Skip to main content

Legal

Cookie Policy

Digital Empire Holdings LLC · Last updated: August 20, 2026

In plain English: Digital Empire Holdings LLC uses a small number of essential cookies (your consent choice, a free-scan session, and a short-lived security check while you connect a Shopify store) and, only if you say yes on the cookie banner, cookies that help us understand which pages people find useful and catch errors before they become support tickets. We do not run third-party advertising cookies, we do not sell or share cookie data with data brokers or ad networks, and we do not use fingerprinting.

1. How your choice works

The first time you visit, a banner asks you to Accept all, Decline non-essential, or Manage preferences. Essential cookies (marked Necessary in the table below) always run. Analytics, error-tracking and attribution cookies follow the rule below. Once you click Decline, they stop in your browser and our servers also stop recording analytics events and attribution visits for you.

This is the same for every visitor, wherever you are: analytics, error tracking, marketing attribution and A/B-test cookies default to off until you explicitly accept. If you decline, any of these cookies already in your browser are deleted.

Your choice is saved in your browser's local storage and a first-party cookie for one year; you can change it any time with the Cookie settings link at the bottom of every page (it re-opens the banner), by clearing your browser's site data for this domain and reloading, or by emailing support@enforceintel.com.

2. Cookie categories

Cookie
Category
Purpose
Expiry
de_cookie_consent
Necessary
Records your cookie choice (accepted / declined) so the banner does not re-appear and our servers can honor it.
1 year
pp_free_scan_sid
Necessary
PixelProof free scan only: random ID that applies the free-scan limit and links your scan to its result page. HttpOnly.
1 hour
pp_shopify_oauth_state
Necessary
Security check while you connect a Shopify store (OAuth state). HttpOnly.
10 minutes
de_session, de_challenge, de_slack_stash, mc_oauth_state
Necessary
Site-operator admin sign-in (passkey) and integration setup only. Never set for visitors or customers.
de_challenge 5 minutes, mc_oauth_state 10 minutes, de_slack_stash 15 minutes, de_session 30 days
nps_dismiss_<product>
Preferences
Remembers that you dismissed the one-question feedback prompt so it is not shown again.
90 days
ph_*
Analytics
PostHog product analytics + masked session replay. Set only after Accept.
1 year
Sentry (no cookie)
Analytics
Client-side error tracking. The script loads only after Accept and sets no cookie.
n/a
de_ab_vid
Analytics
Random A/B-test visitor ID so a page test shows you the same version on every visit. Set only after Accept; deleted on Decline. Before you accept, a one-page-load value is used and never stored.
1 year
de_exp_assignments
Analytics
Which call-to-action test variant you were shown (variant letters only, no ID). Set only after Accept; deleted on Decline.
1 year
de_utm_sid
Marketing attribution
First-party, HttpOnly visit ID linking a campaign (UTM) landing page to a later signup or checkout. Set only after Accept; deleted on Decline.
90 days
de_ref
Marketing attribution
Partner referral code from a ?ref= link, so the referring partner can be credited. Set only after Accept; deleted on Decline.
7 days
rewardful.referral
Marketing attribution
Rewardful affiliate referral ID, set by the Rewardful script when you arrive through an affiliate link (only if our affiliate program is active). The script loads only after Accept.
60 days (our program cookie window)
Cal.com (booking calendar)
Third-party embed
Only on /book/onboarding. The Cal.com booking calendar loads only after you accept cookies or click "Load the booking calendar"; Cal.com then sets its own cookies to run it (see cal.com/privacy). Until then a direct link to the same booking page on cal.com is shown instead.
Set by Cal.com

3. Necessary cookies

These do only what you asked for: remember your cookie choice, apply the free-scan limit and link a scan to its result, and run the security check while you connect a Shopify store. The admin-only cookies in the table are set only when the site operator signs in or connects an integration, never for visitors or customers. Necessary cookies are set by our own domain and cannot be turned off in the consent banner. No consent is required for these under ePrivacy / GDPR because they are "strictly necessary" to deliver the service you explicitly requested.

4. Analytics & error-tracking

We use two analytics vendors, both loaded only after you accept:

Both vendors are listed as sub-processors on every per-product sub-processors page and in the DPA (/dpa).

5. Marketing attribution (first-party, no ad targeting)

When you click a UTM-tagged or ?ref= partner link (e.g. from a blog post, referral partner, or one of our emails) and you have accepted cookies, we set a first-party cookie (de_utm_sid / de_ref) so we can credit the referring source on signup. Without Accept, no attribution cookie is set and no stored campaign history is used; if the page you check out or sign up from was itself opened with campaign tags (utm_*), those tags and the referring page are sent with that request. On the PixelProof free scanner, campaign tags in the link you arrived on are sent with the email signup form on that page; only after you accept are they also kept in that browser tab's session storage (pp_utm) so a reload keeps them. After you accept, pages that record first-touch campaign tags also keep them in that tab's session storage under sierra12:utm_* keys (plus a sierra12:utm-beacon:* marker so each page reports a visit once). Decline removes pp_utm, every sierra12:utm* key and pp_referral_code. We do not use this data for ad retargeting or share it with any ad network. If our affiliate program is active, Rewardful's script loads only after you accept and sets its referral cookie (rewardful.referral, 60 days) when you arrive through an affiliate link, so the referring affiliate can be credited. On PixelProof, a ?ref= invite code is also kept in your browser's local storage for up to 30 days so a later free-scan signup can credit the inviter, again only after you accept; Decline removes it.

6. What we do not use

Bing UET (Microsoft Advertising conversion tag) is conditionally loaded from the site layout only when the site owner has configured it via environment variable (currently not live in production), and even then only after you click Accept on the cookie banner. If it goes live, its cookies will be listed in the table above.

The onboarding-call page (/book/onboarding) can show a Cal.com booking calendar. It is a third-party embed: it loads only after you accept cookies or click "Load the booking calendar", and Cal.com then sets its own cookies under Cal.com's privacy policy. You can always book through the direct cal.com link instead.

7. Per-product cookie disclosures

Each product page ships its own product-specific cookie disclosure, since the exact cookie names / vendors overlap but the product context differs:

8. Contact

Questions or opt-out requests: support@enforceintel.com. The trust hub (/trust) links every legal document.

This portfolio-level policy is versioned; the per-product cookie pages remain the detailed source of truth for each product surface. Where this document and a per-product cookie page conflict, the per-product page controls for that product.

Cookie settings