GrantRT Cookie Policy
Effective Date: September 1, 2026 Version: 1.0 Operator: dakdan LLC, a Colorado limited liability company, doing business as GrantRT Contact: info@grantrt.com Jurisdiction of operation: Colorado, United States of America
1. Scope
This Cookie Policy explains how GrantRT uses cookies and similar technologies on grantrt.com, its subdomains, and the GrantRT application (the "Service"). It supplements and is incorporated into the GrantRT Privacy Policy and Terms of Service.
2. What These Technologies Are
Cookies are small text files placed on a device by a website and returned to that website on later visits.
First-party cookies are set by grantrt.com. Third-party cookies are set by another domain, such as a payment or analytics provider.
Session cookies expire when the browser closes. Persistent cookies remain until they expire or are deleted.
Local storage and session storage are browser storage mechanisms used to hold application state, drafts, and preferences on the device.
Pixels and web beacons are small transparent files used to record whether a page or email was opened.
Software development kits and scripts are code embedded in the Service by us or a vendor to deliver a function such as error monitoring or support chat.
In this Policy, "cookies" refers to all of these technologies.
3. Cookie Categories
GrantRT groups cookies into four categories. Strictly necessary cookies are always active because the Service cannot function without them. The other three categories are subject to consent where required by law.
3.1 Strictly Necessary
Required for authentication, session integrity, security, load balancing, and preserving unsaved work. These cannot be disabled through our preference center.
| Cookie | Provider | Purpose | Type | Duration |
|---|---|---|---|---|
grt_session |
GrantRT (first party) | Maintains the authenticated session | HTTP cookie | Session |
sb-access-token |
Supabase (first party context) | Authentication access token | HTTP cookie | 1 hour |
sb-refresh-token |
Supabase (first party context) | Renews the authenticated session | HTTP cookie | 30 days |
grt_csrf |
GrantRT (first party) | Cross-site request forgery protection | HTTP cookie | Session |
grt_consent |
GrantRT (first party) | Stores cookie preferences | HTTP cookie | 12 months |
__cf_bm |
Cloudflare (third party) | Bot management and abuse prevention | HTTP cookie | 30 minutes |
__Host-next-auth.csrf-token |
GrantRT (first party) | Sign-in flow integrity | HTTP cookie | Session |
grt_draft_state |
GrantRT (first party) | Local storage of unsaved application drafts | Local storage | Until cleared |
__stripe_mid |
Stripe (third party) | Payment fraud prevention | HTTP cookie | 12 months |
__stripe_sid |
Stripe (third party) | Payment session fraud prevention | HTTP cookie | 30 minutes |
3.2 Functional
Remember preferences and improve usability. Disabling these degrades convenience features but not core function.
| Cookie | Provider | Purpose | Type | Duration |
|---|---|---|---|---|
grt_theme |
GrantRT (first party) | Light or dark interface preference | Local storage | Until cleared |
grt_workspace |
GrantRT (first party) | Last active workspace | HTTP cookie | 90 days |
grt_locale |
GrantRT (first party) | Language and regional format | HTTP cookie | 12 months |
grt_ui_state |
GrantRT (first party) | Sidebar, table, and view preferences | Local storage | Until cleared |
grt_onboarding |
GrantRT (first party) | Tracks completion of onboarding steps | HTTP cookie | 12 months |
3.3 Analytics and Performance
Help us understand feature usage, diagnose errors, and improve reliability. Data is used in aggregate and pseudonymous form.
| Cookie | Provider | Purpose | Type | Duration |
|---|---|---|---|---|
ph_* |
PostHog (third party) | Product analytics, feature usage, funnels | HTTP cookie and local storage | 12 months |
sentry-* |
Sentry (third party) | Error and performance trace correlation | Session storage | Session |
grt_perf |
GrantRT (first party) | Page and interaction timing | Local storage | 30 days |
3.4 Marketing and Attribution
Measure the effectiveness of campaigns and content. GrantRT does not use cookies to build advertising profiles across unaffiliated sites and does not sell or share personal information for cross-context behavioral advertising.
| Cookie | Provider | Purpose | Type | Duration |
|---|---|---|---|---|
grt_utm |
GrantRT (first party) | Records campaign source for attribution | HTTP cookie | 90 days |
grt_referrer |
GrantRT (first party) | Records referring domain | HTTP cookie | 90 days |
_gcl_au |
Google (third party, if enabled) | Conversion measurement | HTTP cookie | 90 days |
li_fat_id |
LinkedIn (third party, if enabled) | Campaign conversion measurement | HTTP cookie | 30 days |
Third-party marketing tags are deployed only where enabled in a given region and only after consent where consent is required.
4. Third-Party Providers
| Provider | Role | Privacy Information |
|---|---|---|
| Cloudflare, Inc. | Security, bot mitigation, content delivery | cloudflare.com/privacypolicy |
| Supabase Inc. | Authentication and session tokens | supabase.com/privacy |
| Stripe, Inc. | Payment processing and fraud prevention | stripe.com/privacy |
| PostHog Inc. | Product analytics | posthog.com/privacy |
| Sentry (Functional Software, Inc.) | Error monitoring | sentry.io/privacy |
| Google LLC | Conversion measurement, where enabled | policies.google.com/privacy |
| LinkedIn Corporation | Conversion measurement, where enabled | linkedin.com/legal/privacy-policy |
GrantRT does not control third-party cookie practices. Review the provider's policy for details on its own processing.
5. Legal Basis and Regional Treatment
United States. Strictly necessary and functional cookies are used without consent. Analytics and marketing cookies are subject to opt-out rights under the Colorado Privacy Act, California Consumer Privacy Act, and comparable state laws.
European Economic Area, United Kingdom, and Switzerland. Non-essential cookies are set only after affirmative opt-in consent through the consent banner. Consent is recorded, may be withdrawn at any time, and is re-requested at least every twelve (12) months.
6. Managing Cookies
6.1 Consent Banner and Preference Center
A consent banner is presented on first visit where required. Preferences can be changed at any time through the "Cookie Preferences" link in the site footer or in account settings. Withdrawing consent stops future collection by the affected technologies. Cookies already set may be cleared through the browser.
6.2 Browser Controls
Most browsers allow blocking or deleting cookies through settings. Blocking strictly necessary cookies will prevent sign-in and may cause loss of unsaved work.
- Chrome: Settings, Privacy and security, Third-party cookies
- Safari: Settings, Privacy
- Firefox: Settings, Privacy and Security
- Edge: Settings, Cookies and site permissions
6.3 Global Privacy Control
GrantRT honors the Global Privacy Control signal and other recognized universal opt-out mechanisms. When a browser transmits such a signal, GrantRT treats it as an opt-out of sale and sharing and disables analytics and marketing cookies for that browser without further action by the user.
6.4 Do Not Track
There is no consistent industry standard for the legacy Do Not Track header. GrantRT does not respond to Do Not Track but does honor Global Privacy Control as described in Section 6.3.
6.5 Email Pixels
Marketing emails may contain pixels that record opens and clicks. Disabling automatic image loading in an email client prevents this. Every marketing email includes an unsubscribe link. Transactional, security, billing, and deadline notices do not contain marketing pixels and cannot be unsubscribed while an account is active.
7. Data Collected Through Cookies
Cookies may collect internet protocol address, device and browser characteristics, pages viewed, features used, referring URL, campaign parameters, session duration, interaction events, and error diagnostics. Retention follows the schedule in Section 7 of the Privacy Policy. Rights of access, deletion, and opt-out are described in Section 8 of the Privacy Policy and may be exercised by writing to info@grantrt.com with the subject line "Privacy Rights Request."
8. Changes to This Policy
We may update this Policy to reflect changes in technology, providers, or law. Material changes take effect thirty (30) days after notice by email to account administrators and by in-product notice. Non-material changes, including additions to the cookie tables, take effect on posting with an updated Effective Date and Version. Prior versions are available on request.
9. Contact
dakdan LLC d/b/a GrantRT Colorado, United States of America Email: info@grantrt.com Subject line for cookie and privacy questions: "Privacy Rights Request"