland, transfers rely on the EU Standard Contractual Clauses and the UK International Data Transfer Addendum where applicable. PostHog and Stripe are also self-certified under the EU–US and UK Extension Data Privacy Framework.
8. Changes to this policy
We will post material changes on this page with an updated effective date. When the change is material, we increment the policy version recorded with your consent so the banner re-prompts you for a fresh decision. The "Last updated" date at the top of this page indicates when this policy was last revised.
9. Contact us
- By email: privacy@offertrackr.com (privacy and data rights)
- By email: support@offertrackr.com (general support)
- By post: OfferTrackr LLC, 18970 Bryant Rd, Lake Oswego, OR 97034, USA