Applies to BOTH the NXTRUNN consumer app (web) and the NXTRUNN Partners Portal.
What's combined & why. One Cookie Policy covers both the app and the Portal because they share the same authentication, payment, and analytics technologies and the same consent approach. App-vs-Portal differences are labeled where relevant. This Policy supplements the Privacy Policy.
1. What this Policy covers
This Policy explains how NXTRUNN uses cookies and similar technologies (local storage, SDKs, pixels, device identifiers) on the NXTRUNN web app and Partners Portal, and how you can control them. In our mobile apps, similar technologies (e.g., local storage and SDKs from Clerk, Sentry, and analytics) perform comparable functions.
2. What cookies are
Cookies are small text files stored on your device. Session cookies expire when you close your browser; persistent cookies remain until they expire or you delete them. First-party cookies are set by NXTRUNN; third-party cookies are set by our service providers.
3. The categories of cookies we use
3.1 Strictly necessary (always on) — required for the platform to function; cannot be switched off in-product.
- Authentication & session — keep you signed in and secure your session (set by our auth provider, Clerk).
- [Portal] Active organization — remember which business/organization you're managing.
- Security & fraud prevention / rate limiting — protect accounts and the platform (supported by Upstash (Redis)).
- Load balancing / core preferences — basic functionality and your settings.
3.2 Functional — remember your preferences (e.g., display options). Improve experience but are not strictly essential.
3.3 Analytics / performance (consent-based) — help us understand feature usage so we can improve the product.
- PostHog product analytics — loaded only where enabled and, where required by law, only after you consent. When the analytics key is not configured, no analytics cookies/SDK load at all.
- Diagnostic/error context via Sentry (used for stability and security; configured to minimize personal data).
3.4 Third-party service cookies — set by providers when you use specific features:
- Stripe — secure payment processing and fraud prevention during checkout/payouts. Governed by Stripe's own cookie/privacy policies.
- Mapbox [App] — maps and location search.
- Clerk — authentication (also listed under necessary).
We do not use advertising or cross-context behavioral-tracking cookies, and we do not sell data collected via cookies.
4. Cookie table
Format: Cookie / technology — Provider — Type — Purpose — Duration
- __session / auth tokens — Clerk — Necessary — Sign-in & session — Session to 7 days
- Rate-limit / security keys — Upstash (Redis) — Necessary — Abuse & fraud prevention — Minutes to hours
- __stripe_* — Stripe — Necessary (payments) — Checkout & fraud prevention — Session to 1 year
- Analytics IDs — PostHog — Analytics (consent) — Product usage analytics — Up to 12 months
- Error/diagnostic context — Sentry — Necessary/diagnostic — Stability & security — Session
- Map tiles/session — Mapbox — Functional — Maps & geocoding — Session
Exact cookie names and durations can vary slightly as providers update their SDKs; we keep this table current with our production configuration.
5. Consent and how we ask for it
For non-essential cookies, NXTRUNN uses a cookie-consent mechanism that:
- loads only strictly-necessary cookies by default, with no non-essential cookies/SDKs (including PostHog analytics) firing before consent;
- presents clear "Accept," "Reject," and "Manage preferences" options with equal prominence (no pre-ticked boxes; reject as easy as accept);
- records and stores your consent choice and lets you change or withdraw it at any time via a persistent "Cookie settings" control;
- respects Global Privacy Control (GPC) browser signals; and
- surfaces this Policy and the cookie table from the banner.
Where consent is required (e.g., the EU/UK ePrivacy + GDPR standard, LGPD, and similar laws), non-essential cookies are used only after you opt in. Where consent is not legally required, we rely on legitimate interests for functional/analytics cookies and still honor opt-outs.
6. How to control cookies
- In-product: use the Cookie settings control to accept, reject, or change non-essential cookies.
- Browser controls: you can block or delete cookies in your browser settings. Blocking strictly-necessary cookies will break sign-in and core functionality.
- Global Privacy Control: we treat a valid GPC signal as a request to opt out of non-essential cookies/sharing where applicable.
- Mobile OS controls: manage app permissions and "limit ad tracking"/equivalent in your device settings.
7. Changes
We will update this Policy as our use of cookies changes and revise the "Last updated" date. Material changes will be reflected in the consent banner.
8. Contact
Questions: legal@nxtrunn.com · info@nxtrunn.com (app) · partners@nxtrunn.com (portal). See also the Privacy Policy.