Embedder

Cookie Policy

Effective Date · August 21, 2026

Embedder Tech Inc., a Delaware corporation ("Embedder", "we", "our", or "us"), describes in this Cookie Policy how we use cookies and similar tracking technologies across the Services.

1. Scope

This Cookie Policy applies to everyone who accesses or uses the Services. Consistent with our Terms of Service, the "Services" include our websites at https://embedder.com and https://app.embedder.com, and all applications, services, and related software we make available through those websites, the Free Tier, or an Evaluation Period. This Policy describes the technologies we set, why we set them, and the choices available to you.

This Cookie Policy supplements our Privacy Policy, which describes how we handle personal data more broadly, including personal data collected through the technologies described here. Where both documents address the same processing, read them together.

By using the Services, you acknowledge that you have read this Cookie Policy. This acknowledgment is not consent where applicable law requires separate consent, which we request through the controls described in Sections 4 and 5.

Browser storage is specific to each domain. A choice saved on https://embedder.com does not automatically apply on https://app.embedder.com, or vice versa. You must manage preferences separately using the controls made available on each domain.

Our website and Services are intended only for adults who are at least 18 years old. See our Privacy Policy for more information.

2. What Are Cookies?

Cookies are small text files placed on your device when you access a website or application. They are widely used to make online services work, or work more efficiently, and to provide information to the operator. Similar technologies include local storage, session storage, and pixel tags. In this Policy, we refer to all of these collectively as "cookies."

First-party cookies are set by the Embedder domain you are using. Third-party cookies are set by another domain, typically by services we embed (such as analytics or advertising providers).

3. Categories of Cookies We Use

3.1 Strictly necessary

These cookies and similar storage are required for the Services to function and cannot be turned off in our systems. They are usually set in response to actions you take, such as recording your cookie preferences, signing in, maintaining a secure session, or protecting an account.

  • embedder-cookie-consentfirst-party localStorage entry that records whether you accepted or rejected all optional technologies in the EU/EEA/UK and Switzerland on the domain where you make the choice. Persists until you clear it.
  • embedder-privacy-opt-outfirst-party localStorage entry that records your "Do Not Sell or Share" preference (California). Persists until you clear it.
  • Application authentication and session storagefirst-party cookies or browser storage on app.embedder.comthat authenticate users, maintain secure sessions, and protect accounts. Session identifiers generally expire when the session ends or under the application's configured security schedule.

3.2 Analytics and experimentation

On our marketing website, these technologies help us understand how visitors interact with the website and run limited product experiments. Third-party analytics (Google Analytics) and the first-party analytics storage described below remain off until you accept all optional technologies in regions where our banner is shown. They are enabled by default only in regions where the banner is not shown.

  • Google Analytics 4measures site traffic and usage. Sets cookies with a typical duration of up to 2 years. We have configured Google Consent Mode to deny analytics storage until consent is granted in the EU/EEA/UK and Switzerland.
  • embedder_marketing_anonymous_idfirst-party localStorage entry that stores a randomly generated anonymous identifier so we can attribute first-party marketing-site events (for example, page views and CTA clicks) without relying on a login. In opt-in regions, it is created only after analytics consent. Persists until you clear it.

3.3 Advertising and visitor identification

On our marketing website, these cookies and scripts support advertising, conversion measurement, and visitor identification. They remain off until you accept all optional technologies in regions where our banner is shown, and are enabled by default elsewhere. We honor the Global Privacy Control (GPC) signal globally by disabling these technologies.

  • Google Adsmeasures the effectiveness of our advertising. Sets conversion-tracking cookies with a typical duration of up to 90 days.
  • Unifywebsite intent and visitor identification. Sets first-party cookies (including unify_visitor_id and unify_session_id) with a typical duration of up to 400 days, and may associate company-level or person-level identity signals with site activity.

3.4 Performance and security

These technologies help us operate, secure, and debug the Services. They are not used for advertising.

  • Sentryself-hosted error monitoring and performance tracing. Uses browser storage (such as session storage) to correlate errors across a visit; it is not used for advertising or visitor identification.
  • Cloudflareedge network, security (including bot challenges where applicable), and optional privacy-oriented Web Analytics / performance beacons that help us understand traffic and availability.

4. How We Obtain Consent

We tailor our controls based on your location, which we determine from network signals. Where our banner is shown, you can accept all optional analytics, advertising, and visitor-identification technologies or reject them all. Strictly necessary technologies remain active so the Services can function securely and remember your choice. You can change your preference using the controls described in Section 5.

4.1 European Economic Area, United Kingdom, and Switzerland

First-party marketing-site analytics and Google Analytics are blocked until you accept all optional technologies. Google Ads and Unify are blocked under the same choice. Strictly necessary storage and performance/security tooling may still operate. If your browser sends a GPC signal, advertising and visitor identification remain disabled even if you accept all optional technologies.

4.2 California

Optional analytics, advertising, and visitor-identification technologies remain off until you accept them. You can reject them or change your choice at any time using our "Do Not Sell or Share" control. We honor GPC signals from your browser as an opt-out from advertising and visitor identification.

4.3 Other regions

Analytics and advertising cookies are enabled by default unless your browser sends a GPC signal, in which case we disable advertising and visitor-identification technologies. You can disable cookies through your browser settings at any time.

5. Managing Your Preferences

You can manage cookies in several ways:

  • Our preference controls: use the privacy controls made available on each domain to update your consent or opt-out preference. Where the banner is available, you can accept or reject all optional analytics, advertising, and visitor-identification technologies.
  • Browser settings: most browsers let you block, delete, or be alerted to cookies. Refer to your browser's help documentation for instructions. Note that disabling cookies may affect functionality.
  • Global Privacy Control: we honor the GPC signal, which you can enable through supported browsers and extensions. When detected, we automatically disable advertising and visitor-identification tracking globally.
  • Do Not Track: some browsers send a "Do Not Track" (DNT) signal. We do not currently respond to DNT signals. DNT is distinct from GPC, which we honor as described above.
  • Provider opt-outs: you can opt out of Google Analytics across all sites using Google's browser add-on, and manage Google ad personalization at Google Ad Settings.

Preference changes are saved immediately. Rejecting optional technologies removes our first-party marketing identifier and prevents new client-side marketing events. Google receives updated consent settings when available. If Unify already loaded on the current page, your rejection takes full effect on the next full page load, when the script will no longer load. You may reload the page at any time to apply the choice immediately.

6. Changes to This Cookie Policy

We may update this Cookie Policy from time to time to reflect changes to our practices, the technologies we use, or applicable law. You are responsible for regularly reviewing this Cookie Policy. If we make material changes, we will notify you by email (if provided) or through the Services at least 30 days before they take effect.

7. Contact

Questions about this Cookie Policy or our cookie practices: [email protected].
Security reports: [email protected].
Our Chief Information Security Officer oversees our privacy program as our privacy lead. We have not designated that role as a statutory Data Protection Officer.

Embedder Tech Inc.
2261 Market Street STE 95828
San Francisco, CA 94114
United States