01
How these technologies work
RipHQ uses cookies, local storage, session storage, and similar technologies to provide the service, protect accounts, remember your choices, understand product usage, and measure advertising.
Essential technologies operate when needed to provide features you request. Product analytics and advertising measurement are on by default and can be turned off at any time; an enabled Global Privacy Control signal turns both off automatically. You can change your choices at any time in Your Privacy Choices. RipHQ does not display a first-visit cookie banner on its supported United States storefront.
02
Essential technologies
sb-{project}-auth-token and cookie chunks- Provider
- Supabase
- Purpose
- Maintains a secure signed-in session and refreshes authentication.
- Duration
- Up to 400 days, or until the session expires or you sign out.
{storage-key}-code-verifier- Provider
- Supabase
- Purpose
- Completes secure PKCE authentication and provider sign-in flows.
- Duration
- Limited to the authentication flow.
riprush:presentation:v2:{presentation}:{pack}- Provider
- RipHQ
- Purpose
- Resumes an interrupted pack reveal at the correct position.
- Duration
- Until the reveal is completed, reset, or browser storage is cleared.
riprush:checkout:{product}:attempt-key- Provider
- RipHQ
- Purpose
- Prevents duplicate checkout attempts when a payment is retried.
- Duration
- For the current browser tab; removed after successful checkout.
Stripe-managed cookies and browser storage- Provider
- Stripe
- Purpose
- Supports payment processing, fraud prevention, and payment authentication when checkout or saved payment features are used.
- Duration
- Varies by Stripe technology; session-based and persistent identifiers may be used.
hCaptcha-managed cookies and browser storage- Provider
- hCaptcha
- Purpose
- Supports bot detection and authentication challenges when the login security check is used.
- Duration
- Varies by hCaptcha technology and the security session.
rhq_vid- Provider
- RipHQ
- Purpose
- Assigns this browser consistently to experiments. When analytics is enabled, it also links browser and server events before sign-in.
- Duration
- Up to 365 days; rotated on sign-out or account switching.
rhq_vid_sig- Provider
- RipHQ
- Purpose
- Authenticates the browser visitor identifier so another visitor's analytics history cannot be linked during sign-in.
- Duration
- Up to 365 days; replaced when the visitor identifier rotates.
rhq_authenticated- Provider
- RipHQ
- Purpose
- Records that this browser completed authentication so a later account switch can rotate its visitor identifier safely.
- Duration
- Up to 365 days; cleared on sign-out or account switching.
rhq_skip_pre_auth_alias- Provider
- RipHQ
- Purpose
- Prevents analytics history from a previous account being linked during an account switch.
- Duration
- Up to 10 minutes; cleared when the next sign-in starts.
03
Preference storage
riprush_analytics_consent- Provider
- RipHQ
- Purpose
- Remembers whether product analytics was accepted or declined.
- Duration
- 365 days.
riprush_advertising_consent- Provider
- RipHQ
- Purpose
- Remembers whether advertising measurement was accepted or declined.
- Duration
- 365 days.
riprush-analytics-consent- Provider
- RipHQ
- Purpose
- Keeps the browser copy of your product analytics choice.
- Duration
- Until browser storage is cleared.
riprush-pending-tracking-preferences- Provider
- RipHQ
- Purpose
- Temporarily queues a preference while account synchronization is unavailable.
- Duration
- Until synchronization succeeds or browser storage is cleared.
04
Optional product analytics
RipHQ loads PostHog for necessary error monitoring. Unless you opt out of product analytics, PostHog also records selected page and product events with interaction autocapture disabled and, for a signed-in user, may associate them with an account ID, email address, and display name. An enabled Global Privacy Control signal turns product analytics off automatically. When analytics is off, browser error monitoring uses memory-only state and does not persist a PostHog identifier.
ph_{project-key}_posthog- Provider
- PostHog
- Purpose
- Maintains the analytics identity, session, and related analytics state.
- Duration
- Managed by PostHog until consent is withdrawn or browser storage is cleared.
riprush-analytics-user-id- Provider
- RipHQ
- Purpose
- Keeps the signed-in analytics identity synchronized in this browser.
- Duration
- Until sign-out, consent withdrawal, identity reset, or browser storage is cleared.
05
Optional advertising measurement
Unless you opt out of advertising measurement, RipHQ may load Meta Pixel, the Google Ads tag, TikTok Pixel, and Reddit Pixel and preserve campaign information. For a signed-in user, these providers may also receive a hashed (SHA-256) version of the account email address to improve conversion matching; the plain address is never shared. RipHQ treats an enabled Global Privacy Control signal as an advertising opt-out.
riprush_campaign_attribution- Provider
- RipHQ
- Purpose
- Stores the landing page and campaign parameters used to attribute a completed purchase.
- Duration
- 90 days.
riprush_provider_attribution- Provider
- RipHQ
- Purpose
- Stores the latest consented Meta, Google Ads, TikTok, and Reddit click identifiers for purchase attribution.
- Duration
- 90 days.
_fbc- Provider
- RipHQ and Meta
- Purpose
- Stores a Meta click identifier used for advertising attribution.
- Duration
- 90 days when set by RipHQ.
_fbp- Provider
- Meta
- Purpose
- Stores a browser identifier used for Meta advertising measurement.
- Duration
- Provider-managed, typically up to 90 days.
_gcl_*- Provider
- Google
- Purpose
- Stores advertising click and conversion-linking identifiers used for Google Ads measurement and remarketing.
- Duration
- Provider-managed; duration varies by identifier.
_ttp, ttcsid*, ttclid, and _tt_enable_cookie- Provider
- TikTok
- Purpose
- Stores browser, session, and click identifiers used for TikTok advertising measurement.
- Duration
- Provider-managed, typically up to 13 months.
_rdt_uuid, _rdt_cid, and _rdt_em- Provider
- Reddit
- Purpose
- Stores browser and click identifiers used for Reddit advertising measurement.
- Duration
- Provider-managed, typically up to 90 days.
06
Your controls
Use the tracking preference settings to allow or disable optional categories. Withdrawing consent stops future optional tracking and clears RipHQ-managed advertising attribution storage where supported.
You can also delete cookies and site data through your browser. Doing so may sign you out, reset your preferences, or prevent an interrupted checkout or reveal from resuming. Browser settings cannot always remove information already received by a third-party provider.