Archived version
Cookie Policy
Version 2.1 · Effective 2026-07-26 · jamcrew-cookies-v2.1
SHA-256 31f3a477ce238fa60c8986b1cf43e5eaddca1660485682853ff9930ae570332e
This page is a permanent record. Its words are frozen at the hash above and will never change. Later revisions are published as new versions at their own addresses.
For the version in force today, read Cookie Policy.
Cookie Policy
Version 2.1 · Effective July 26, 2026
Cookies are small files a website stores in your browser. Other technologies do the same job with different plumbing: local storage, session storage, and small scripts that report back to a service we use. This policy covers all of them, on the JamCrew marketing site and inside workspace subdomains.
It describes what runs today, not what we would like to run. If something here does not match what your browser shows you, that is a bug and we want to hear about it.
You can change your choices at any time.
The short version
- Signing in, keeping the site secure, and remembering your privacy choices need cookies. Those always run.
- Everything else falls into three groups you control: measurement, diagnostics, and session replay.
- We run no advertising cookies and no ad targeting. Not in any region, not for anyone, not ever.
- In the EEA, the UK, or Switzerland, or if we cannot tell where you are, nothing optional loads until you allow it, and you get a banner asking.
- Everywhere else, measurement and diagnostics start on and you switch them off from Cookie Settings in the footer.
- Global Privacy Control turns all three off in every region, and it overrides a saved yes.
Where you are changes what happens
When a page is requested, our edge server reads the country the request came from and sorts it into one of three buckets. It writes that answer to the jc_geo cookie so the rest of the page can act on it.
The EEA, the UK, and Switzerland. The 27 EU member states plus Iceland, Liechtenstein, and Norway, plus the United Kingdom and Switzerland. Nothing optional loads until you say yes. You see a banner with Allow, Deny, and Choose, and Allow and Deny are the same size and the same style, because refusing should not be harder than agreeing.
Anywhere we cannot read a country. Missing, malformed, or a placeholder value. Treated exactly like the regulated list above. If we are unsure, we ask.
Everywhere else. No banner. Measurement and diagnostics start on under a notice and opt-out model, and this page is the notice. Session replay starts on only for a confirmed United States visit. Cookie Settings in the footer is always there, in every region, and switching a category off takes effect immediately.
Two things hold in every region regardless of what you choose. Advertising signals are denied, always. And Google Analytics never loads at all for an EEA, UK, Swiss, or unidentified visitor, even if that visitor allows measurement.
These are defaults, not verdicts. The moment you make a choice, it replaces the regional default and we stop recomputing one for you.
Strictly necessary · always on
These run in every region with no toggle, because without them the product does not work. They are not used for analytics, profiling, or advertising.
Sign-in is handled by Clerk. You can sign in with Google, Apple, or Microsoft, and if you do, that provider knows you signed in to JamCrew. Subscription checkout and billing management run on Stripe's own pages, so any cookie set there is Stripe's and is governed by Stripe's policy, not this one.
Measurement that has no toggle
Two Vercel tools are mounted on every page in every region, and they are not part of any consent category. We are naming them rather than implying they are gated. They set no cookies and store nothing in your browser, so there is nothing for a toggle to switch off.
Measurement · you control this
How many people use JamCrew, which pages they open, and where they give up. Two services, both loaded when your browser goes idle rather than while the page is still rendering.
Google Analytics 4
- It never loads for an EEA, UK, Swiss, or unidentified visitor. Not by default, and not after that visitor allows measurement.
- Ad storage, ad user data, and ad personalization are set to denied in every region, for every visitor, whatever your stored preferences say. Google Signals and ad personalization signals are off. There is no state of the world in which we grant them.
- We send page views by hand after cutting the address back to the site and the path. Query strings and fragments never reach Google.
- Event parameters pass through a sanitizer first. Email addresses are replaced, and keys carrying contact, identity, financial, location, or credential material are dropped.
- We use Google Analytics as a service provider for measurement. We do not use it to build advertising audiences.
PostHog product analytics
- It loads when you allow measurement, session replay, or both.
- Person profiles are created for signed-in users only. Surveys are off. Web vitals collection is off, because Vercel Speed Insights already does that and doing it twice is duplicate work on your device.
- Every event passes the same sanitizer: email addresses replaced, addresses cut back to site and path, and sensitive keys dropped.
- Errors are never sent to PostHog. Errors belong to Sentry, under diagnostics.
Diagnostics · you control this
Error monitoring, so a crash on your screen becomes a bug report we can act on instead of a mystery.
- Sentry does not start at all until diagnostics is permitted. If you allow it later, monitoring begins from that moment, without a reload.
- Personal information is not attached to reports by default, and every report and breadcrumb passes the sanitizer described above.
- About a fifth of page loads are sampled for performance timing.
- Sentry records a short replay when an error happens. Sentry never records a replay of an ordinary session, but when the site throws an error it captures the moments around that error so we can see what broke. The code that does this is fetched from Sentry only when diagnostics is permitted. If you switch diagnostics off, none of it runs.
Session replay · you control this
Session replay reconstructs what a page looked like and how it was used, so we can watch a broken flow happen instead of guessing at it. It is provided by PostHog. It is the most invasive thing we collect, so it gets its own switch: allowing measurement never turns it on.
It runs on the marketing site as well as inside the app. We are saying that plainly rather than burying it, because a recording you did not expect is worse than one you did.
What it records, and what it does not
- Text is masked by default. So are input fields, and so are element attributes. A recording shows the shape of the page and where things were clicked, not the words on it.
- Console output is not recorded. Network request headers and bodies are not recorded, and captured request bodies are dropped outright. Fonts are not collected. Cross-origin frames are not recorded.
- Replay snapshots are not run through the payload sanitizer used for other events. A snapshot is a nested page tree far past what that sanitizer can handle, and scrubbing it would silently corrupt the recording. Privacy is enforced at capture time instead, by the masking above.
- We use recordings to fix bugs and to find the places where the product confuses people. We do not use them for advertising.
When it starts
Where replay is allowed and where it stays off until you say yes is the Session replay column of the defaults table above. Allowed is not the same as running: in every region, and whether replay is on by default or because you switched it on, recording waits for your first interaction with the page, meaning a pointer press, a touch, a key press, or a scroll, so landing on a page and leaving records nothing.
Where it never runs
Whatever your stored choice says, replay is blocked on sign-in, sign-up, login, settings, billing, payroll, payments, invoices, onboarding, and account pages. Credentials, money, and personal settings are not worth reconstructing. The check runs again on every navigation, so an active recording stops the moment you walk into one of those pages and picks up only if you leave.
If you want recordings of your sessions deleted, email privacy@jamcrew.io (mailto:privacy@jamcrew.io).
Advertising · none of it
JamCrew runs no advertising cookies, no remarketing tags, and no ad network pixels. The three Google advertising consent signals are sent as denied in every region, for every visitor, regardless of what anyone chose, and Google Signals is switched off. Earlier versions of this page listed Marketing and Personalization categories. Those categories described something that did not exist, and they are gone.
Global Privacy Control
Global Privacy Control is a browser-level opt-out. Some browsers send it on their own, some need an extension, and it travels with every request you make. We read it two ways, from the Sec-GPC request header and from navigator.globalPrivacyControl, and either one counts.
We treat it as an absolute opt-out.
- Every optional category is off, in every region. Not just California, not just the EU.
- It overrides a stored allow. If you allowed measurement last month and turn on Global Privacy Control today, measurement is off today. We override the record rather than deleting it, so your earlier choice comes back if you turn the signal off.
- You will not see a banner. You already told us what you want, and asking again would be noise.
- The preferences panel shows the switches locked, and explains why.
- If you had no stored record, we write one marked as set by Global Privacy Control, so the refusal leaves a trail.
More about the signal at globalprivacycontrol.org (https://globalprivacycontrol.org/).
Do Not Track
We do not act on the Do Not Track browser header. No agreed standard for responding to it ever arrived, browsers send it inconsistently, and no law gives it force. We would rather say that here than let you assume a signal is working when it is not. Global Privacy Control is the signal that carries legal weight, and it is the one we honor, as described above.
Changing your mind
On this site. Use the Cookie Settings link in the footer of every page, or here. The panel has four rows: Essential, which is always on and has no switch, then one switch each for Measurement, Diagnostics, and Session replay. You can Allow all, Deny all, or save exactly the combination you want. If you have never chosen, every optional switch starts off, because a pre-ticked box is not a choice.
What happens when you switch something off. It takes effect immediately, with no reload. The script stops, and whatever that service wrote to your browser is erased across every scope we could have written it to. Google Analytics gets a consent update to denied, a disable flag for its measurement id, and its _ga and _ga_* cookies deleted. PostHog is told to stop recording and stop capturing, and every ph_, __ph_, and posthog key is cleared from cookies, local storage, and session storage. One PostHog marker is kept on purpose: it is the thing that stops an already-loaded script from restarting itself.
What switching off cannot do. It stops future collection. It does not reach back and erase what was already collected and sent while the category was on. To ask for that, email privacy@jamcrew.io (mailto:privacy@jamcrew.io).
How long it sticks. Your choice is stored in the jc_consent cookie for 180 days. If we add a category, we ask again rather than assuming your old answer covers it.
Controls in your browser
- Every major browser can block or delete cookies from its settings, and can clear site data for a single site.
- Clearing site data deletes jc_consent along with everything else, so your saved answer goes with it. In a region with a banner you will be asked again. Elsewhere you fall back to the regional default in the table above.
- Blocking the strictly necessary cookies will break sign-in. There is no way around that.
- Google publishes a Google Analytics opt-out browser add-on (https://tools.google.com/dlpage/gaoptout) that works across every site, not just this one.
Changes to this policy
Every version of this policy carries a version number and an effective date, both at the top of the page. We update it when we add or remove a tracker, when a category changes, or when a provider changes what it does. If we introduce a new category, we ask for your choice again instead of folding it into an existing one.
Contact
Questions about anything on this page, or a correction to make, go to privacy@jamcrew.io (mailto:privacy@jamcrew.io). For the wider picture of what we collect and why, see the Privacy Policy (/privacy).
name Name
provider Set by
duration Lasts
purpose What it holds
jc_consent JamCrew 180 days Your answer for each optional category, when you gave it, how it was recorded (banner, preferences panel, regional default, or Global Privacy Control), and the country and region we resolved at the time.
jc_geo JamCrew 24 hours A coarse two-letter country code and the region it maps to, written as US.unregulated, DE.regulated, or XX.unknown. Readable by JavaScript on purpose: the consent layer runs in your browser and has to read it.
jc_gpc JamCrew 24 hours 1 or 0, recording whether your request arrived with a Global Privacy Control signal.
__session, __client_uat, and other names beginning __clerk Clerk Set by Clerk. Session length or short lived. Keeps you signed in and ties this browser to your account across jamcrew.io and your workspace subdomain.
__stripe_mid, __stripe_sid Stripe Set by Stripe. The first is long lived, the second lasts minutes. Fraud prevention on payment forms. Stripe.js loads only on pages that actually render a card field, such as paying an invoice in the client portal.
Google sign-in (One Tap and FedCM) Google, through Clerk Set by Google Offers your Google account as a sign-in option. It loads on sign-in pages and inside the app, never on marketing pages.
_ga, _ga_<measurement id> Google Analytics 4 Set by Google. Up to two years. A randomly generated browser identifier and session state, so page views can be grouped into visits. Written on .jamcrew.io with SameSite=Lax and Secure.
Cookies and browser storage starting with ph_, __ph_, or posthog PostHog Set by PostHog. The main cookie is roughly a year. A browser and session identifier, plus which pages you opened and which elements you used. Stored in cookies, local storage, and session storage.
Vercel Analytics Vercel No cookie Counts page views and referrers. Sets no cookies and stores no identifier in your browser.
Vercel Speed Insights Vercel No cookie Measures how fast pages load and respond. Sets no cookies and stores no identifier in your browser.
Sentry error monitoring Sentry No cookie Sends a report when the site throws an error: the error, the page it happened on, and the browser it happened in. It sets no cookies.
where Where you are
measurement Measurement
diagnostics Diagnostics
replay Session replay
banner Banner
United States On On On, after your first interaction No
Other countries outside the EEA, UK, and Switzerland On On Off No
EEA, United Kingdom, Switzerland Off until you allow it Off until you allow it Off until you allow it Yes
We cannot tell where you are Off until you allow it Off until you allow it Off until you allow it Yes
Global Privacy Control on, any region Off Off Off No