Privacy & Legal
Cookies & Consent

Cookies & Consent

This page explains how cookies and consent work on TimberCloud. The authoritative document is the Cookie Policy (opens in a new tab).

The four categories

  • Strictly necessary — authentication, multi-tenancy, security, payment-fraud prevention, and remembering your consent choice. Always on.
  • Preferences — UI choices like light/dark theme.
  • Analytics — understanding how the product is used.
  • Marketing — limited measurement and live chat.

Consent-first

When you first visit, only strictly-necessary cookies are set. Non-essential cookies and trackers (Preferences, Analytics, Marketing) fire only after you opt in through the cookie banner. There are no pre-ticked boxes and no implied consent.

Changing or withdrawing consent

Use the "Cookie preferences" control in the site footer (and in the banner) at any time. Withdrawing is as easy as granting — turning a category off stops the corresponding trackers. Your choice is stored in the tc_consent cookie and recorded in our consent ledger.

What we use

Non-essential trackers include PostHog (product analytics; session replay is disabled pending a DPIA), Vercel Analytics, Cloudflare Insights, Intercom (chat), Supademo, Calendly, per-merchant Google Analytics on storefronts, Google Maps (address autocomplete), and embedded YouTube/Vimeo/Loom videos. Stripe.js loads only on payment pages and is strictly necessary. Google Fonts are self-hosted, so loading a page no longer sends your IP to Google for fonts.

See the Cookie Policy (opens in a new tab) for the full per-cookie and per-tracker tables (name, provider, purpose, duration).

White-label storefronts

On storefronts TimberCloud hosts on a merchant's own domain, the merchant's cookie banner governs where present; otherwise a minimal consent control is shown. TimberCloud and the merchant may be joint controllers for certain analytics — see the Data Processing Addendum (opens in a new tab).

Contact

privacy@timbercloud.com.