dailybuilt
  • Platform
  • Pricing
  • Writing
  • Get early access
Get early access
Legal

Cookie Policy

A surface-by-surface list of what gets set in your browser, who sets it, and what it is for. It supplements the Privacy Policy and, for hosted booking, signing, and payment pages, the Consumer Privacy Notice.

Effective July 28, 2026

This Cookie Policy explains how DailyBuilt, Inc., a Delaware corporation ("DailyBuilt", "we", "us") and our service providers use cookies and similar technologies, what each one does, how long it lasts, and how you can control it.

It supplements our Privacy Policy and, for people using a booking, signing, or payment page hosted for a business, the Consumer Privacy Notice.


1. Scope, and who is responsible

This policy covers three different kinds of pages, and the answer to "who decides what runs here" is different for each.

Surface What it is Who decides what technologies run
dailybuilt.co Our marketing website DailyBuilt
app.dailybuilt.co The DailyBuilt application, used by our business customers ("Customers") DailyBuilt
Hosted End User pages — booking pages at {slug}.dailybuilt.co/book, document signing pages, invoice payment pages Pages we host on behalf of a business so its own customers ("End Users") can book, sign, or pay The business, using the settings we make available. DailyBuilt sets the defaults and acts on the business's instructions

On the hosted pages, the business you are dealing with — not DailyBuilt — decides whether optional measurement is enabled, and that business is the party responsible for the personal information you submit to it. DailyBuilt processes it on that business's behalf.

2. What these technologies are

Cookies are small text files a website asks your browser to store and send back on later requests. A first-party cookie is set by the site you are visiting; a third-party cookie is set by another domain. A session cookie is deleted when you close your browser; a persistent cookie has an expiry date.

We also use, and this policy also covers, similar technologies that are not technically cookies:

  • Browser storage (localStorage and sessionStorage) — key/value data your browser keeps for a site. It is not sent automatically with requests, and it does not expire on its own; it stays until it is cleared. We use it to remember your cookie choice and for some product state.
  • Server-side counting without an identifier — our analytics on hosted pages count visits by computing a hash on our server from the request, using a salt that rotates daily. Nothing is written to your browser to do it, and yesterday's hash cannot be matched to today's.
  • Software development kits and scripts loaded from a provider (for example the payment form or the bot check), which may set their own cookies or storage under their own domain.

We refer to all of these together as "cookies" below.

3. Categories we use

Category What it means Can you turn it off?
Strictly necessary Required to deliver a page or a feature you asked for: signing in, keeping you signed in, remembering which workspace you are in, protecting a form from abuse, processing a payment, and remembering your cookie choice No. Blocking these breaks sign-in, booking submission, or payment
Functional / preferences Remembers a choice you made so you do not have to make it again Yes, though the feature may forget your preference
Analytics / performance Helps us and our business customers understand how pages are used, in aggregate Yes — see Section 8
Security / anti-fraud Distinguishes automated traffic from people and helps our payment processor detect fraud Largely no; these are part of the security of the transaction

We do not run advertising, retargeting, or cross-site tracking cookies on any of these properties, and we do not sell personal information or share it for cross-context behavioral advertising. If that ever changes, this policy and our consent controls will change first.

4. dailybuilt.co (our marketing website)

Name Provider Category Purpose Duration
dailybuilt:consent DailyBuilt (first party) Strictly necessary Stores your accept/reject choice for analytics so we do not ask again. Stored in localStorage, not as a cookie Until you clear your browser storage for this site
_ga Google (Google Analytics 4) Analytics Distinguishes one browser from another so visits can be counted About 2 years (set by Google)
_ga_<measurement-id> Google (Google Analytics 4) Analytics Maintains analytics session state for our specific property About 2 years (set by Google)
Metricool tracker cookies Metricool (tracker.metricool.com) Analytics Recognizes repeat visits and attributes traffic to marketing campaigns. Cookie names and durations are set by Metricool and may change; see Metricool's privacy policy Set by Metricool
__cf_bm Cloudflare Security Distinguishes automated traffic from people, where Cloudflare's bot-management protections are applied to a request Up to 30 minutes
_cfuvid Cloudflare Strictly necessary Supports Cloudflare rate limiting; contains no information that identifies you Session

Google Analytics is configured with consent mode. Before any measurement runs, analytics_storage, ad_storage, ad_user_data, and ad_personalization are all set to denied; only analytics_storage is ever granted, and only after your choice (see Section 8). If you reject, _ga cookies are not written and the Metricool tracker is not loaded. IP anonymization is enabled on our Google Analytics property.

We do not use Google Analytics Advertising Features, Google Signals, or remarketing audiences.

5. app.dailybuilt.co (the application)

You need an account to reach these pages. Everything here is strictly necessary or security, except where noted.

Name Provider Category Purpose Duration
wos-session WorkOS (our authentication provider), set as a first-party cookie Strictly necessary Your encrypted sign-in session. Without it you cannot stay signed in Up to 12 hours
wos-oauth-state WorkOS / DailyBuilt Strictly necessary Protects the sign-in redirect against cross-site request forgery Minutes; deleted when sign-in completes
wos-oauth-return DailyBuilt Strictly necessary Remembers the page you were trying to reach so you land there after signing in Minutes; deleted when sign-in completes
wos-pending-verification DailyBuilt Strictly necessary Carries state through email verification during sign-up Short-lived; deleted when verification completes
wos-last-method DailyBuilt Functional Remembers whether you last signed in with email or with Google, so the sign-in screen can offer it first. HTTP-only 1 year
active_workspace_id DailyBuilt Strictly necessary Remembers which workspace you were last working in. HTTP-only and Secure 30 days
__stripe_mid Stripe Security / anti-fraud Fraud prevention on pages where a payment or payment setup is possible 1 year
__stripe_sid Stripe Security / anti-fraud Fraud prevention within a single payment session 30 minutes
Error-monitoring and session-replay storage Sentry Analytics / performance Diagnoses application errors. Where session replay of the signed-in application interface is enabled, a session identifier is kept in browser storage. Session replay never runs for Healthcare Edition workspaces, and session replay is never loaded on the public booking, signing, or payment pages. Error monitoring itself does run on those public pages — see Section 6 Session

Stripe cookies appear on the application's payments and billing surfaces, and on any page where Stripe's components are loaded. Stripe's cookie use is described in Stripe's cookie policy.

6. Hosted booking, signing, and payment pages

These are the pages a business publishes to its own customers. We deliberately keep them light.

Name / technology Provider Category Purpose Duration
DailyBuilt analytics (Umami, self-hosted at analytics.dailybuilt.co) DailyBuilt (first party) Analytics Counts page views and visits for the business whose page you are on. Cookieless by design — no cookie is set and no advertising identifier is created. Visits are counted from a hash computed on our server using a salt that rotates every day, so a visitor cannot be recognized across days No cookie set
Session replay and heatmap recording (Umami recorder) DailyBuilt (first party) Analytics Only if the business turns it on for its page. Records on-page interaction — pointer movement, clicks, scrolling, and page changes — so the business can see how its page is used. Not enabled by default, and never loaded on a Healthcare Edition page Session; recordings are retained in our analytics engine and deleted per our retention schedule (see the Privacy Policy)
Error and performance monitoring Sentry Analytics / performance Diagnoses failures and slow responses on the hosted page. Sends the page address, browser and device information, and error detail. No session replay is loaded here. No cookie is set Session
Cloudflare Turnstile (challenges.cloudflare.com) Cloudflare Security Confirms a booking or inquiry submission comes from a person, not an automated script. Turnstile is designed not to use cookies to track people across sites; where Cloudflare's challenge platform issues a managed challenge for the domain, it may set cf_clearance to remember that the challenge was passed Set by Cloudflare
__stripe_mid / __stripe_sid Stripe Security / anti-fraud Fraud prevention on the invoice payment page 1 year / 30 minutes

No advertising or cross-site tracking technology runs on these pages, and the analytics data is scoped to the business whose page you visited.

Healthcare Edition pages. Where a business has enabled our Healthcare Edition, analytics on its public pages are off by default. If analytics are enabled for such a page at all, only a privacy-hardened profile is available: the Do Not Track browser signal is honored, query strings and URL fragments are excluded, and the page address is reduced to its first path segment before anything leaves your browser. Session replay and heatmaps are never loaded on those pages.

7. Emails

Our emails do not contain tracking pixels or link wrapping, and we do not measure whether a message was opened or a link was clicked. No cookie is involved in sending or receiving an email from us.

Marketing emails sent through DailyBuilt are required to carry an unsubscribe link and the sender's postal address; the business sending the message is responsible for including them (see the Acceptable Use Policy §3.2).

8. Your choices

The consent banner (dailybuilt.co). When you first visit our marketing website, we decide whether to ask you or to apply a default, as follows:

  • We look for a choice you have already made. A stored choice always wins.
  • If you have not chosen, and your browser is sending a Global Privacy Control signal, we treat that as an opt-out and analytics do not load.
  • If you have not chosen and there is no GPC signal, we look at whether you appear to be somewhere that requires opt-in consent for analytics — the EU/EEA, the UK, or Switzerland. We infer this from your browser's time zone setting. We do not look up your IP address or call any third party to do it, which means the inference is approximate: a traveler or a browser configured to a different time zone may be prompted, or not prompted, incorrectly. If you are prompted, nothing analytics-related loads until you choose.
  • Everywhere else, analytics are on by default and you can opt out at any time using the controls below.

Why we show that banner at all. National rules implementing Article 5(3) of the EU ePrivacy Directive can apply to storing or reading anything on a device located in those countries, whether or not the operator is established there. We show the banner for that reason. It describes how the banner behaves; it is not a grant of rights under the GDPR or UK GDPR, and it does not change the position in Section 12 of our Privacy Policy.

Your choice is stored in your browser's localStorage under dailybuilt:consent. It is per-browser and per-device, so a choice on your laptop does not carry to your phone.

Global Privacy Control. We honor the GPC signal as an opt-out of analytics. Today, GPC applies where you have not already recorded a choice; a stored "accept" is not currently overridden by a later GPC signal. We are changing this so that a GPC signal takes precedence over a previously stored acceptance. Until that ships, if you have previously accepted and now want GPC honored, clear this site's storage in your browser (which removes the stored choice) and GPC will apply on your next visit.

Changing or withdrawing your choice. There is currently no in-page "cookie settings" link to reopen the banner. To change your choice today, clear this site's data or its localStorage in your browser settings; the banner will reappear (or the default will re-apply) on your next visit. A persistent "Cookie settings" control that reopens the banner is on our roadmap and will be added to the site footer.

Browser controls. Every major browser lets you block or delete cookies, block third-party cookies, and clear site storage, generally under Settings → Privacy. Blocking strictly necessary cookies on app.dailybuilt.co will prevent you from signing in; blocking them on a payment page may prevent payment.

Google Analytics opt-out. You can install Google's Analytics Opt-out Browser Add-on to stop your activity being measured on any site that uses Google Analytics.

Do Not Track. Browsers send a "Do Not Track" signal inconsistently and there is no agreed standard for responding to it, so our marketing website does not respond to DNT. Our hosted-page analytics do honor DNT when a page is running the privacy-hardened profile described in Section 6. We do honor GPC, which is a legally recognized opt-out signal, as described above.

Rights over your personal information. Your access, deletion, correction, and opt-out rights, and how to exercise them, are described in the Privacy Policy and, for End Users of a business's hosted pages, in the Consumer Privacy Notice.

9. Changes to this policy

We will update this policy when we add, remove, or change a technology it describes, and we will change the effective date at the top. Where a change would broaden how your information is used, we will seek your consent or provide a new opportunity to opt out before the change takes effect. Prior versions of this document are archived by date and are available on request to hello@dailybuilt.co.

10. Contact

Questions about this policy, or about a cookie you saw that is not listed here:

DailyBuilt, Inc. c/o Corporation Service Company, 251 Little Falls Drive, Wilmington, DE 19808 hello@dailybuilt.co

Related pages: Privacy Policy · Consumer Privacy Notice · Terms of Service · Security · Subprocessors

dailybuilt

The thinking layer for your whole business. Customers, bookings, payments, messaging, and your website in one login, one bill. In early access from Miami.

Platform
FeaturesHow it worksPricing
Company
Why we’re building itWritingFAQ
Contact
Get early accesshello@dailybuilt.coLinkedIn
Legal
TermsPrivacyEnd-User TermsConsumer Privacy NoticeDPAAcceptable UseSMS TermsBilling & RefundsCopyright & DMCASecurityAccessibilityCookiesLegal ProcessMeta Data DeletionSubprocessors
Consumer Health Data Privacy
dailybuilt
© 2026 DailyBuilt, Inc. All rights reserved.