Cookie Policy
Last updated July 12, 2026
This Cookie Policy explains how Ready for Commerce, Inc. ("Ready for Commerce," "we," "us," or "our") uses cookies and similar technologies on our websites and applications, including our authentication service, our account and billing service, the PIM product, and the Repricer product (together, the "Services"). It supplements our Privacy Policy, which explains how we handle personal information more generally.
What cookies and similar technologies are
Cookies are small text files placed on your device when you visit a website. Similar technologies include local storage, session storage, software development kits, pixels, and device identifiers. We refer to all of these as "cookies" in this policy. Cookies may be set by us ("first-party") or by a third-party provider acting on our behalf ("third-party"), and they may last only for your browsing session ("session cookies") or for a set period ("persistent cookies").
How we use cookies
We use cookies to keep you signed in, to remember your preferences, to keep the Services secure, and to understand and improve how the Services are used. We do not use cookies for cross-context behavioral advertising or to build advertising profiles about you. We group them into the following categories.
Strictly necessary. These are required to operate the Services and cannot be switched off through our systems. They include authentication and session cookies that keep you signed in across our applications, and security and bot-mitigation cookies that help protect against fraud and automated abuse.
- sb-tfc-auth — our authentication session cookie, which keeps you signed in across our applications. First-party, scoped to .readyforcommerce.com, HTTP-only, up to ~12 months.
- Bot-mitigation cookies (such as __cf_bm, set by Cloudflare on our login service) — used to distinguish humans from automated traffic. Third-party, short-lived (typically around 30 minutes).
- Sign-in cookies (such as g_state, set by Google when you choose Google sign-in) — used to complete and secure the sign-in flow. Third-party, session-based.
- Payment-security cookies (such as __stripe_mid and __stripe_sid, set by Stripe on our billing pages) — used for fraud prevention during checkout and payment-method setup. Third-party; __stripe_sid is short-lived, __stripe_mid lasts up to ~12 months.
- tfc-consent — remembers the choices you make in our marketing website's cookie-consent banner, so we can honor them and avoid asking again. First-party, stored in your browser's local storage, up to ~12 months.
- tfc-cc-regime — records which privacy regime applies to you (derived from the country of your connection), so our marketing website knows whether it must ask for your consent before any analytics. It stores only this setting, not your location. First-party, readable by your browser, up to ~1 day.
Functional and preferences. These remember choices you make so the Services work the way you expect. Turning them off may affect how the Services function.
- NEXT_LOCALE — remembers your language preference (for example, English or Spanish). First-party, readable by your browser, up to ~12 months.
- tfc_active_org — remembers the organization (workspace) you are currently using, so you stay in the right account across our applications. First-party, readable by your browser, up to ~12 months.
- Interface preferences stored in your browser's local storage — remember non-sensitive interface settings such as data-table column widths, density, and saved views. First-party, stored until you clear them; they do not contain your catalog or account data.
Analytics and product measurement. These help us understand how the Services are used so we can fix problems and improve them. We use the product-analytics provider PostHog for product analytics, error tracking, and limited session replay.
- PostHog cookies (such as cookies beginning with ph_) — assign an analytics identifier and measure usage across our applications. We serve PostHog through a same-origin path (/ph) on our own domain. First-party in appearance, scoped to .readyforcommerce.com, up to ~12 months.
Where required by law (including in the EEA and the UK), we set analytics cookies and enable session replay only after you consent (see Your choices and consent).
Session replay
Session replay reconstructs how visitors interact with the interface so we can diagnose problems and improve usability. Our session replay is privacy-protective by design: it captures only structural interactions (such as navigation and clicks), and input fields and on-screen text are masked, so the contents you type and view — such as login codes, billing details, and catalog data — are not recorded. Session replay is disabled entirely on our login service. Where consent is required, session replay runs only after you consent.
Third-party services that may set cookies
Some cookies are set by trusted providers that help us deliver the Services, including PostHog (analytics and error tracking), Cloudflare (bot mitigation and security), Google (sign-in), and Stripe (payments). When the Services are used embedded inside a sales channel — for example, inside the Shopify admin — that channel may also set its own cookies governed by its own policies. These providers process information under their own privacy and cookie notices, and our use of them is described in our Privacy Policy.
Our marketing website
How our public marketing website handles analytics depends on the privacy rules of the country you connect from, and no analytics cookie or session replay is ever set on your device without your explicit consent, anywhere.
Where the law requires prior consent (such as in the EEA, the United Kingdom, and certain other jurisdictions, and by default whenever we cannot determine your location), we show a consent banner and run nothing — no analytics events, no storage — until you decide. If you accept, the PostHog cookies described above are set and session replay (masked as described above) may run; if you reject, we save only your choice itself (see tfc-consent above) and count your visit without any identifier in your browser, using a short-lived pseudonymous identifier computed on PostHog's servers.
Where prior consent is not required, we do not show a banner; by default we measure your visit in that same privacy-preserving way (no cookie stored on your device, no session replay), and you can turn on full analytics, or turn measurement off entirely, at any time via "Cookie preferences" in the website footer. We honor the Global Privacy Control signal as a rejection everywhere; while it is present, we run no analytics at all.
Your choices and consent
Consent banner. Where required by law, we ask for your consent to non-essential cookies (such as analytics and session replay) through our cookie-consent banner before they are set, and you can withdraw or change your choices at any time using the banner. Strictly necessary cookies do not require consent.
Browser controls. Most browsers let you block or delete cookies through their settings. If you block strictly necessary cookies, parts of the Services may not function, including signing in.
Preference signals. Where required by applicable law, we honor recognized opt-out preference signals, such as the Global Privacy Control, as a request to opt out of applicable processing.
Provider opt-outs. Some third-party providers offer their own controls; please refer to their notices for details.
Changes to this policy
We may update this Cookie Policy from time to time as the technologies we use change. If we make material changes, we will update the "Effective" date above and, where appropriate, provide additional notice. As the specific cookies in use may change over time, the examples above are representative rather than exhaustive.