Cookie Policy
Entity: Hangpost, Inc. · Last updated: September 2026 ·
Contact: privacy@hangpost.app
1. What this policy covers
This policy explains the cookies, local storage, SDKs, and similar technologies the Hangpost websites and apps use, and your choices. It supplements, and is incorporated into, our Privacy Policy. "Cookies" below is shorthand for all of these technologies (browser cookies, mobile-app local storage, device identifiers, and software development kits).
2. The technologies we use
We use only the categories below. Apart from the two narrow ad-measurement tags described below -- a Google Ads conversion tag and a Meta Pixel, each of which only tells us whether one of our own ads led to a waitlist signup and nothing about you -- we do not use retargeting, social-media, data-broker, or cross-app tracking technologies to profile you or follow you across other companies' apps and sites, and we do not sell or share your information for cross-context behavioral advertising. The Meta Pixel is itself a social-media measurement tag: it is the only social-media technology on our stack, it runs with Limited Data Use enabled and no advanced matching, and it never receives your name, email, or phone. The only advertising-related technologies we use are those narrow ad-measurement tags: they tell us whether an ad we bought led to a waitlist signup, and nothing about you.
| Category | Why | Examples on our stack | Can you turn it off? |
|---|---|---|---|
| Strictly necessary | Sign you in, keep you signed in, secure the session, remember basic preferences, and protect against abuse/rate-limit attacks | Clerk authentication session cookie/token; Upstash-backed rate-limit counters keyed to your IP address or your signed-in account | No. The Service can't function without these; no consent required for strictly-necessary cookies |
| Functional | Remember your settings (e.g., home-base view, UI preferences) so the app behaves the way you left it | App local storage; preference cookies | Partially. Clearing them resets preferences |
| Performance / diagnostics | Detect and fix errors and crashes, and keep the service reliable | Sentry (error/crash diagnostics, configured to scrub PII before send) | Yes, where required; the privacy choice on this page stops optional measurement loading in this browser, though crash diagnostics continue; see § 4 |
| Ad measurement (added August 2026) | Tell us whether one of our own ads (for example a Google search ad) led to a waitlist signup, so we know which ads are worth buying | Google Ads conversion tag on our public website pages only, with ad-personalization signals disabled. It counts a signup against the ad click; we never send it your name, email, or phone, and it is not used to target or profile you. Outside the US it does not load and sets nothing | Yes. Block it with your browser or an ad blocker and everything on the site still works; the privacy choice on this page stops it loading in this browser from then on; see § 4 |
| Ad measurement, Meta (added August 2026) | Tell us whether one of our own Meta ads (on Facebook or Instagram) led to a waitlist signup, for the same reason | Meta Pixel on our public website pages only, with Limited Data Use enabled and no advanced matching. It counts a signup against the ad click; we never send it your name, email, or phone, and it is not used to target or profile you. Outside the US it does not load and sets nothing | Yes. Block it with your browser or an ad blocker and everything on the site still works; the privacy choice on this page stops it loading in this browser from then on; see § 4 |
What's deliberately absent: Google Analytics / TikTok pixel / any retargeting or "identity resolution" or fingerprinting vendor. (Updated August 2026: the Google Ads conversion tag above was added, with this policy, the Service providers page, and the Privacy Policy updated in the same change to describe it -- the process this paragraph always promised. It measures our own ads' signups; it does not profile you, and personalization signals are off.) (Updated again August 2026: the Meta Pixel moved off this absent list and into the table above, by the same process -- this policy, the Service providers page, and the Privacy Policy all updated in the change that added it. It measures our own Meta ads' signups with Limited Data Use enabled and no advanced matching; it does not profile you.) Anything further ships only after the same three documents describe it, and, if it is a non-essential tracking technology, behind a consent control.
3. Mobile apps (no "cookies," same idea)
Our iOS/Android apps don't use browser cookies, but they use the equivalent local storage and SDKs above (auth token storage, crash diagnostics, push-notification tokens). We do not use the device advertising identifier (IDFA/AAID) and do not present an App Tracking Transparency tracking prompt because we do not track you across other companies' apps or websites: the honest answer to Apple's ATT question is "no tracking," so there is nothing to ask permission for.
4. Your choices
- Browser controls. You can block or delete cookies in your browser settings. Blocking strictly-necessary cookies will break sign-in and core features.
- The privacy choice on this page. The control at the top of this page turns optional website measurement off in the browser you are using. It stops the ad-measurement and performance tags from loading from that point on, and reloads the page so any already-loaded vendor script is gone. Two honest limits: it is stored in this browser only, so it does not follow you to another device, and it does not delete cookies a vendor already set, so use your browser's controls to clear those. Crash diagnostics still run: they are how we find out the site is broken, and they are scrubbed of personal data before they are sent.
- Diagnostics opt-out. Where required by applicable law, or simply on request, you can opt out of non-essential performance/diagnostics collection at privacy@hangpost.app. Strictly-necessary processing continues regardless.
- Do Not Track / Global Privacy Control. We do not engage in cross-context behavioral advertising or "sales" of personal information, and the ad-measurement cookies above carry no name, email, or phone. Blocking them (browser settings or any ad blocker) fully disables them with no effect on the site, and we honor GPC/DNT as an opt-out of non-essential analytics by policy.
- Push notifications can be turned off in your device settings or in-app.
5. Third parties setting these technologies
The only parties that set or read the technologies above are the providers acting on our behalf: Clerk, Upstash, Sentry, and our hosting providers, summarized by category on our Service providers page. They only handle the data needed to provide their service to us and may not use it for their own advertising. The one exception is the two ad measurement pixels described in section 2, Google's and Meta's: they run only on our public marketing pages, never inside the Hangpost app, and only in the measurement-only setup described there. Nobody shows you third-party ads inside Hangpost, and no advertiser is given member data.
6. Changes
We update this policy when the stack changes. Material changes are announced as described in the Privacy Policy. The "effective date" above and the git history of this file are the version record.