Skip to main content

Cookie Policy

Last updated: January 15, 2026

Cookie Policy

Document owner: Chief Privacy Officer (CPO) Version: 3.0 Effective date: January 1, 2026 Last updated: January 15, 2026 Classification: Public — Trust Center Review cadence: Semi-annual, and upon changes to cookie usage or consent requirements Company: Acme Cloud, Inc. Address: 1200 Market Street, Suite 400, San Francisco, CA 94103, USA Primary contacts: trust@acmecloud.com | security@acmecloud.com | privacy@acmecloud.com


Definitions

TermDefinition
CookieA small text file stored on a user's device by a web browser
First-Party CookieA cookie set by the domain the user is visiting (Acme Cloud domains)
Third-Party CookieA cookie set by a domain other than the one the user is visiting
Session CookieA cookie that expires when the browser is closed
Persistent CookieA cookie that remains on the device until it expires or is deleted
Strictly Necessary CookieA cookie essential for website functionality
Functional CookieA cookie that remembers user preferences and settings
Performance CookieA cookie that collects analytics data about website usage
Targeting CookieA cookie used for advertising and marketing purposes
Consent Management Platform (CMP)Software for managing user cookie consent
TCFTransparency and Consent Framework (IAB Europe standard)
IDFAIdentifier for Advertisers (Apple mobile devices)
GAIDGoogle Advertising ID (Android mobile devices)
FingerprintingCollecting device characteristics to identify users without cookies
Local StorageBrowser storage mechanism similar to cookies but with larger capacity
PixelA small image file used to track user behavior
SDKSoftware Development Kit, libraries for mobile app analytics
Web BeaconA technique using images or scripts to monitor user behavior

Scope and Applicability

1.1 Covered Properties

This Cookie Policy applies to all digital properties owned or operated by Acme Cloud, Inc.:

Property TypeExamplesCookie Usage
Marketing websitesacmecloud.com, www.acmecloud.comAll cookie categories
Application platformapp.acmecloud.comNecessary + functional
Developer documentationdocs.acmecloud.comNecessary + performance
Blog and resourcesblog.acmecloud.com, resources.acmecloud.comAll cookie categories
Support portalsupport.acmecloud.comNecessary + functional
Status pagestatus.acmecloud.comNecessary only
Mobile applicationsiOS and Android appsSDK analytics

1.2 Geographic Applicability

Cookie consent requirements vary by jurisdiction. Acme Cloud implements consent mechanisms to comply with applicable laws:

JurisdictionLegal BasisConsent RequirementOpt-Out Mechanism
European UnionGDPR, ePrivacy DirectivePrior consent for non-essentialCookie banner
United KingdomUK GDPR, PECRPrior consent for non-essentialCookie banner
California (US)CCPA/CPRANotice + opt-out for sale/sharing"Do Not Sell" link
Other US statesState privacy lawsVaries by statePreference center
BrazilLGPDPrior consent for non-essentialCookie banner
CanadaPIPEDA, CASLImplied consent (analytics), express consent (marketing)Preference center
AustraliaPrivacy ActNotice required, consent best practicePreference center

1.3 Updates to This Policy

Acme Cloud reviews this Cookie Policy semi-annually and updates it when:

  • New cookies or tracking technologies are implemented
  • Existing cookies change purpose or duration
  • Consent requirements change due to new regulations
  • Third-party providers modify their tracking practices

Changes are communicated via updated policy publication and, where required, renewed consent requests.


Cookie Categories

2.1 Strictly Necessary Cookies

These cookies are essential for website functionality and cannot be disabled. They enable basic functions like page navigation, secure area access, and session management.

Cookie NameProviderPurposeDurationData Collected
session_idAcme CloudMaintains user session stateSessionSession identifier
csrf_tokenAcme CloudPrevents cross-site request forgerySessionSecurity token
auth_tokenAcme CloudAuthenticates logged-in users30 daysAuthentication token
device_idAcme CloudDevice recognition for security1 yearDevice identifier
consent_statusAcme CloudStores cookie consent preferences1 yearConsent choices
cf_clearanceCloudflareVerifies human visitors (bot protection)30 minutesChallenge result
__cf_bmCloudflareBot management30 minutesBot detection score
rate_limitAcme CloudPrevents abuse through rate limiting1 hourRequest count

Legal basis: These cookies are exempt from consent requirements under Article 5(3) of the ePrivacy Directive as they are strictly necessary for the service explicitly requested by the user.

2.2 Functional Cookies

These cookies enable enhanced functionality and personalization. While the website can function without them, user experience may be degraded.

Cookie NameProviderPurposeDurationData Collected
localeAcme CloudRemembers language preference1 yearLanguage code
timezoneAcme CloudStores timezone preference1 yearTimezone identifier
themeAcme CloudRemembers dark/light mode preference1 yearTheme selection
sidebar_stateAcme CloudRemembers navigation sidebar state1 yearCollapsed/expanded
dashboard_layoutAcme CloudRemembers dashboard configuration1 yearLayout preferences
recent_itemsAcme CloudStores recently accessed itemsSessionItem identifiers
tour_completedAcme CloudTracks onboarding tour completion1 yearCompletion status
notification_prefsAcme CloudStores notification preferences1 yearPreference settings
cookie_banner_dismissedAcme CloudTracks if banner was dismissed1 yearDismissal status
feature_announcementsAcme CloudTracks viewed feature announcements90 daysAnnouncement IDs

Legal basis: Consent required in GDPR jurisdictions. In non-consent jurisdictions, legitimate interest for improved user experience.

2.3 Performance Cookies

These cookies collect information about how visitors use the website, including which pages are visited most often and any error messages received. Data is aggregated and anonymous.

Cookie NameProviderPurposeDurationData Collected
_gaGoogle AnalyticsDistinguishes unique users2 yearsUser identifier
ga[ID]Google AnalyticsMaintains session state2 yearsSession data
_gidGoogle AnalyticsDistinguishes users24 hoursUser identifier
_gatGoogle AnalyticsThrottles request rate1 minuteN/A
_gcl_auGoogle AdsConversion tracking90 daysConversion data
mp_[token]MixpanelProduct analytics1 yearEvent data
ajs_anonymous_idSegmentAnonymous user tracking1 yearAnonymous ID
ajs_user_idSegmentIdentified user tracking1 yearUser ID (if logged in)
ph_[key]PostHogProduct analytics1 yearEvent data
intercom-sessionIntercomSession tracking for support1 weekSession data
intercom-device-idIntercomDevice identification9 monthsDevice ID
FullStory_uidFullStorySession replay90 daysUser identifier
fs_uidFullStorySession replay1 yearUser identifier
datadog_rumDatadogReal user monitoringSessionPerformance data

Legal basis: Consent required. Users can decline these cookies without affecting core functionality.

2.4 Targeting and Advertising Cookies

These cookies track browsing activity to deliver relevant advertisements and measure advertising campaign effectiveness.

Cookie NameProviderPurposeDurationData Collected
_fbpMeta (Facebook)Facebook advertising90 daysBrowser ID
_fbcMeta (Facebook)Click attribution90 daysClick ID
frMeta (Facebook)Advertising delivery90 daysUser data
li_fat_idLinkedInLinkedIn advertising30 daysFirst-party ID
lidcLinkedInData center selection24 hoursRouting data
bcookieLinkedInBrowser identification1 yearBrowser ID
bscookieLinkedInSecure browser cookie1 yearBrowser ID
IDEGoogle DoubleClickAd serving13 monthsConversion data
NIDGooglePreferences and ads6 monthsPreferences
_gcl_awGoogle AdsConversion tracking90 daysConversion data
hubspotutkHubSpotVisitor tracking13 monthsUser token
__hsscHubSpotSession tracking30 minutesSession data
__hssrcHubSpotSession resetSessionSession status
__hstcHubSpotVisitor tracking13 monthsTracking data
_uetsidMicrosoft BingSession trackingSessionSession ID
_uetvidMicrosoft BingVisitor tracking13 monthsVisitor ID

Legal basis: Explicit consent required in all jurisdictions. Users must actively opt in to targeting cookies.


Similar Technologies

3.1 Local Storage and Session Storage

In addition to cookies, Acme Cloud uses browser storage APIs:

Storage TypePurposeData StoredPersistenceConsent Required
localStorageApplication stateUser preferences, cached dataUntil clearedSame as cookie category
sessionStorageSession stateTemporary application dataUntil tab closedNot typically required
IndexedDBOffline functionalityCached documents, offline dataUntil clearedSame as cookie category

Local storage items used by Acme Cloud:

KeyPurposeCategory
app_stateApplication state persistenceFunctional
cached_dataPerformance optimizationPerformance
user_preferencesUser settingsFunctional
draft_contentAutosaved draftsStrictly necessary
analytics_queueQueued analytics eventsPerformance

3.2 Web Beacons and Pixels

Acme Cloud uses web beacons (tracking pixels) for:

Beacon TypeProviderPurposeTriggerConsent Required
Email open trackingHubSpotMeasure email engagementEmail openImplied with email
Conversion pixelMetaTrack sign-up conversionsRegistrationYes (targeting)
Conversion pixelLinkedInTrack demo request conversionsForm submissionYes (targeting)
Conversion pixelGoogle AdsTrack trial start conversionsTrial activationYes (targeting)
Page view beaconGoogle AnalyticsTrack page viewsPage loadYes (performance)

3.3 Mobile SDKs and Device Identifiers

Acme Cloud mobile applications use:

SDK/TechnologyPlatformPurposeData CollectedConsent Required
Firebase AnalyticsiOS, AndroidApp analyticsUsage events, crashesYes
CrashlyticsiOS, AndroidCrash reportingCrash data, device infoLegitimate interest
SegmentiOS, AndroidAnalytics routingConfigurable eventsYes
IntercomiOS, AndroidIn-app supportUser ID, conversation dataLegitimate interest
IDFAiOSAdvertising attributionAdvertising identifierYes (ATT prompt)
GAIDAndroidAdvertising attributionAdvertising identifierYes

Consent Management

4.1 Consent Mechanisms

Acme Cloud implements consent management through:

MechanismDescriptionJurisdictions
Cookie consent bannerProminent banner on first visitEU, UK, Brazil
Granular consent controlsCategory-level opt-in/opt-outEU, UK, Brazil
Preference centerDetailed cookie management pageAll jurisdictions
"Do Not Sell" linkCCPA-required opt-outCalifornia
Global Privacy ControlBrowser signal respectCalifornia, Colorado
ATT promptiOS advertising tracking authorizationiOS devices

4.2 Consent Banner Implementation

The cookie consent banner implements the following workflow:

Step 1: Initial Display 1.1. Banner displays on first visit to any Acme Cloud property 1.2. No non-essential cookies are set before consent 1.3. User presented with clear consent options

Step 2: User Choice 2.1. "Accept All" enables all cookie categories 2.2. "Reject All" (or "Necessary Only") blocks non-essential cookies 2.3. "Customize" opens granular preference center

Step 3: Consent Recording 3.1. Consent choice stored in first-party cookie 3.2. Timestamp and version recorded 3.3. Consent signal shared with third-party providers via CMP integration

Step 4: Consent Enforcement 4.1. JavaScript tag manager respects consent state 4.2. Non-consented tags blocked from firing 4.3. Consent state checked on each page load

4.3 Consent Withdrawal

Users can withdraw consent at any time through:

MethodAccessEffect
Cookie settings linkWebsite footerOpens preference center
Preference centerSettings pageGranular cookie control
Browser settingsBrowser controlsClear cookies, block third-party
"Do Not Sell" linkWebsite footer (California)Opt-out of sale/sharing
Email requestprivacy@acmecloud.comManual processing

Upon consent withdrawal:

  • Non-essential cookies are immediately blocked
  • Existing cookies are not automatically deleted (user must clear browser)
  • Consent preference is updated in consent management system
  • Third-party providers receive updated consent signal

4.4 Consent Records

Acme Cloud maintains consent records as required by GDPR Article 7:

Record ElementData StoredRetention
Consent timestampDate and time of consent3 years
Consent versionPolicy version at time of consent3 years
Categories consentedSelected cookie categoriesUntil withdrawal
User identifierAnonymized session/device ID3 years
Method of consentBanner, preference center, etc.3 years
Withdrawal timestampDate and time of withdrawal (if applicable)3 years

Managing Your Cookie Preferences

5.1 Acme Cloud Preference Center

The Acme Cloud cookie preference center allows granular control:

FeatureFunctionality
Category togglesEnable/disable each cookie category
Cookie listView all cookies in each category
Purpose descriptionsUnderstand why each category is used
Third-party linksAccess third-party privacy policies
Save preferencesStore choices across sessions
Reset defaultsReturn to default consent state

Access the preference center at: acmecloud.com/cookie-preferences

5.2 Browser Controls

Most browsers provide cookie management capabilities:

BrowserCookie Settings LocationDNT SupportGPC Support
ChromeSettings > Privacy and Security > CookiesYes (deprecated)Via extension
FirefoxSettings > Privacy & Security > CookiesYesYes (default)
SafariPreferences > PrivacyN/AVia extension
EdgeSettings > Cookies and Site PermissionsYesYes
BraveSettings > ShieldsN/AYes (default)

Browser cookie controls:

ControlEffect
Block all cookiesMay break website functionality
Block third-party cookiesBlocks advertising cookies; functional/analytics may work
Clear cookies on exitRemoves all cookies when browser closes
Delete specific cookiesRemove individual cookies manually
Private/Incognito modeSession cookies only; cleared on exit

5.3 Industry Opt-Out Programs

Users can opt out of targeted advertising through industry programs:

ProgramCoverageOpt-Out URL
Digital Advertising AllianceUS advertisersoptout.aboutads.info
Network Advertising InitiativeUS ad networksoptout.networkadvertising.org
European Digital Advertising AllianceEU advertisersyouronlinechoices.eu
AdChoicesCross-industryyouradchoices.com

5.4 Mobile Device Settings

Mobile users can manage tracking through device settings:

PlatformSettingLocation
iOS 14+App Tracking TransparencySettings > Privacy > Tracking
iOSLimit Ad TrackingSettings > Privacy > Advertising
AndroidOpt out of personalizationSettings > Google > Ads
AndroidReset advertising IDSettings > Google > Ads

Data Processing and Transfer

6.1 Data Collected Through Cookies

Data TypeExamplesPurposeRetention
Device informationBrowser type, OS, screen sizeAnalytics, compatibility2 years
IP addressFull or truncated IPGeolocation, security30 days (full), 2 years (truncated)
Page visitsURLs visited, time on pageAnalytics2 years
ReferrerSource of visitMarketing attribution90 days
InteractionsClicks, scrolls, form submissionsUX optimization2 years
Conversion eventsSign-up, purchase, demo requestMarketing ROI2 years

6.2 Third-Party Data Processing

Third-party cookie providers process data according to their privacy policies:

ProviderPrivacy PolicyPurposeData Shared
Googlepolicies.google.com/privacyAnalytics, advertisingUsage data, device info
Metafacebook.com/privacyAdvertisingConversion events
LinkedInlinkedin.com/legal/privacy-policyAdvertisingConversion events
HubSpothubspot.com/legal/privacy-policyMarketing automationContact data, behavior
Intercomintercom.com/legal/privacyCustomer supportUser data, conversations
Segmentsegment.com/legal/privacyData routingConfigurable
PostHogposthog.com/privacyProduct analyticsUsage events
FullStoryfullstory.com/legal/privacy-policySession replaySession recordings

6.3 International Data Transfers

Cookie data may be transferred internationally:

Transfer RouteMechanismSafeguards
EU to US (Google)EU-US Data Privacy FrameworkDPF certification
EU to US (Meta)SCCs + supplementary measuresAdditional technical measures
EU to US (HubSpot)EU-US Data Privacy FrameworkDPF certification
EU to US (Segment)SCCsContractual protections
UK transfersUK adequacy + IDTAAppropriate safeguards

Cookie Compliance by Website Section

7.1 Marketing Website (acmecloud.com)

Cookie CategoryCookies ActiveConsent Required
Strictly Necessarysession_id, csrf_token, consent_statusNo
Functionallocale, themeYes (EU/UK)
PerformanceGoogle Analytics, Mixpanel, FullStoryYes
TargetingMeta Pixel, LinkedIn, HubSpotYes

7.2 Application Platform (app.acmecloud.com)

Cookie CategoryCookies ActiveConsent Required
Strictly Necessaryauth_token, session_id, csrf_tokenNo
Functionallocale, timezone, dashboard_layoutImplied (logged in)
PerformanceProduct analytics (PostHog)Yes
TargetingNoneN/A

7.3 Documentation (docs.acmecloud.com)

Cookie CategoryCookies ActiveConsent Required
Strictly Necessarysession_idNo
FunctionallocaleYes (EU/UK)
PerformanceGoogle AnalyticsYes
TargetingNoneN/A

Cookie Security

8.1 Cookie Security Attributes

Acme Cloud implements security best practices for cookies:

AttributeImplementationPurpose
SecureAll cookies on HTTPSPrevent transmission over insecure connections
HttpOnlyAuthentication cookiesPrevent JavaScript access (XSS protection)
SameSite=StrictAuthentication cookiesPrevent CSRF attacks
SameSite=LaxFunctional cookiesBalance security and usability
SameSite=NoneThird-party cookies (with Secure)Cross-site functionality
PathScoped to relevant pathsLimit cookie exposure
DomainExplicit domain settingPrevent subdomain access where not needed

8.2 Cookie Encryption

Cookie TypeEncryptionKey Management
Authentication tokensAES-256 encryptionRotating server keys
Session identifiersCryptographically randomGenerated per session
Consent preferencesPlaintext (non-sensitive)N/A
Third-party cookiesPer providerProvider-managed

Framework Mapping Appendix

GDPR and ePrivacy Compliance

RequirementArticle/SectionAcme Cloud ImplementationEvidence
Consent for non-essentialePrivacy Art. 5(3)Cookie consent bannerCMP records
Clear informationGDPR Art. 13Cookie policy, banner textPublished policy
Consent recordsGDPR Art. 7(1)Consent timestamp, versionCMP database
Withdrawal mechanismGDPR Art. 7(3)Preference centerSettings link
Lawful basisGDPR Art. 6Consent, legitimate interestDocumentation
Purpose limitationGDPR Art. 5(1)(b)Category-based consentCookie inventory
Data minimizationGDPR Art. 5(1)(c)Necessary data onlyRegular audits

CCPA/CPRA Compliance

RequirementSectionAcme Cloud ImplementationEvidence
Notice at collection1798.100Cookie policy, bannerPublished policy
"Do Not Sell/Share"1798.120Footer link, preference centerWebsite implementation
Service provider contracts1798.140(ag)Vendor agreementsContracts
Consumer requests1798.105-106Privacy request formRequest records
Sensitive personal info1798.121Consent for sensitive dataConsent records

IAB TCF 2.0 Compliance

TCF RequirementImplementationVerification
CMP registrationRegistered CMP IDIAB CMP list
TC StringGenerated and storedCMP functionality
Vendor consentPer-vendor consent capturedTC String parsing
Purpose consentPurpose-level consentTC String parsing
Publisher restrictionsConfigured restrictionsCMP configuration
Global scopeApplied to EU/UK visitorsGeolocation detection

Related Trust Center documents

privacy policy, terms of service, data retention, security overview, acceptable use

Document revision history

VersionDateAuthorSummary of changes
1.02024-06-01Legal & ComplianceInitial Trust Center publication
2.02025-03-15GRC ProgramSOC 2 Type II alignment refresh; expanded subprocessors
2.52025-09-01Security EngineeringEncryption standards update; ISO 27001 mapping
3.02026-01-15Trust Center ProgramFull procurement-grade expansion; 34-document set

Contact

Acme Cloud, Inc. 1200 Market Street, Suite 400 San Francisco, CA 94103, USA

ChannelEmailUse case
Trust & procurementtrust@acmecloud.comSecurity questionnaires, trust reviews
Securitysecurity@acmecloud.comIncidents, vulnerabilities, control questions
Privacyprivacy@acmecloud.comDSRs, privacy assessments
Legallegal@acmecloud.comContractual, DPA, legal notices
Last updated: January 15, 2026
EthicPages logoEthicPages