Policies & terms
Last Updated: August 24, 2026
Cookie Policy
Last Updated: August 24, 2026
This Cookie Policy explains how Establishment Offerlash ("we," "us," and "our") uses cookies and similar technologies to recognize you when you visit our website at offerlash.com ("Website"). It explains what these technologies are and why we use them, as well as your rights to control our use of them.
What are cookies?
A cookie is a small data file that is placed on your device when you visit a website. Cookies are widely used by website owners in order to make their websites work, or to work more efficiently, as well as to provide reporting information.
Why do we use cookies?
Our landing site is intentionally lightweight. For referral-bearing visits, we store a referral code and timestamp in first-party browser storage and a random UUID v4 in the strictly necessary, HTTP-only first-party cookie offerlash_visitor_id, each for up to 7 days. The UUID is created only when a referral purpose is present, including a valid referral link, app-referral route, or canonical public-profile attribution fallback on /[handle]; it is not created for authenticated visits. We use it only to connect qualifying referral requests and credit commissions, not for advertising, profiling, or cross-site tracking. Where app-install attribution relies on provider matching, matching can be deterministic or probabilistic; probabilistic matching is inferential and is not guaranteed to be 100% accurate in every case. Optional analytics, performance monitoring, error reporting, and eligible profile-owner advertising are enabled by default unless you disable them. PostHog, Google Analytics, and TrustedSite run only when configured. Profile-owner GA4 measurement follows the analytics choice. Profile-owner Google Ads, Meta, TikTok, and Snap advertising tags require both analytics and personalized advertising to remain enabled.
What types of cookies do we use?
- Strictly Necessary Referral Attribution: When you arrive through a valid referral link or app-referral route, or when you open a canonical public-profile page at
/[handle]and the canonical public-profile attribution fallback applies, we store the referral code and timestamp inlocalStorageand a random UUID v4 in the HTTP-only first-party cookieofferlash_visitor_id, each for up to 7 days. The UUID is purpose-gated, is not created for authenticated visits, and is used only to associate qualifying requests with the referral attribution you requested. It is not used for advertising, profiling, or cross-site tracking. - Privacy Preference Storage: We store each analytics, performance, error-reporting, and personalized-advertising decision in first-party
localStorageand a corresponding first-party cookie. The storage keys areofferlash.analytics.consent,offerlash.performance.consent,offerlash.crashlytics.consent, andofferlash.personalized_ads.consent; their cookie counterparts areofferlash_analytics_consent,offerlash_performance_consent,offerlash_crashlytics_consent, andofferlash_personalized_ads_consent. A saved decision isv2:acceptedorv2:rejected. Missing, legacy, or unrecognized values do not count as current decisions, so the category remains enabled by default. The values contain no personal information. - Sitewide Analytics: We use PostHog and Google Analytics for configured product analytics. Analytics is enabled by default. Selecting "Disable" records
v2:rejected, stops subsequent Offerlash analytics events, opts PostHog out of capture, and revokes Google analytics storage. Selecting "Keep enabled" or checking the setting recordsv2:accepted. Re-enabling capture does not require PostHog to initialize a second time. - Google Consent Mode: Google storage consent is granted by default and updated to denied when you disable a required category. If Google's runtime has already loaded, Google Consent Mode may send cookieless consent-status or measurement pings after denial. We stop future events initiated by Offerlash and remove the Google script and bootstrap globals that Offerlash owns. We preserve a shared Google runtime created by other code. A preference change cannot recall requests that were already dispatched.
- Profile Owner Analytics and Advertising: Public profile owners may configure their own GA4 measurement, Google Ads conversion tag, Meta Pixel, TikTok Pixel, or Snap Pixel. Owner GA4 measurement runs unless analytics is disabled. Google Ads, Meta, TikTok, and Snap advertising tags require both analytics and personalized advertising to remain enabled. They run only on that public profile page and only when the public API returns a valid configuration for that profile.
- TrustedSite Trustmark: TrustedSite loads by default when analytics is configured as enabled. It may use the
trustedsite_visitcookie and browserlocalStorageto operate, verify, and measure the trustmark. If analytics is disabled, we do not load it and remove the script and badge elements we added. - Error and Performance Monitoring: Sentry browser error reporting and performance monitoring are enabled by default. Disabling error reporting blocks later browser errors, logs, and breadcrumbs. Disabling performance monitoring blocks later browser transactions and metrics. For request-associated server telemetry, a current
v2:rejectedcookie blocks that category; a missing, legacy, or unrecognized value leaves it enabled. A browser change affects later client events immediately and server processing from the next request. Clearly non-request operational events may still be retained.
How can I control cookies?
You may keep all optional categories enabled, disable all of them from the privacy notice, or manage them individually in the Privacy & Consent Settings on this public Cookie Policy page. Unchecking a category records v2:rejected and disables it. Checking it records v2:accepted and keeps it enabled. You may also manage cookies and localStorage through your browser settings; the methods vary by browser and version.
Please note that if you choose to block or delete cookies, some parts of our Website may not function properly.
Changes to This Cookie Policy
We may update this Cookie Policy from time to time, at our sole discretion and without prior notice. We will post the revised Cookie Policy on this page and update the "Last Updated" date. Your continued use of the Website after any changes constitutes your acceptance of the updated Cookie Policy. We encourage you to review this page periodically.
Contact Us
If you have any questions about our use of cookies, please contact us at [email protected].
Privacy & Consent Settings
These optional features are enabled by default. Uncheck any category you want to disable; changes are saved in this browser.
