Cookies are small values stored by your browser and sent with relevant requests. Local storage keeps values in your browser for a particular website. We use both for the purposes described below. For information about other personal data, see our privacy notice.
Essential storage
This storage supports sign-in, security and preferences you select. Rejecting analytics does not disable these functions.
cr_session— staff sign-in- An HTTP-only, secure app cookie that authenticates your session. Sign-in sessions last up to 12 hours, including sessions used during account setup or workspace selection. Signing out clears the session cookie.
cr_trusted— trusted device- An HTTP-only, secure app cookie used when you choose to trust a device during two-step verification. It lasts up to 30 days. You can revoke trusted devices in account security settings.
privacyrequests.cookie-consent.v1— cookie preferences- Local storage records your choice, the date and the analytics configuration it applies to. We treat it as expired after 180 days and ask again. It stays in browser storage until overwritten or cleared; it does not identify your account. The website and app remember choices separately.
- Appearance and saved views
- The app uses local storage for your selected appearance (
clearrequest.appearance) and saved inbox views (privacyrequests.saved-inbox-views). These preferences remain until changed or cleared in your browser. - Connecting an external tool
- The secure
cr_mcp_consentcookie andmcp-consent-returnlocal storage support the sign-in and approval flow when you connect a tool. They are valid for up to 10 minutes; the local storage value is removed when consumed.
Optional analytics
With your permission, we use Google Analytics 4 and Matomo on the marketing website and staff app. The cookie banner controls both providers together. Neither provider loads before you accept analytics, or after you reject it. An earlier acknowledgement of essential storage is not analytics consent.
Analytics helps us measure visits, campaign referrals, CTA clicks, successful signups and inquiries, checkout starts and confirmed subscription activity. Google Analytics 4 is provided by Google. Matomo sends analytics to our installation at analytics.jumpstartlabs.co. Our integration requires your permission before loading either provider. It sends sanitized page routes, fixed event labels, limited campaign labels and referring site origins. It excludes arbitrary query parameters, fragments, referrer paths and case or task identifiers. We do not intentionally send request contents, uploaded files, names or email addresses through these events. An analytics provider also receives network information, such as your IP address, when your browser connects to it.
With consent, analytics visitor cookies are shared between privacyrequests.co and app.privacyrequests.co to connect visits to conversions. The integrations use first-party analytics cookies: Google Analytics uses _ga and _ga_*; Matomo uses _pk_id.*, _pk_ses.* and, where applicable, _pk_ref.*. Our configuration limits persistent analytics cookies to 180 days and Matomo session cookies to 30 minutes. These cookies are not set by the new integrations while analytics is disabled or rejected. No advertising or session-recording integration is included. We do not use Google advanced consent-mode pings or cookieless Matomo tracking before consent. Cookie lifetimes describe browser storage, not the retention period of data already collected by the providers. See our privacy notice for recipients and international processing and retention.
For consenting billing administrators, our server records confirmed purchases, renewals, refunds and cancellations using analytics identifiers, transaction references, currency and amounts. This association expires with the original consent, after no more than 180 days. Withdrawing analytics while signed in removes that account’s pending subscription analytics and stops future delivery. Browser settings cannot erase events already delivered. No payment card details are sent to analytics.
Managing your choice
Use Cookie settings in the website footer or at the bottom of the staff app to review your current choice. You can accept or reject both analytics providers with equal ease. You can also for this website.
Rejecting analytics stops further collection by our integration and removes the known analytics cookies it can access on the current site. It does not undo data already sent. For questions about previously collected data, contact us at support@privacyrequests.co.
Choices apply to this browser and this site. Make your choice separately on the marketing website and app, and on other browsers or devices. We ask again after 180 days, when the provider configuration or policy version changes, or if your preference is missing or invalid. If your browser blocks local storage, the choice applies only to the current page and cannot be remembered across visits.
You can delete cookies and local storage in your browser settings. Clearing essential storage may sign you out or reset your preferences. Blocking JavaScript prevents our optional analytics integration from loading.
Requester pages
Our request forms, requester status pages, email verification pages and secure delivery pages do not display this banner or load our optional analytics integrations. They may still need security or access storage to operate. A secure cr_delivery_* cookie is used after delivery access is verified; it lasts up to 30 minutes, is limited by the delivery link's lifetime and can be revoked. Requester pages can remember a selected language in cr_requester_locale local storage until it is changed or cleared.
If a company embeds its request form in another website, that host website may have its own cookies and policy. Contact the company handling your request about its website and privacy practices.
Questions and changes
We will update this policy when our use of cookies changes. Contact support@privacyrequests.co with questions about Privacy Requests storage or privacy choices.