In plain English: PixelProof uses a small number of essential cookies (your consent choice, a free-scan session, and a short-lived security check while you connect a Shopify store) and, only if you say yes on the cookie banner, cookies that help us understand which pages people find useful and catch errors before they become support tickets. We do not run third-party advertising cookies, and we do not sell or share cookie data with data brokers or ad networks.
1. How your choice works
The first time you visit, a banner asks you to Accept all, Decline non-essential, or Manage preferences. Essential cookies (listed in the table below) always run. Analytics and error-tracking cookies only run if you accept. This is the same for every visitor, wherever you are: analytics, error tracking, attribution and A/B-test cookies default to off until you explicitly accept, and declining deletes any that are already set. Your choice is saved in your browser's local storage and a first-party cookie for one year; you can change it any time by clearing your browser's site data for this domain and reloading.
2. Cookie categories
| Cookie | Category | What it does | Duration | Runs before consent? |
|---|---|---|---|---|
de_session | Essential (admin only) | Site-operator admin sign-in only. Never set for visitors or customers. | 30 days | Only when the site operator signs in. |
de_cookie_consent | Essential | Remembers your Accept/Decline choice from the cookie banner so we don't ask again every page. | 1 year | Yes, this is the choice itself. |
pp_free_scan_sid | Essential | Free scan only: random ID (HttpOnly) that applies the free-scan limit and links your scan to its result page. | 1 hour | Yes, only if you run a free scan. |
pp_shopify_oauth_state | Essential | Security check (OAuth state, HttpOnly) while you connect a Shopify store. | 10 minutes | Yes, only while you connect a Shopify store. |
nps_dismiss_pixelproof | Preferences | Remembers that you dismissed the one-question feedback prompt so it is not shown again. | 90 days | Only if you dismiss the prompt. |
| CSP nonce header (not a cookie, listed for transparency) | Essential | Per-request Content-Security-Policy nonce that lets our own scripts run and blocks injected ones. Never stored client-side. | Single request | Yes. |
de_utm_sid | Attribution | First-party visit ID that links a UTM-tagged landing page to a later signup or checkout, so we can credit the source. Never shared with ad networks. | 90 days | No, only after you Accept. Deleted when you Decline. |
de_ab_vid | Experiments | Random A/B-test visitor ID so a headline test shows you the same version on every visit. Before you accept, a one-page-load value is used and never stored. | 1 year | No, only after you Accept. Deleted when you Decline. |
de_exp_assignments | Experiments | Which test variant you were shown (variant names only, no ID). | 1 year | No, only after you Accept. Deleted when you Decline. |
de_ref | Attribution | Partner referral code from a ?ref= link, so the referring partner can be credited. | 7 days | No, only after you Accept. Deleted when you Decline. |
rewardful.referral | Attribution | Rewardful affiliate referral ID, set by Rewardful's script when you arrive through an affiliate link, only if our affiliate program is active. | 60 days | No, the script loads only after you Accept. |
ph_* (PostHog) | Analytics | Anonymous/pseudonymous device ID for pageview and product-usage analytics, plus masked session replay (all typed text and inputs are masked, never recorded in plaintext). | Up to 1 year | No, only after you Accept. |
sentry-* (local storage, not a cookie) | Analytics / error tracking | Client-side JS error reports so we can find and fix bugs. No page content or form values are captured. | Session | No, only after you Accept. |
3. Rewardful (affiliate tracking)
If our affiliate program is active, Rewardful's script loads only after you accept and sets its referral cookie (rewardful.referral, 60 days, our program's cookie window) when you arrive through an affiliate link, so the referring affiliate can be credited when you sign up or buy. Until you accept, or if you decline, the Rewardful script does not load and sets no cookie.
4. Third-party cookie policies
5. Your choices
Change your decision any time with the Cookie settings link at the bottom of every page (it re-opens the cookie banner), or via your browser's site-settings (clear cookies/site data for this domain and reload to see the banner again), or block cookies entirely in your browser settings. If you block essential cookies, the banner cannot remember your choice and a free scan or Shopify connection may not complete.
6. Legal basis for each category
Essential cookies run under GDPR Art. 6(1)(b) (necessary to provide the scan or store connection you asked for) and are outside the scope of ePrivacy consent requirements for exactly that reason. Analytics and error-tracking cookies run under GDPR Art. 6(1)(a), your freely-given, specific, informed consent via the banner, which is why they default off for every visitor until you actively accept, and why declining costs you nothing: every core feature works identically either way.
7. Browser-level controls
You can also block or clear cookies at the browser level instead of (or in addition to) using our banner: Chrome, Settings → Privacy and security → Cookies; Safari, Settings → Privacy → Manage Website Data; Firefox, Settings → Privacy & Security → Cookies and Site Data. Blocking all cookies browser-wide means our banner cannot remember your choice, and it will log you out of many other sites; that's a browser-level tradeoff, not something our banner controls.
8. Related pages
9. Contact
Questions about this policy: support@pixeluptime.com.
Digital Empire Holdings LLC, 30 N Gould St Ste N, Sheridan WY 82801