Cookies Policy

Last updated: 2026-05-24

This Cookies Policy explains what cookies and similar technologies Dealybee uses on dealybee.ai, what they do, and the choices you have over them.

It supplements (and does not replace) our Privacy Policy.

1. What cookies are

Cookies are small text files a website places on your device when you visit. They let the site remember things like whether you're signed in, your preferences, and whether you've completed a verification challenge. Most modern websites use them — Dealybee uses them sparingly.

We also use "similar technologies" — localStorage, sessionStorage, and HTTP-only auth cookies — to the same effect, and treat them under the same policy here.

2. The categories we use

Dealybee divides what we set into three categories. We don't currently use advertising or cross-site tracking cookies of any kind.

Strictly necessary (always on)

These cookies are required for the site to work. Disabling them will break sign-in, escrow, and anything that needs to know who you are.

  • Authentication session — set by our auth provider (Supabase) when you sign in via magic link. HTTP-only, secure, SameSite=Lax. Lets you stay signed in across pages.
  • CSRF token — protects server actions and form submissions against cross-site request forgery. Refreshed automatically.
  • Session identifier — a per-browser sessionStorage entry used to link an anonymous valuation lookup to a later signup, so we can show "you're #N on the waitlist" reliably. Does not persist across tabs or browser closes.

Functional (always on, no opt-out)

These cookies remember preferences you've chosen. They're not used for tracking and aren't shared.

  • Display preferences — when you change a setting (notification preference, voice profile, dashboard view), the choice is stored in your account database row rather than a cookie. We currently set no functional cookies on the client.

Analytics

  • None today. Dealybee does not currently use analytics cookies (Google Analytics, Meta Pixel, Hotjar, Mixpanel, PostHog, or any equivalent). If we add analytics in the future, this policy will be updated and — where required by law — we will ask for your consent before any analytics cookie is set.

Advertising

  • None, ever. Dealybee does not run advertising on dealybee.ai and does not allow third-party advertising trackers on our pages.

3. Third-party cookies set during specific interactions

Some Dealybee features rely on third-party services that may set their own cookies, but only at the point you use that specific feature:

  • Stripe — when you initiate a payment, Stripe's checkout flow may set cookies for fraud detection and session continuity. Stripe's cookie policy is at stripe.com/cookies-policy/legal.
  • Cloudflare Turnstile — our anti-bot challenge widget. If a challenge fires (most users never see one), Cloudflare may set short-lived cookies to remember you passed it. See cloudflare.com/cookie-policy.
  • Supabase — our authentication infrastructure provider sets the session cookie described above when you sign in.

We don't share data with these providers beyond what's needed for that specific function. We don't run ad-tech pixels, social-network share buttons, or any third-party tag that fires across the whole site.

4. Your choices

You can clear or block cookies at any time in your browser settings:

  • Chrome — Settings → Privacy and security → Third-party cookies
  • Firefox — Settings → Privacy & Security → Cookies and Site Data
  • Safari — Settings → Privacy → Manage Website Data
  • Edge — Settings → Cookies and site permissions → Manage and delete cookies and site data

Blocking strictly-necessary cookies will sign you out and may prevent escrow and dispute features from working. Blocking functional or analytics cookies has no effect today because we don't set any.

You can also use private browsing / incognito mode, which clears cookies automatically when you close the window.

5. Do Not Track and Global Privacy Control

Dealybee honors the Global Privacy Control (GPC) signal. If your browser sends a GPC header, we treat it as an opt-out from any future analytics or cross-site tracking — meaning even if we add analytics later, GPC-signaling browsers will be exempt by default.

The legacy "Do Not Track" header is no longer broadly supported by browsers and is not relied on; GPC has replaced it.

6. Updates to this policy

If we change which cookies we use — including adding analytics or any new third party — we will update this page, change the "Last updated" date, and (where required by law) request your consent before the new cookie is set.

7. Contact

Questions about cookies or any other privacy practice: write to [email protected]. We respond to every inquiry.