Current Status
How We Use Cookies
Essential Cookies: Minimal Use
We use minimal essential cookies for authentication and session management. We also use browser localStorage for consent preferences.
| Cookie/Storage | Purpose | Duration |
|---|---|---|
| cleanrev_session | Authentication session (JWT) | Session |
| cookie-consent | Your cookie choice (localStorage) | Until cleared |
| cookie-consent-date | When you made your choice (localStorage) | Until cleared |
| cr_wl_popup | Waitlist-popup dismiss/join state, so we don't re-prompt you (localStorage) | Until cleared |
| cr_wl_shown | Whether the waitlist popup already displayed this browser session (sessionStorage) | Session |
Third-Party Cookies (Stripe - Requires Consent)
Only loaded after you explicitly consent. These cookies are set by Stripe when you use checkout or payment features.
| Cookie Name | Provider | Purpose | Duration |
|---|---|---|---|
| __stripe_* | Stripe | Payment processing, fraud detection | Session + 1 year |
| checkout-* | Stripe | Checkout session state | Session only |
Consent Required: These cookies are only set AFTER you consent. Rejecting may limit checkout functionality. Stripe Privacy Policy →
Analytics & Experimentation (opt-out available)
Non-essential. cleanrev.io runs first-party, cookieless analytics that we built and operate ourselves — no third-party vendor, no cookie, no cross-site tracking, no IP address or raw browser identifier stored. It records anonymous page-view and interaction events (retained 90 days) and, on our homepage only, a randomly assigned headline-variant identifier used to compare two versions of the main headline at the top of the page. None of this is required for the site to function; you can opt out at any time below.
| Storage Key | Storage | Purpose | Duration |
|---|---|---|---|
| cr_hv2 | localStorage | Sticky headline-variant assignment (which version of the headline at the top of our homepage you see) | 180 days |
| cr_hv2_e | sessionStorage | Deduplicates the "variant seen" event so it counts once per tab, not once per scroll | Tab session (cleared when the tab closes) |
| cr_hv, cr_hv_e | localStorage, sessionStorage | Retired. These were the same two identifiers under their previous names, used while the experiment ran on our closing headline. We now delete them on every page load — you do not need to do anything. | Deleted automatically |
| cr_cv_c | sessionStorage | Deduplicates the "clicked a call-to-action" event so it counts once per tab, not once per click | Tab session (cleared when the tab closes) |
| cr_cv_w | sessionStorage | Deduplicates the "joined the waitlist" event so it counts once per tab, not once per submission | Tab session (cleared when the tab closes) |
| cr_no_track | localStorage | Records that you opted out of this analytics (see below) | Until you clear it |
Reject Cookies opts you out. Clicking Reject Cookies below (or in the cookie banner) stops both the headline-variant assignment and every analytics beacon — no storage is written and no event is sent.
Cloudflare Web Analytics — cookieless, no stored identifier
Non-essential. This site, our web app (app.cleanrev.io) and our customer portal (portal.cleanrev.io) also load Cloudflare Web Analytics, a cookieless measurement product operated by Cloudflare, Inc. — already our CDN, hosting and security provider. It has no row in the table above because it sets no cookie and writes nothing to your browser's storage. It reports the page address, the referring page, coarse browser / device / country information and page-performance timings, aggregated into counts. It cannot follow you to other websites.
Two limits we impose on top of the product's own design:
- Reject stops it entirely. Clicking Reject Cookies below means the measurement script is never fetched — not merely that its data is discarded.
- We never report a URL that can carry a credential. The beacon is not loaded on password-reset, e-mail-verification, sign-up, invitation-acceptance or single-sign-on return pages, because those addresses can contain a sign-in link, invitation code or verification token.
Enablement is per surface: where the measurement token is not configured, no beacon is loaded at all.
Privacy-First Approach
- No Google Analytics or tracking cookies
- No Advertising or marketing cookies
- No Social media tracking pixels
- No Cross-site tracking or behavioral profiling
- Yes Minimal cookies (only essential + Stripe)
- Yes Explicit consent required before third-party cookies
- Yes Cloudflare Web Analytics is cookieless, consent-gated, and never loaded on pages whose address can carry a credential
- Yes Easy opt-out (reject button always available)
Update Your Preferences
You can change your cookie preferences at any time. Note that rejecting cookies may limit your ability to use certain features, particularly checkout and payment functionality.