Cookie Policy
BranStory — a product of Brandmerce, LLC
Effective Date: April 2026 Last Updated: April 2026
This Cookie Policy explains how BranStory (a product of Brandmerce, LLC) uses cookies and similar technologies on branstory.com and on web applications powered by the BranStory platform.
1. What Are Cookies?
Cookies are small text files stored on your device when you visit a website. Similar technologies include browser localStorage, sessionStorage, and device tokens used in mobile applications. Throughout this policy, we use “cookies” to refer to all of these technologies collectively.
2. What We Use and Why
We group our use of cookies into four categories:
Category 1: Strictly Necessary
These are required for the Platform to function. They cannot be disabled without breaking core functionality such as staying logged in.
| Technology | Purpose | Stored Where | Expiry |
|---|---|---|---|
| Supabase auth token | Authenticates your session and keeps you logged in across browser sessions; used to authorize all API requests | Browser localStorage | Session / configurable TTL based on account settings |
| CSRF tokens | Protects form submissions against cross-site request forgery attacks | Session memory | Per session |
| Tenant context | Identifies which community network you are accessing so the correct branded experience is loaded | Browser localStorage | Session |
Category 2: Functional
These enhance your experience and remember preferences so you don’t have to reset them each visit.
| Technology | Purpose | Stored Where | Expiry |
|---|---|---|---|
| UI preferences | Stores settings such as notification preferences and display options you have configured | Browser localStorage | Persistent |
| Onboarding state | Tracks onboarding step completion to avoid showing completed steps again on return visits | Browser localStorage | Persistent |
Category 3: Analytics
We may collect anonymized, aggregated usage data to understand how the Platform is used and to improve it. No personally identifiable information is transmitted to analytics systems.
| Technology | Purpose | Stored Where | Expiry |
|---|---|---|---|
| Anonymized session analytics | Aggregate page views, feature usage frequency, and performance metrics; no personal identifiers are included | Server-side | 90 days |
What We Do Not Use
- Third-party advertising cookies or pixels
- Ad network tracking cookies
- Social media platform tracking cookies
- Cross-site behavioral profiling technologies
- Retargeting or remarketing cookies of any kind
3. Push Notification Tokens
Push notification tokens are separate from browser cookies. If you opt into push notifications, your device generates a unique push token. This token is stored server-side in our database (not in your browser) and is associated with your account solely to enable notification delivery.
You can revoke push notification permissions at any time:
- Via your device’s system settings (iOS: Settings → Notifications → [App Name])
- Within the app’s notification preferences settings
4. Third-Party Service Cookies
Some third-party services integrated with the Platform may independently set cookies or use similar technologies:
- Stripe may set session-scoped cookies during the payment checkout flow to support secure transaction processing
- Supabase manages authentication session tokens; the session token is stored in your browser’s localStorage as described above
We do not permit third-party advertising vendors, analytics aggregators, or data brokers to set cookies through our Platform.
5. Managing Your Cookie Preferences
You can control or delete cookies at any time through your browser settings. Please be aware that disabling strictly necessary cookies — particularly the authentication session token — will prevent you from remaining logged in to the Platform.
Browser controls by browser:
- Chrome: Settings → Privacy and Security → Cookies and other site data
- Safari: Settings → Safari → Privacy & Security → Manage Website Data
- Firefox: Settings → Privacy & Security → Cookies and Site Data
- Edge: Settings → Privacy, search, and services → Cookies and site permissions
Mobile app data:
- iOS: Settings → [App Name] → Reset, or uninstall and reinstall the app
- Android: Settings → Apps → [App Name] → Storage → Clear Data
Opt-out of analytics: Contact us at privacy@brandmerce.com to request exclusion from analytics data collection.
6. Do Not Track
Some browsers offer a “Do Not Track” (DNT) setting. Because there is no industry-wide standard for responding to DNT signals, BranStory does not currently respond to DNT browser signals differently than standard requests. We do not use third-party advertising trackers regardless of DNT status.
7. Changes to This Policy
We may update this Cookie Policy periodically as the Platform evolves or as regulations change. Material changes will be posted on this page with an updated effective date. We encourage you to review this policy periodically. The current version is always available at branstory.com/cookie-policy.
8. Contact
Cookie questions or opt-out requests: privacy@brandmerce.com Brandmerce, LLC · Nocatee, Florida
BranStory is a product of Brandmerce, LLC. © 2026 Brandmerce, LLC. All Rights Reserved.