Cookie Policy
Last updated 2026-10-05
This Cookie Policy explains how CredScape uses cookies and similar technologies on our website. CredScape is owned and operated by CredScape Market Intelligence Inc.
We believe in being transparent about how we collect and use data. This policy details what cookies we set, what they do, and how you can control them.
1. What Are Cookies
Cookies are small text files that websites store on your device. Your browser saves these files when you load a page. Cookies help websites remember your actions, identify your session, and track page views.
We also use similar technologies, such as local storage, to run our application. For the sake of simplicity, we refer to all these technologies as "cookies" in this policy.
2. Our Approach to Cookies
We do not use cookies to build profiles for advertising. We do not run remarketing campaigns. We do not place third-party advertising pixels on our website.
Our website uses three categories of cookies and similar technologies. These are strictly necessary cookies, analytics cookies, and session replay.
Under Quebec Law 25, we practice privacy by default. This means everything non-essential is turned off automatically when you first visit our site. We will not run analytics or session replay unless you actively click to consent, and you can accept one without the other.
3. Cookie Categories
We group our cookies and similar technologies into the following three categories:
Strictly Necessary Cookies
These cookies are required for the basic operation of the website. Without these cookies, you cannot log in or use the platform. They allow you to move between pages and access secure areas. They also help keep our platform secure and stable.
Strictly necessary cookies perform the following functions:
- Session Authentication: We use Supabase Auth to manage your account login. Supabase sets cookies to remember your logged-in status.
- Consent Record: Your cookie choices are stored in your browser's local storage, not in a cookie, so the banner is not shown again on every visit. Clearing your browsing data clears this choice, and you will be asked again.
- Application State: We set a small first-party cookie to record that your account profile has been loaded, which avoids a redundant lookup on each page.
- Security and Load Balancing: We serve the platform through Cloudflare. Cloudflare may set cookies to identify trusted traffic and protect the site.
Analytics Cookies
These cookies help us understand how visitors interact with our platform. We use them to improve our website design and user experience.
Analytics cookies perform the following functions:
- Usage Statistics: We use Google Analytics 4 to measure how visitors find and use CredScape.
- Feature Optimization: Google Analytics helps us see which pages are popular and where visitors experience errors.
- Product Usage: We use PostHog, hosted in the European Union (Frankfurt), to see which features are used. Its requests go through our own domain. Signed-in users are identified only by an account identifier, never a name or email address, and search text is not recorded.
Google Analytics 4 collects identifiers such as cookies, device information, and IP addresses. We do not share this data with any advertising networks.
Session Replay
Session replay records how pages are used — where you move, click, and scroll — so we can see where the product is confusing or broken. It is a separate choice from analytics, because recording a session is a different thing from counting a page view. You can accept analytics and decline session replay.
We use OpenReplay, which is open source software that we host ourselves on our own server in Canada. Recordings are not sent to OpenReplay the company, or to any other third party. There is no vendor account behind this.
What is deliberately not recorded:
- What you type. Input fields are set to be ignored, so their contents never leave your browser. This includes search boxes and every form on the platform.
- Numbers shown on screen. Figures such as prices and counts are masked before the recording is sent.
- Email addresses and dates, in both form fields and page text.
Session replay sets no cookie. The recording session is identified by values kept in your own browser's local and session storage, under keys beginning __openreplay_ and or_.
Recordings are deleted automatically after a set retention period. Because a recording is the most detailed thing we hold about a visit, we keep it for the shortest period that is useful and no longer.
Support chat
Zendesk loads and sets its own cookies and local storage only after you click Help or Contact Support to request a chat. These are set by Zendesk (zendesk.com) to keep your conversation open. Retention is per Zendesk.
These cookies and local storage are strictly necessary for the chat you requested.
4. Consent and How to Control Cookies
You have full control over the cookies we set on your device. We respect your preferences and make it simple to change them.
Consent Banner
We present the banner using the Silktide Consent Manager, an open source tool we host ourselves on our own domain. It is not a third-party service: no request is made to the tool's authors, and your consent choice is not sent to anyone outside CredScape. It sets no cookie of its own — your choice is stored in your own browser's local storage, under the keys stcm.hasConsented and stcm.consent.analytics.
We also keep a record of the choice on our own servers. Data protection law requires us to be able to demonstrate that you consented, and a choice held only in your browser is not something we can show. Each record contains the categories you chose, the date and time, the version of this policy you were shown, and a randomly generated identifier that is also stored in your browser. We do not record your IP address or your browser's user-agent string with it. The identifier is not linked to your name or email unless you were signed in when you made the choice, in which case your account is recorded too. Changing your mind adds a new record rather than replacing the old one, because the history is the evidence.
When you first visit our website, you will see a cookie consent banner. You can choose to accept analytics cookies or decline them. If you click decline, we will not set any analytics cookies. Only strictly necessary cookies will be active.
Withdrawing Your Consent
You can change your mind at any time. If you want to withdraw your consent and delete analytics cookies, you can do so by clicking the "Cookie settings" link in our website footer. This link opens the consent banner again. You can then change your selection to decline.
Browser Settings
You can also manage cookies through your web browser settings. Most browsers allow you to block all cookies, accept all cookies, or block specific types of cookies. If you block all cookies, some parts of CredScape may stop working. You will not be able to log in to your account.
To learn how to manage cookies in your browser, check your browser's help menu.
5. Detailed Cookie Table
The table below lists all cookies used on the CredScape platform. It includes their names, categories, purposes, and retention periods.
| Cookie Name | Category | Purpose | Retention Period |
|---|---|---|---|
sb-<project>-auth-token |
Strictly Necessary | Supabase Auth session token that keeps you signed in. | Up to 1 year |
cs-profile-checked |
Strictly Necessary | Records that your account profile has been loaded. | Session |
| Zendesk cookies and local storage | Strictly Necessary | set by Zendesk (zendesk.com) to keep your conversation open | per Zendesk |
_ga |
Analytics | Google Analytics 4, distinguishes unique visitors. | 2 years |
_ga_1JL43K5NKV |
Analytics | Google Analytics 4, maintains session state. | 2 years |
ph_<project>_posthog and local storage |
Analytics | PostHog, distinguishes visitors and keeps product-usage state. Set only after you accept analytics. | 1 year |
Your cookie choice itself is not in this table because it is not a cookie. It is
stored in your browser's local storage under stcm.hasConsented,
stcm.consent.analytics, stcm.consent.sessionReplay and credscape.consentId. The choice and that random
identifier are sent to us once, when you make or change it, so that we hold the record
described in section 4.
Cloudflare may additionally set short-lived security cookies such as __cf_bm on
requests it screens. These are set by Cloudflare, not by us, and are strictly
necessary to protect the site.
The live list below is generated by scanning this site, so it stays accurate as the platform changes. Where it differs from the table above, the scan is correct.
6. Contact Information
If you have questions about our Cookie Policy or how we use tracking technologies, please contact us. You can email us at privacy@credscape.io.
Our registered mailing address is:
CredScape Market Intelligence Inc.
Attention: Privacy Officer
214-1111 Frost Road
Kelowna, British Columbia V1W 0G8
Canada