Legal
Cookie Policy
Digital Empire Holdings LLC · Last updated: August 20, 2026
In plain English: Digital Empire Holdings LLC uses a small number of essential cookies (your consent choice, a free-scan session, and a short-lived security check while you connect a Shopify store) and, only if you say yes on the cookie banner, cookies that help us understand which pages people find useful and catch errors before they become support tickets. We do not run third-party advertising cookies, we do not sell or share cookie data with data brokers or ad networks, and we do not use fingerprinting.
1. How your choice works
The first time you visit, a banner asks you to Accept all, Decline non-essential, or Manage preferences. Essential cookies (marked Necessary in the table below) always run. Analytics, error-tracking and attribution cookies follow the rule below. Once you click Decline, they stop in your browser and our servers also stop recording analytics events and attribution visits for you.
This is the same for every visitor, wherever you are: analytics, error tracking, marketing attribution and A/B-test cookies default to off until you explicitly accept. If you decline, any of these cookies already in your browser are deleted.
Your choice is saved in your browser's local storage and a first-party cookie for one year; you can change it any time with the Cookie settings link at the bottom of every page (it re-opens the banner), by clearing your browser's site data for this domain and reloading, or by emailing support@enforceintel.com.
2. Cookie categories
3. Necessary cookies
These do only what you asked for: remember your cookie choice, apply the free-scan limit and link a scan to its result, and run the security check while you connect a Shopify store. The admin-only cookies in the table are set only when the site operator signs in or connects an integration, never for visitors or customers. Necessary cookies are set by our own domain and cannot be turned off in the consent banner. No consent is required for these under ePrivacy / GDPR because they are "strictly necessary" to deliver the service you explicitly requested.
4. Analytics & error-tracking
We use two analytics vendors, both loaded only after you accept:
- PostHog — product analytics (which pages, which buttons) and masked session replay (all text and input fields are masked before recording). US-hosted. See PostHog's privacy policy.
- Sentry — client-side JavaScript error tracking, so we can find and fix bugs. US-hosted. See Sentry's privacy policy.
Both vendors are listed as sub-processors on every per-product sub-processors page and in the DPA (/dpa).
5. Marketing attribution (first-party, no ad targeting)
When you click a UTM-tagged or ?ref= partner link (e.g. from a blog post, referral partner, or one of our emails) and you have accepted cookies, we set a first-party cookie (de_utm_sid / de_ref) so we can credit the referring source on signup. Without Accept, no attribution cookie is set and no stored campaign history is used; if the page you check out or sign up from was itself opened with campaign tags (utm_*), those tags and the referring page are sent with that request. On the PixelProof free scanner, campaign tags in the link you arrived on are sent with the email signup form on that page; only after you accept are they also kept in that browser tab's session storage (pp_utm) so a reload keeps them. After you accept, pages that record first-touch campaign tags also keep them in that tab's session storage under sierra12:utm_* keys (plus a sierra12:utm-beacon:* marker so each page reports a visit once). Decline removes pp_utm, every sierra12:utm* key and pp_referral_code. We do not use this data for ad retargeting or share it with any ad network. If our affiliate program is active, Rewardful's script loads only after you accept and sets its referral cookie (rewardful.referral, 60 days) when you arrive through an affiliate link, so the referring affiliate can be credited. On PixelProof, a ?ref= invite code is also kept in your browser's local storage for up to 30 days so a later free-scan signup can credit the inviter, again only after you accept; Decline removes it.
6. What we do not use
- No third-party advertising cookies (no Meta Pixel, no Google Ads remarketing tag, no LinkedIn Insight Tag on the app itself).
- No data-broker pixels or tag-manager containers loaded on our own site.
- No device fingerprinting or cross-site tracking.
- No sale or sharing of personal information as defined by CCPA / CPRA.
Bing UET (Microsoft Advertising conversion tag) is conditionally loaded from the site layout only when the site owner has configured it via environment variable (currently not live in production), and even then only after you click Accept on the cookie banner. If it goes live, its cookies will be listed in the table above.
The onboarding-call page (/book/onboarding) can show a Cal.com booking calendar. It is a third-party embed: it loads only after you accept cookies or click "Load the booking calendar", and Cal.com then sets its own cookies under Cal.com's privacy policy. You can always book through the direct cal.com link instead.
7. Per-product cookie disclosures
Each product page ships its own product-specific cookie disclosure, since the exact cookie names / vendors overlap but the product context differs:
8. Contact
Questions or opt-out requests: support@enforceintel.com. The trust hub (/trust) links every legal document.
This portfolio-level policy is versioned; the per-product cookie pages remain the detailed source of truth for each product surface. Where this document and a per-product cookie page conflict, the per-product page controls for that product.