Back to home
Legal & Transparency

Cookie Policy

LAST UPDATED: AUGUST 13, 2026

1. About This Policy

This Cookie Policy explains how ShipReady (“we,” “us,” or “our”) uses cookies and similar storage technologies on our website and dashboard (the “Service”), and what choices you have. It supplements, and should be read with, our Privacy Policy and Terms of Service.

2. What Cookies Are

Cookies are small text files a website places on your device. They are used to make a site work, to keep you signed in, to remember preferences, and to understand how a product is used. In this Policy “cookies” also covers similar technologies — HTML5 localStorage, sessionStorage, IndexedDB, pixel tags, and service workers.

Cookies may be session cookies, deleted when you close the browser, or persistent, remaining until they expire or you delete them. They may be set by us (“first-party”) or by a provider we use (“third-party”).

3. Cookies We Use

Name / patternPurposeCategoryDuration
sb-*-auth-tokenSupabase authentication session. Stores your encrypted login session so you stay signed in across page loads.Strictly necessarySliding, up to 7 days
sb-*-auth-token.0, .1, …Chunked authentication cookies, used when the encrypted session token exceeds a single cookie’s size limit.Strictly necessarySliding, up to 7 days
CSRF / same-site protection cookiesHelps prevent another site from submitting requests on your behalf.Strictly necessarySession
localStorage / sessionStorageIn-browser storage for UI state such as dashboard layout, draft form input, and pending scan details, so the Service stays responsive.Strictly necessaryUntil you clear browser storage
_ga, _ga_*Google Analytics 4. Distinguishes browsers and sessions so we can see aggregate traffic and which pages are used. Loaded only on production builds.AnalyticsUp to 2 years
Vercel AnalyticsAggregate page-view and Web Vitals measurement. Operates without a persistent identifying cookie.AnalyticsNo persistent cookie

Exact cookie names can vary by environment. The full set issued during a session is always visible in your browser’s developer tools under Application → Storage.

4. Cookie Categories

4.1 Strictly necessary

These are required for the Service to work and cannot be switched off. They are set in response to actions that amount to a request for service — logging in, submitting a scan, saving project settings, navigating the dashboard. Without them you cannot sign in. Under Article 5(3) of the ePrivacy Directive and equivalent national law, they are exempt from consent requirements.

4.2 Analytics

We use Google Analytics 4 and Vercel Analytics to understand aggregate traffic and product usage — which pages people reach, where flows break, how the site performs. IP addresses are handled by those providers in accordance with their own documentation, and we do not use analytics data to build advertising profiles. Where consent is required in your jurisdiction, we will request it before analytics cookies are set.

4.3 Advertising — none

We do not serve advertising, run remarketing or retargeting, or use advertising cookies, conversion pixels, or interest-based advertising tags. We do not allow third-party advertising networks to collect data on our site.

4.4 Social media — none

We do not embed third-party social plug-ins such as “Like” or “Share” widgets that would set cookies on our domain. Our social links are plain outbound links.

5. Third-Party Cookies

When you enter our payment flow, our payment provider may set its own cookies on its own domain to process the payment and prevent fraud. Those cookies are controlled by that provider and governed by its privacy and cookie policies; we have no control over them.

Cookies set by infrastructure providers such as our hosting platform and our authentication provider appear as first-party cookies on our domain. They support availability, security, and sign-in, and are necessary for the Service.

6. Managing & Disabling Cookies

Because sign-in depends on strictly necessary cookies, disabling them will prevent you from using ShipReady. You can still manage cookies through your browser:

  • Chrome: Settings → Privacy and security → Third-party cookies / Site data
  • Firefox:Settings → Privacy & Security → Cookies and Site Data
  • Safari (macOS): Settings → Privacy → Manage Website Data
  • Safari (iOS): Settings → Apps → Safari → Block All Cookies
  • Edge: Settings → Cookies and site permissions → Cookies and site data
  • Brave / Opera / Arc:see the privacy section of the browser’s settings

You can also opt out of Google Analytics specifically using Google’s browser opt-out add-on. Blocking strictly necessary cookies will break sign-in, scan submission, and dashboard access.

7. Do Not Track & Global Privacy Control

Browsers may send a “Do Not Track” (DNT) or Global Privacy Control (GPC) signal. We do not engage in cross-context behavioral advertising and do not sell personal data, so these signals do not change the strictly necessary cookies we set. To the extent required by applicable law, we treat a GPC signal as a valid opt-out request for any processing that would be subject to opt-out under that law.

8. Consent

Strictly necessary cookies are exempt from consent under Article 5(3) of the ePrivacy Directive, so we do not ask for opt-in to those. Where analytics cookies require consent in your jurisdiction, we will request it through a consent mechanism before those cookies are set, and you will be able to withdraw consent at any time.

9. Changes to This Policy

We may update this Policy to reflect changes in technology, providers, or law. The current version is always at /cookieswith a “Last updated” date. For material changes, such as introducing a new category of cookie, we will give reasonable notice and, where required, request consent first.

10. Contact Us

If you have questions about our use of cookies or similar technologies, contact us at:

hello@useshipready.dev