Legal

Cookie Policy

Short, because there is still very little to say.

Last updated August 27, 2026

The short version

These marketing pages run Google Analytics, which sets two cookies in your browser and tells Google which of our pages you read. It is how we find out whether anybody is reading them. That is the only measurement on this site.

It never runs where the work happens. No analytics loads in the signed-in workspace, on a customer’s menu link, on a document-capture page, or on the demo tour. Those pages send Google nothing, because their URLs are nobody else’s business.

If your browser sends Global Privacy Control, none of it loads at all — no script, no cookies, no request to Google.

Signing in sets one strictly necessary cookie: the session that keeps you signed in. A second appears only when you pick which rooftop you are working, and it is a preference, not a tracker. That is the complete list.

Before you sign in

Two cookies, both set by Google Analytics, both first-party — they are written on this domain and no other site can read them. Named here, because a policy that will not name them is not a policy.

_ga

Google Analytics’ visitor identifier: a random number that lets Google tell a returning browser from a new one, so two visits from you are not counted as two people. It contains no name, no email and nothing you typed. It expires two years after your last visit.

_ga_ followed by our measurement ID

The session counter for this specific site — the rest of its name is our own measurement ID. It records when the current visit started, so a page you open after lunch is a second visit rather than a very long first one. Also two years.

What Google receives alongside them is the ordinary analytics set: which page you are on and which page or search sent you, an approximate location worked out from your IP address, and your browser, device type and screen size. We do not send it anything else, and there is nothing to send — you have not told us anything at this point.

The tag is configured with Google Signals and ad-personalisation signals switched off. That is set in our own code rather than in a settings panel, and it is what keeps this a page count instead of an advertising audience: nothing here is joined to your Google account across other sites, and none of it can be used to target an ad at you.

If you submit the demo-request form, what you typed is sent to us and stored — see the privacy policy. That is a form submission, not a cookie, and it does not travel to Google.

Where analytics never runs

Analytics is switched on by an allowlist of the eleven marketing and legal pages, matched as whole paths. Everything else on this domain is off, including everything that does not exist yet. Concretely, no analytics script loads and no page view is sent from:

This is not a promise about our intentions. It is one list of paths, shared with the file that generates our sitemap so the two cannot drift apart, and a test that fails if the analytics component is imported anywhere except the site’s root layout.

Global Privacy Control

Some browsers, and several privacy extensions, send a signal called Global Privacy Control — a standing instruction not to sell or share your data. If yours does, this site does not load Google Analytics at all: the script is never requested, the two cookies above are never set, and Google never learns you were here.

No banner to dismiss, and nothing to remember on your next visit. Your browser already said it; we listened.

After you sign in

At most two more cookies, and no analytics whatsoever.

The Supabase authentication session

Set by our authentication provider when you sign in, and refreshed as you use the product. It is what makes the next page know it is still you. Without it there is no way to be signed in at all. It is stored so that page scripts cannot read it, and it is cleared when you sign out.

dt_active_store

Remembers which rooftop you are currently working, for people who hold a role at more than one store in a group. It is set when you pick a store — someone who only ever works one rooftop may never receive it. It is a preference, never a permission: the value is only ever used to pick from the list of dealerships your account provably has a role at, so editing it in your browser changes which of your stores you land on and nothing else.

Both are strictly necessary — the product cannot function without them — which is the category exempt from consent requirements under every privacy regime that applies to us. We are not relying on that exemption to sneak anything past it; those two are genuinely the whole list, and the analytics cookies above are not among them because analytics does not run here.

What we do not use

The demo-request form records which page it was submitted from. That is a hidden field in the form itself — no cookie, and it tells us nothing about you before you decide to press the button.

If that ever changes

Adding anything beyond what is named on this page means rewriting this page in the same change, and re-dating it. Adding a cookie that is neither strictly necessary nor covered by the analytics described above means adding real consent first — a genuine choice, defaulting to off, that works if you decline it. DealerTech.io would rather not have the data than have it dishonestly.

You can also block or clear cookies in your browser, and blocking Google Analytics changes nothing about how this site works. Clearing the two sign-in cookies signs you out and forgets which rooftop you were on; nothing else in the product depends on them.

Questions

info@dealertech.io.

This document was written from the software it describes, and has not been reviewed by counsel. It is the honest starting text, not legal advice. If a term here matters to your dealership’s decision, tell us and we will get it right rather than argue it later.