Cookies, in full.
We use the smallest possible number of cookies and local-storage keys. No third-party ad trackers, no cross-site identifiers, no session replay. Everything we store is first-party and scoped to tradefloor.co.
What we set
Essential cookies for authentication (an HttpOnly refresh token), security (CSRF protection), and your session. A handful of local-storage keys remember your preferences: language, layout, last-viewed coin, dismissed banners. Local-storage is not technically a cookie but is listed here for transparency; these keys never leave your browser.
What we do not use
- No Facebook Pixel, no advertising or retargeting tracker, no ad network.
- No session-replay tools (Hotjar, FullStory, LogRocket, and the like).
- No cross-site fingerprinting.
- No affiliate-network cookies.
The analytics we do use
Two things, and we would rather name them than describe them as nothing. Google Analytics 4 measures which pages get read. It runs under Consent Mode with storage denied by default, so the first paint of any page writes no analytics cookie and nothing is stored until you accept the banner; declining keeps the whole site usable. And a first-party pipeline on our own servers, keyed by an anonymous account id, records a short whitelist of product events (feature use, retention, referrals) so our own numbers do not depend on a third party. Neither is an advertising tracker and neither follows you to other sites.
How to disable
All standards-compliant browsers let you block cookies and clear local-storage from settings. For per-site control, use the browser lock icon in the address bar. Disabling essential cookies will sign you out and prevent login.
Changes
We revise this page whenever we change what we store. The "last revised" date at the top of the in-app version is authoritative.
// questions · [email protected]