Cookies
Last updated: 2026-08-17
What are cookies and similar technologies?
Cookies are small text files placed on your device. We also use similar technologies that store data in your browser in the same way: localStorage, sessionStorage, IndexedDB, and the offline cache used by the installable app. We treat all of these under the same rules, and this policy applies to them equally.
We use them to keep you signed in, remember your preferences, let the app work offline, and — only with your permission — to understand how our marketing site is used.
The examples below are illustrative rather than a complete list of every stored item. If you want a full inventory of what Fixray stores on your device, email hello@fixray.app and we’ll send you one.
Categories we use
| Category | Purpose | Examples | Consent |
|---|---|---|---|
| Essential | Keeping you signed in, keeping your account secure, and remembering your cookie choice | Your sign-in session (localStorage); your cookie choice (fixray.consent.v1); the consent banner’s own cookie (fixray_cc_unused); Cloudflare Turnstile, which checks that form submissions come from a person rather than a bot | Always on |
| Functional | Remembering your preferences and in-progress work, and letting the app keep working when you lose signal | Light/dark and branding theme (fx-theme-cache, gs-theme); an unfinished issue report you started (fx-report-draft); which site and organisation you last had open; your recent searches; dismissing prompts such as “install the app”. In IndexedDB we also hold issue reports you submitted while offline — including any photos and voice notes attached to them — until they can be sent, plus a cache of your recent issues and settings so the app opens quickly. | Always on |
| Analytics | Understand which marketing pages convert, and recognise repeat visitors so demo bookings can be tied back to campaigns | PostHog — a cookie plus localStorage and sessionStorage entries named ph_*; HubSpot (hubspotutk, __hssc, __hssrc, __hstc, messagesUtk), which may also record what you submit through forms on our marketing site; and Apollo — localStorage entries (apolloAnonId, …_eventQueue) used to recognise which companies visit, which we clear if you withdraw analytics consent. PostHog additionally keeps a record of your analytics choice itself (__ph_opt_in_out_…) — this one is stored even if you decline, because it is how we remember not to track you. | Opt-in |
| Marketing | No marketing-only cookies currently loaded — reserved for future ad pixels | — | Off by default |
Performance and error monitoring
To keep fixray.app fast and available we use aggregate, network-level performance metrics (such as request counts and response times) provided by our hosting platform (Cloudflare), measured on the server side. No cookie is set for this, no user identifier is attached, and the data isn't shared with third parties.
Separately, on every page load of our marketing site — not only when something goes wrong — we send a short diagnostic report to our analytics provider PostHog telling us whether the page loaded correctly. It contains the page path (without anything after the ?), how long the page took to become usable, and any error encountered. We do not send your browser or device details, and this report stores nothing on your device — the random reference it carries exists only for that single page load and is never saved, so it cannot be used to recognise you on a later visit. As with any request to an outside service, PostHog does receive your IP address and may work out approximate location or browser information from the request itself. This is what tells us the site has broken for real visitors, and it is recorded regardless of your cookie choice.
If a page fails, we send the technical details of that error to our error-monitoring provider Sentry so we can fix it. This stores nothing on your device and we do not record your session. Before a report leaves your browser we strip out email addresses, IP addresses and cookies — and any email address or access token that appears in the text of the error message itself. As with any request to an outside service, Sentry still sees your IP address from the connection.
None of this is used to build a profile of you or to target advertising. We treat it as operational telemetry necessary to keep the service working.
Campaign attribution
If you arrive from an advert, email, or campaign link, that link carries tags identifying the campaign. If you opt in to analytics, we store those tags for the length of your visit (fx_utms, held in sessionStorage) so that if you later sign up or book a demo, we can tell which campaign brought you here.
If you decline, or you haven’t answered the banner yet, nothing is stored: the tags stay in memory for that one page and are discarded as soon as you go anywhere else. The same applies to the marker we use to avoid counting the same signup twice (fx_signup_started) — it is only written once you have opted in.
In-app product analytics
When you're signed in to the Fixray app (/app/*), we collect product analytics on a contract-necessity basis to operate and improve the service. This tracking is cookieless — no analytics or tracking identifiers are written to your browser, and analytics data is held only in memory for the length of your visit. The essential and functional items listed above (such as your sign-in session and theme preference) still apply inside the app.
Global Privacy Control (GPC)
We honour the GPC signal automatically. If your browser sends GPC, we record a "reject all" decision on first visit and never show you the banner. You can still opt back in at any time.
Manage your choices
You can change your cookie preferences at any time:
Contact
Questions about cookies or your data? Email hello@fixray.app. For how we handle personal data more broadly, see our Privacy Policy.