Cookie Policy
A surface-by-surface list of what gets set in your browser, who sets it, and what it is for. It supplements the Privacy Policy and, for hosted booking, signing, and payment pages, the Consumer Privacy Notice.
This Cookie Policy explains how DailyBuilt, Inc., a Delaware corporation ("DailyBuilt", "we", "us") and our service providers use cookies and similar technologies, what each one does, how long it lasts, and how you can control it.
It supplements our Privacy Policy and, for people using a booking, signing, or payment page hosted for a business, the Consumer Privacy Notice.
1. Scope, and who is responsible
This policy covers three different kinds of pages, and the answer to "who decides what runs here" is different for each.
| Surface | What it is | Who decides what technologies run |
|---|---|---|
| dailybuilt.co | Our marketing website | DailyBuilt |
| app.dailybuilt.co | The DailyBuilt application, used by our business customers ("Customers") | DailyBuilt |
Hosted End User pages — booking pages at {slug}.dailybuilt.co/book, document signing pages, invoice payment pages |
Pages we host on behalf of a business so its own customers ("End Users") can book, sign, or pay | The business, using the settings we make available. DailyBuilt sets the defaults and acts on the business's instructions |
On the hosted pages, the business you are dealing with — not DailyBuilt — decides whether optional measurement is enabled, and that business is the party responsible for the personal information you submit to it. DailyBuilt processes it on that business's behalf.
2. What these technologies are
Cookies are small text files a website asks your browser to store and send back on later requests. A first-party cookie is set by the site you are visiting; a third-party cookie is set by another domain. A session cookie is deleted when you close your browser; a persistent cookie has an expiry date.
We also use, and this policy also covers, similar technologies that are not technically cookies:
- Browser storage (
localStorageandsessionStorage) — key/value data your browser keeps for a site. It is not sent automatically with requests, and it does not expire on its own; it stays until it is cleared. We use it to remember your cookie choice and for some product state. - Server-side counting without an identifier — our analytics on hosted pages count visits by computing a hash on our server from the request, using a salt that rotates daily. Nothing is written to your browser to do it, and yesterday's hash cannot be matched to today's.
- Software development kits and scripts loaded from a provider (for example the payment form or the bot check), which may set their own cookies or storage under their own domain.
We refer to all of these together as "cookies" below.
3. Categories we use
| Category | What it means | Can you turn it off? |
|---|---|---|
| Strictly necessary | Required to deliver a page or a feature you asked for: signing in, keeping you signed in, remembering which workspace you are in, protecting a form from abuse, processing a payment, and remembering your cookie choice | No. Blocking these breaks sign-in, booking submission, or payment |
| Functional / preferences | Remembers a choice you made so you do not have to make it again | Yes, though the feature may forget your preference |
| Analytics / performance | Helps us and our business customers understand how pages are used, in aggregate | Yes — see Section 8 |
| Security / anti-fraud | Distinguishes automated traffic from people and helps our payment processor detect fraud | Largely no; these are part of the security of the transaction |
We do not run advertising, retargeting, or cross-site tracking cookies on any of these properties, and we do not sell personal information or share it for cross-context behavioral advertising. If that ever changes, this policy and our consent controls will change first.
4. dailybuilt.co (our marketing website)
| Name | Provider | Category | Purpose | Duration |
|---|---|---|---|---|
dailybuilt:consent |
DailyBuilt (first party) | Strictly necessary | Stores your accept/reject choice for analytics so we do not ask again. Stored in localStorage, not as a cookie |
Until you clear your browser storage for this site |
_ga |
Google (Google Analytics 4) | Analytics | Distinguishes one browser from another so visits can be counted | About 2 years (set by Google) |
_ga_<measurement-id> |
Google (Google Analytics 4) | Analytics | Maintains analytics session state for our specific property | About 2 years (set by Google) |
| Metricool tracker cookies | Metricool (tracker.metricool.com) |
Analytics | Recognizes repeat visits and attributes traffic to marketing campaigns. Cookie names and durations are set by Metricool and may change; see Metricool's privacy policy | Set by Metricool |
__cf_bm |
Cloudflare | Security | Distinguishes automated traffic from people, where Cloudflare's bot-management protections are applied to a request | Up to 30 minutes |
_cfuvid |
Cloudflare | Strictly necessary | Supports Cloudflare rate limiting; contains no information that identifies you | Session |
Google Analytics is configured with consent mode. Before any measurement runs, analytics_storage, ad_storage, ad_user_data, and ad_personalization are all set to denied; only analytics_storage is ever granted, and only after your choice (see Section 8). If you reject, _ga cookies are not written and the Metricool tracker is not loaded. IP anonymization is enabled on our Google Analytics property.
We do not use Google Analytics Advertising Features, Google Signals, or remarketing audiences.
5. app.dailybuilt.co (the application)
You need an account to reach these pages. Everything here is strictly necessary or security, except where noted.
| Name | Provider | Category | Purpose | Duration |
|---|---|---|---|---|
wos-session |
WorkOS (our authentication provider), set as a first-party cookie | Strictly necessary | Your encrypted sign-in session. Without it you cannot stay signed in | Up to 12 hours |
wos-oauth-state |
WorkOS / DailyBuilt | Strictly necessary | Protects the sign-in redirect against cross-site request forgery | Minutes; deleted when sign-in completes |
wos-oauth-return |
DailyBuilt | Strictly necessary | Remembers the page you were trying to reach so you land there after signing in | Minutes; deleted when sign-in completes |
wos-pending-verification |
DailyBuilt | Strictly necessary | Carries state through email verification during sign-up | Short-lived; deleted when verification completes |
wos-last-method |
DailyBuilt | Functional | Remembers whether you last signed in with email or with Google, so the sign-in screen can offer it first. HTTP-only | 1 year |
active_workspace_id |
DailyBuilt | Strictly necessary | Remembers which workspace you were last working in. HTTP-only and Secure |
30 days |
__stripe_mid |
Stripe | Security / anti-fraud | Fraud prevention on pages where a payment or payment setup is possible | 1 year |
__stripe_sid |
Stripe | Security / anti-fraud | Fraud prevention within a single payment session | 30 minutes |
| Error-monitoring and session-replay storage | Sentry | Analytics / performance | Diagnoses application errors. Where session replay of the signed-in application interface is enabled, a session identifier is kept in browser storage. Session replay never runs for Healthcare Edition workspaces, and session replay is never loaded on the public booking, signing, or payment pages. Error monitoring itself does run on those public pages — see Section 6 | Session |
Stripe cookies appear on the application's payments and billing surfaces, and on any page where Stripe's components are loaded. Stripe's cookie use is described in Stripe's cookie policy.
6. Hosted booking, signing, and payment pages
These are the pages a business publishes to its own customers. We deliberately keep them light.
| Name / technology | Provider | Category | Purpose | Duration |
|---|---|---|---|---|
DailyBuilt analytics (Umami, self-hosted at analytics.dailybuilt.co) |
DailyBuilt (first party) | Analytics | Counts page views and visits for the business whose page you are on. Cookieless by design — no cookie is set and no advertising identifier is created. Visits are counted from a hash computed on our server using a salt that rotates every day, so a visitor cannot be recognized across days | No cookie set |
| Session replay and heatmap recording (Umami recorder) | DailyBuilt (first party) | Analytics | Only if the business turns it on for its page. Records on-page interaction — pointer movement, clicks, scrolling, and page changes — so the business can see how its page is used. Not enabled by default, and never loaded on a Healthcare Edition page | Session; recordings are retained in our analytics engine and deleted per our retention schedule (see the Privacy Policy) |
| Error and performance monitoring | Sentry | Analytics / performance | Diagnoses failures and slow responses on the hosted page. Sends the page address, browser and device information, and error detail. No session replay is loaded here. No cookie is set | Session |
Cloudflare Turnstile (challenges.cloudflare.com) |
Cloudflare | Security | Confirms a booking or inquiry submission comes from a person, not an automated script. Turnstile is designed not to use cookies to track people across sites; where Cloudflare's challenge platform issues a managed challenge for the domain, it may set cf_clearance to remember that the challenge was passed |
Set by Cloudflare |
__stripe_mid / __stripe_sid |
Stripe | Security / anti-fraud | Fraud prevention on the invoice payment page | 1 year / 30 minutes |
No advertising or cross-site tracking technology runs on these pages, and the analytics data is scoped to the business whose page you visited.
Healthcare Edition pages. Where a business has enabled our Healthcare Edition, analytics on its public pages are off by default. If analytics are enabled for such a page at all, only a privacy-hardened profile is available: the Do Not Track browser signal is honored, query strings and URL fragments are excluded, and the page address is reduced to its first path segment before anything leaves your browser. Session replay and heatmaps are never loaded on those pages.
7. Emails
Our emails do not contain tracking pixels or link wrapping, and we do not measure whether a message was opened or a link was clicked. No cookie is involved in sending or receiving an email from us.
Marketing emails sent through DailyBuilt are required to carry an unsubscribe link and the sender's postal address; the business sending the message is responsible for including them (see the Acceptable Use Policy §3.2).
8. Your choices
The consent banner (dailybuilt.co). When you first visit our marketing website, we decide whether to ask you or to apply a default, as follows:
- We look for a choice you have already made. A stored choice always wins.
- If you have not chosen, and your browser is sending a Global Privacy Control signal, we treat that as an opt-out and analytics do not load.
- If you have not chosen and there is no GPC signal, we look at whether you appear to be somewhere that requires opt-in consent for analytics — the EU/EEA, the UK, or Switzerland. We infer this from your browser's time zone setting. We do not look up your IP address or call any third party to do it, which means the inference is approximate: a traveler or a browser configured to a different time zone may be prompted, or not prompted, incorrectly. If you are prompted, nothing analytics-related loads until you choose.
- Everywhere else, analytics are on by default and you can opt out at any time using the controls below.
Why we show that banner at all. National rules implementing Article 5(3) of the EU ePrivacy Directive can apply to storing or reading anything on a device located in those countries, whether or not the operator is established there. We show the banner for that reason. It describes how the banner behaves; it is not a grant of rights under the GDPR or UK GDPR, and it does not change the position in Section 12 of our Privacy Policy.
Your choice is stored in your browser's localStorage under dailybuilt:consent. It is per-browser and per-device, so a choice on your laptop does not carry to your phone.
Global Privacy Control. We honor the GPC signal as an opt-out of analytics. Today, GPC applies where you have not already recorded a choice; a stored "accept" is not currently overridden by a later GPC signal. We are changing this so that a GPC signal takes precedence over a previously stored acceptance. Until that ships, if you have previously accepted and now want GPC honored, clear this site's storage in your browser (which removes the stored choice) and GPC will apply on your next visit.
Changing or withdrawing your choice. There is currently no in-page "cookie settings" link to reopen the banner. To change your choice today, clear this site's data or its localStorage in your browser settings; the banner will reappear (or the default will re-apply) on your next visit. A persistent "Cookie settings" control that reopens the banner is on our roadmap and will be added to the site footer.
Browser controls. Every major browser lets you block or delete cookies, block third-party cookies, and clear site storage, generally under Settings → Privacy. Blocking strictly necessary cookies on app.dailybuilt.co will prevent you from signing in; blocking them on a payment page may prevent payment.
Google Analytics opt-out. You can install Google's Analytics Opt-out Browser Add-on to stop your activity being measured on any site that uses Google Analytics.
Do Not Track. Browsers send a "Do Not Track" signal inconsistently and there is no agreed standard for responding to it, so our marketing website does not respond to DNT. Our hosted-page analytics do honor DNT when a page is running the privacy-hardened profile described in Section 6. We do honor GPC, which is a legally recognized opt-out signal, as described above.
Rights over your personal information. Your access, deletion, correction, and opt-out rights, and how to exercise them, are described in the Privacy Policy and, for End Users of a business's hosted pages, in the Consumer Privacy Notice.
9. Changes to this policy
We will update this policy when we add, remove, or change a technology it describes, and we will change the effective date at the top. Where a change would broaden how your information is used, we will seek your consent or provide a new opportunity to opt out before the change takes effect. Prior versions of this document are archived by date and are available on request to hello@dailybuilt.co.
10. Contact
Questions about this policy, or about a cookie you saw that is not listed here:
DailyBuilt, Inc. c/o Corporation Service Company, 251 Little Falls Drive, Wilmington, DE 19808 hello@dailybuilt.co
Related pages: Privacy Policy · Consumer Privacy Notice · Terms of Service · Security · Subprocessors