Grant RTGrant RT
Privacy PolicyTerms of ServiceCookie PolicyAccessibility

GrantRT Cookie Policy

Effective Date: September 1, 2026 Version: 1.0 Operator: dakdan LLC, a Colorado limited liability company, doing business as GrantRT Contact: info@grantrt.com Jurisdiction of operation: Colorado, United States of America


1. Scope

This Cookie Policy explains how GrantRT uses cookies and similar technologies on grantrt.com, its subdomains, and the GrantRT application (the "Service"). It supplements and is incorporated into the GrantRT Privacy Policy and Terms of Service.


2. What These Technologies Are

Cookies are small text files placed on a device by a website and returned to that website on later visits.

First-party cookies are set by grantrt.com. Third-party cookies are set by another domain, such as a payment or analytics provider.

Session cookies expire when the browser closes. Persistent cookies remain until they expire or are deleted.

Local storage and session storage are browser storage mechanisms used to hold application state, drafts, and preferences on the device.

Pixels and web beacons are small transparent files used to record whether a page or email was opened.

Software development kits and scripts are code embedded in the Service by us or a vendor to deliver a function such as error monitoring or support chat.

In this Policy, "cookies" refers to all of these technologies.


3. Cookie Categories

GrantRT groups cookies into four categories. Strictly necessary cookies are always active because the Service cannot function without them. The other three categories are subject to consent where required by law.

3.1 Strictly Necessary

Required for authentication, session integrity, security, load balancing, and preserving unsaved work. These cannot be disabled through our preference center.

Cookie Provider Purpose Type Duration
grt_session GrantRT (first party) Maintains the authenticated session HTTP cookie Session
sb-access-token Supabase (first party context) Authentication access token HTTP cookie 1 hour
sb-refresh-token Supabase (first party context) Renews the authenticated session HTTP cookie 30 days
grt_csrf GrantRT (first party) Cross-site request forgery protection HTTP cookie Session
grt_consent GrantRT (first party) Stores cookie preferences HTTP cookie 12 months
__cf_bm Cloudflare (third party) Bot management and abuse prevention HTTP cookie 30 minutes
__Host-next-auth.csrf-token GrantRT (first party) Sign-in flow integrity HTTP cookie Session
grt_draft_state GrantRT (first party) Local storage of unsaved application drafts Local storage Until cleared
__stripe_mid Stripe (third party) Payment fraud prevention HTTP cookie 12 months
__stripe_sid Stripe (third party) Payment session fraud prevention HTTP cookie 30 minutes

3.2 Functional

Remember preferences and improve usability. Disabling these degrades convenience features but not core function.

Cookie Provider Purpose Type Duration
grt_theme GrantRT (first party) Light or dark interface preference Local storage Until cleared
grt_workspace GrantRT (first party) Last active workspace HTTP cookie 90 days
grt_locale GrantRT (first party) Language and regional format HTTP cookie 12 months
grt_ui_state GrantRT (first party) Sidebar, table, and view preferences Local storage Until cleared
grt_onboarding GrantRT (first party) Tracks completion of onboarding steps HTTP cookie 12 months

3.3 Analytics and Performance

Help us understand feature usage, diagnose errors, and improve reliability. Data is used in aggregate and pseudonymous form.

Cookie Provider Purpose Type Duration
ph_* PostHog (third party) Product analytics, feature usage, funnels HTTP cookie and local storage 12 months
sentry-* Sentry (third party) Error and performance trace correlation Session storage Session
grt_perf GrantRT (first party) Page and interaction timing Local storage 30 days

3.4 Marketing and Attribution

Measure the effectiveness of campaigns and content. GrantRT does not use cookies to build advertising profiles across unaffiliated sites and does not sell or share personal information for cross-context behavioral advertising.

Cookie Provider Purpose Type Duration
grt_utm GrantRT (first party) Records campaign source for attribution HTTP cookie 90 days
grt_referrer GrantRT (first party) Records referring domain HTTP cookie 90 days
_gcl_au Google (third party, if enabled) Conversion measurement HTTP cookie 90 days
li_fat_id LinkedIn (third party, if enabled) Campaign conversion measurement HTTP cookie 30 days

Third-party marketing tags are deployed only where enabled in a given region and only after consent where consent is required.


4. Third-Party Providers

Provider Role Privacy Information
Cloudflare, Inc. Security, bot mitigation, content delivery cloudflare.com/privacypolicy
Supabase Inc. Authentication and session tokens supabase.com/privacy
Stripe, Inc. Payment processing and fraud prevention stripe.com/privacy
PostHog Inc. Product analytics posthog.com/privacy
Sentry (Functional Software, Inc.) Error monitoring sentry.io/privacy
Google LLC Conversion measurement, where enabled policies.google.com/privacy
LinkedIn Corporation Conversion measurement, where enabled linkedin.com/legal/privacy-policy

GrantRT does not control third-party cookie practices. Review the provider's policy for details on its own processing.


5. Legal Basis and Regional Treatment

United States. Strictly necessary and functional cookies are used without consent. Analytics and marketing cookies are subject to opt-out rights under the Colorado Privacy Act, California Consumer Privacy Act, and comparable state laws.

European Economic Area, United Kingdom, and Switzerland. Non-essential cookies are set only after affirmative opt-in consent through the consent banner. Consent is recorded, may be withdrawn at any time, and is re-requested at least every twelve (12) months.


6. Managing Cookies

6.1 Consent Banner and Preference Center

A consent banner is presented on first visit where required. Preferences can be changed at any time through the "Cookie Preferences" link in the site footer or in account settings. Withdrawing consent stops future collection by the affected technologies. Cookies already set may be cleared through the browser.

6.2 Browser Controls

Most browsers allow blocking or deleting cookies through settings. Blocking strictly necessary cookies will prevent sign-in and may cause loss of unsaved work.

  • Chrome: Settings, Privacy and security, Third-party cookies
  • Safari: Settings, Privacy
  • Firefox: Settings, Privacy and Security
  • Edge: Settings, Cookies and site permissions

6.3 Global Privacy Control

GrantRT honors the Global Privacy Control signal and other recognized universal opt-out mechanisms. When a browser transmits such a signal, GrantRT treats it as an opt-out of sale and sharing and disables analytics and marketing cookies for that browser without further action by the user.

6.4 Do Not Track

There is no consistent industry standard for the legacy Do Not Track header. GrantRT does not respond to Do Not Track but does honor Global Privacy Control as described in Section 6.3.

6.5 Email Pixels

Marketing emails may contain pixels that record opens and clicks. Disabling automatic image loading in an email client prevents this. Every marketing email includes an unsubscribe link. Transactional, security, billing, and deadline notices do not contain marketing pixels and cannot be unsubscribed while an account is active.


7. Data Collected Through Cookies

Cookies may collect internet protocol address, device and browser characteristics, pages viewed, features used, referring URL, campaign parameters, session duration, interaction events, and error diagnostics. Retention follows the schedule in Section 7 of the Privacy Policy. Rights of access, deletion, and opt-out are described in Section 8 of the Privacy Policy and may be exercised by writing to info@grantrt.com with the subject line "Privacy Rights Request."


8. Changes to This Policy

We may update this Policy to reflect changes in technology, providers, or law. Material changes take effect thirty (30) days after notice by email to account administrators and by in-product notice. Non-material changes, including additions to the cookie tables, take effect on posting with an updated Effective Date and Version. Prior versions are available on request.


9. Contact

dakdan LLC d/b/a GrantRT Colorado, United States of America Email: info@grantrt.com Subject line for cookie and privacy questions: "Privacy Rights Request"

Grant RTGrant RT

AI-powered grant management platform for nonprofits.

Product

FeaturesPricingHow It WorksHow We Use AI

Company

CareersInternshipsApply for InternshipGrant Readiness Checklist

Legal

Privacy PolicyTerms of ServiceCookie PolicyAccessibility

Get Started

Sign UpSign In

© 2026 Grant RT. All rights reserved. GrantRT.com