Tokenize Cookie Policy
Last updated: September 1, 2026
This Cookie Policy explains how Palindrome Labs, Inc. dba Tokenize ("Tokenize," "we," "us," or "our"), uses cookies and similar technologies on tokenizehq.com, its subdomains, and our hosted platform (the "Services"). It supplements our Privacy Policy.
1. Technologies Covered
Cookies are small text files stored on a device. We also use local storage, browser software development kits, and similar technologies. This policy refers to all of them as "technologies."
Some technologies operate for a browser session. Others persist until they expire, you delete them, or the applicable provider or Tokenize removes them.
2. Technologies We Use
2.1 Essential technologies
Essential technologies provide authentication, security, session management, and application delivery. The Services may not function correctly if you block them.
| Purpose | Information or function | Provider | Typical duration |
|---|---|---|---|
| Authentication and session management | Sign-in state, account session, organization context, and security tokens | Clerk; Tokenize | Session duration or the configured account-session period |
| Enabled identity-provider authentication | Information needed to complete sign-in through an identity provider selected by you or your organization | Google, Microsoft, or an enterprise identity provider, when enabled | Set by the identity provider under its policy |
| Application delivery and security | Routing, delivery, abuse prevention, and security signals | Vercel; Tokenize | Session or the period required for delivery and security |
| Application preferences | Settings stored on the device when a user selects or configures them | Tokenize | Until the preference expires, changes, or is deleted |
| Product Analytics choice | Whether you enabled or disabled optional product analytics in the authenticated platform | Tokenize | Until you change the preference or clear browser storage |
| Cookie consent and preferences | Whether you accepted, rejected, or customized non-essential technologies; information needed to apply and demonstrate the choice | Tokenize; c15t, with Inth as the hosted consent-record backend when configured | Until you change the preference, clear browser storage, or the record expires under the consent-manager configuration |
2.2 Privacy-focused website analytics
We use Fathom Analytics to understand how visitors use our public website. Fathom does not place cookies or persistent identifiers on your device, and we do not use it to follow individuals across websites.
| Purpose | Information or function | Provider | Typical duration |
|---|---|---|---|
| Website audience measurement | Pages viewed, referring websites, browser and device type, country-level location, and aggregated visit and event counts | Fathom Analytics | Fathom deletes its daily visitor hashes each day; aggregate website statistics may remain in our Fathom account |
When a page loads, the visitor's browser sends an IP address and user-agent information to Fathom. Fathom processes that information to create a salted visitor hash that rotates daily and to protect its service against abuse. Fathom does not store the raw IP address with website activity or make it available to us. Additional information appears in Fathom's description of how it processes analytics data.
Our public website provides a consent manager for non-essential technologies. Fathom does not use cookies or other non-essential browser storage, so the marketing choice does not control Fathom. We do not use Fathom to identify individual visitors or for cross-site advertising.
2.3 Application analytics and diagnostic technologies
Our authenticated platform uses browser-side technologies to manage optional product analytics, diagnose errors, monitor performance, and protect the Services.
| Purpose | Information or function | Provider | Typical duration |
|---|---|---|---|
| Optional product analytics and feature management | Page and feature activity, browser and device information, session identifiers, pseudonymous user or organization identifiers, and feature-flag state | PostHog | Off by default; after opt-in, PostHog browser identifiers persist for up to 365 days unless you disable Product Analytics or clear browser storage sooner |
| Error and performance monitoring | Error reports, diagnostic information, request or trace identifiers, and performance measurements | Sentry | No cookies, local storage, or session storage in Tokenize's current configuration; diagnostic events are retained under Tokenize's service-retention schedule |
PostHog product analytics is off by default. If you enable Product Analytics in Settings > Account > Privacy, PostHog may use cookies or local storage to maintain session, pseudonymous user, organization, and feature context. We configure PostHog not to record sessions, autocapture page interactions, or collect prompts, responses, source code, credentials, or other Customer Data. Tokenize does not use PostHog on the public website or for advertising or cross-site tracking. The Privacy Policy describes how we use and disclose Personal Information collected through these technologies.
2.4 Payment and subscription technologies
When you initiate checkout or manage a paid self-service subscription, you may be directed to a Stripe-hosted page. Tokenize provides Stripe only billing contacts, subscription and transaction information, and Tokenize account identifiers needed for billing. Customers submit payment details directly to Stripe. Tokenize does not provide Stripe with prompts, responses, transcripts, telemetry, source code, files, credentials, or other Customer Data.
Stripe may use cookies and similar technologies on its hosted payment pages for payment processing, authentication, security, and fraud prevention. We do not use Stripe technologies for advertising and do not load a Stripe payment form on the public website before you initiate a payment or billing action.
| Purpose | Information or function | Provider | Typical duration |
|---|---|---|---|
| Payment and subscription processing | Checkout session, payment authentication, subscription and transaction information, and payment preferences | Stripe | Session or the period described in Stripe's Cookie Policy, depending on the technology |
| Payment security and fraud prevention | Browser, device, network, transaction, and security signals collected by Stripe on its hosted payment page | Stripe | Session or the period described in Stripe's Cookie Policy, depending on the technology |
2.5 Website measurement and company identification
Subject to the consent model and choice that apply in your location, we use Snitcher, operated by Snitcher B.V., on our public website to measure site use, identify companies that visit, support attribution, and inform business-to-business sales and marketing. For Swiss visitors and others subject to an opt-in model, the consent manager does not load Snitcher before the visitor accepts the marketing category. In an opt-out location, Snitcher may load until the visitor rejects marketing technologies.
Snitcher processes IP address, browser and device characteristics, pages viewed, referring URLs, visit duration, and random device and session identifiers. It uses the IP address to identify the company associated with a visit and derive an approximate location, then aggregates visit information at the company level. Snitcher provides us with company-level activity and firmographic information such as company name, industry, and size. We do not use Snitcher to identify individual consumers or for cross-site advertising.
Snitcher is not necessary for the website to function. Its current browser technologies are:
| Technology | Purpose | Provider | Typical duration |
|---|---|---|---|
snitcher_device_id | Randomly generated identifier used to recognize a returning browser; stored as a first-party cookie and in local storage | Snitcher | 1 year |
snitcher_session | Session identifier and engagement timing used to group page views into a visit; stored in local storage | Snitcher | 30 minutes after the last activity |
__sn_tld_probe | Temporary cookie used to determine the correct first-party cookie domain; stores no data and is deleted after the check | Snitcher | Immediate deletion |
Additional information appears in Snitcher's guidance on data collection, cookies, and GDPR and Snitcher's Privacy Policy.
3. Your Choices
Our public website lets you accept all non-essential technologies, reject them, or customize your choice. Select Cookie Preferences to reopen the consent manager and change your choice. In an opt-in location, the website does not load Snitcher before you accept marketing technologies. In an opt-out location, Snitcher may load until you reject marketing technologies. Rejecting or withdrawing marketing consent prevents the website from loading Snitcher on future page loads from that browser.
Changing your Tokenize cookie preference does not delete company-level visit data that Snitcher processed before the change. You can delete Snitcher cookies and browser storage through your browser and email privacy@tokenizehq.com to exercise an applicable privacy right.
Stripe controls the technologies used on its hosted payment pages under its policies. Essential payment, authentication, security, and fraud-prevention technologies may be necessary to complete a transaction.
PostHog product analytics is controlled separately in the authenticated platform. You may enable or disable it at any time through Settings > Account > Privacy. We do not activate PostHog analytics or place its analytics identifiers in browser storage before you enable it. Disabling Product Analytics stops future PostHog collection from that browser and clears the PostHog browser identity stored there.
Most browsers allow you to block or delete cookies and local storage used for authentication, security, preferences, application delivery, payment processing, and optional product analytics. Blocking essential technologies may prevent sign-in, payment, or other Services from working. Disabling optional Product Analytics does not prevent you from using the core Services, but a feature that is being tested or released through PostHog may remain unavailable.
You may contact privacy@tokenizehq.com with a question about our use of these technologies.
4. Emails
We may use company-level visit information from Snitcher and business contact information from other sources to send marketing or conduct business-to-business outreach as permitted by law. Marketing emails include an unsubscribe mechanism. We may also send product, service, security, support, or transactional emails. We do not currently use tracking pixels to determine whether a recipient opened or interacted with an email.
5. Retention
Essential technology lifetimes vary by purpose and configuration. Session technologies generally expire when the browser session or authenticated session ends. Persistent preference, authentication, and consent technologies remain until their configured expiration, until you change or clear them, or until Tokenize or the provider removes them.
Fathom deletes its daily visitor hashes each day. Aggregate website statistics may remain in our Fathom account so that we can understand website trends over time. Fathom does not store those aggregate statistics on your device. Snitcher browser identifiers persist for the periods listed in Section 2.5, up to one year. We retain company-level visit reports only as long as reasonably necessary for website measurement, attribution, and business-to-business sales and marketing. If you enable PostHog product analytics, its browser identifier expires after no more than 365 days and is removed sooner if you disable Product Analytics or clear browser storage. The Product Analytics preference itself remains until you change it or clear browser storage. Stripe determines the duration of technologies used on its hosted payment pages according to their payment, authentication, security, and fraud-prevention purposes; current details appear in Stripe's Cookie Policy.
Provider updates, browser settings, and customer-specific authentication configuration may change a technology's name or duration. We review the technologies used by the Services and update this policy when a material practice changes.
6. Changes to This Policy
We may update this policy as our technologies or legal obligations change. We will post the revised version with a new "Last updated" date and provide any additional notice required by law.
7. Contact Us
Palindrome Labs, Inc. dba Tokenize
128 King St, Floor 3
San Francisco, CA 94107, United States
privacy@tokenizehq.com