Legal
Cookie policy
Every cookie this site can cause to be set, named individually, with what it stores and how long it lasts.
Two groups, and one of them is new
For most of this site’s life the honest answer here was "preferences and nothing else", and this page said so. That stopped being true when a visitor identification tag was added to the marketing pages, so the older and better-sounding sentence has gone rather than being left to age.
The functional cookies are the site’s own: four preference cookies you create by pressing a control, one that exists only because you signed in, and one that exists only because you asked for a demonstration quote. None of them identifies you, none is read by anyone else, and the product would be worse without them.
The tracking cookies are everything the visitor identification tag brings with it, and they exist to work out who you are and which company you work for. Three of them are set by that vendor’s partners on their OWN domains, which means those partners can read them on any other site that uses the same partners. They are listed below with the rest, because a cookie policy that omitted them would be describing a different website.
They are set on the marketing pages only. The market catalogue, a market, position or order page, the embedded interface and the operator portal do not carry the tag, so none of them sets any of these.
There is no consent banner on this site. That is a deliberate decision rather than an oversight, so these cookies are set on arrival rather than after a choice. The opt-out below is the route out of the advertising they feed.
When you visit or log in to our website, cookies and similar technologies may be used by our online data partners or vendors to associate these activities with other personal information they or others have about you, including by association with your email. We (or service providers on our behalf) may then send communications and marketing to these email addresses. You may opt out of receiving this advertising by visiting https://app.retention.com/optout.
Preference cookies
em_theme: your colour mode, "dark" or "light". Read during the server render so the correct palette is in the first paint. One year.
em_accent: the brand accent colour. In an operator deployment this is the operator’s setting rather than a visitor’s; it is exposed here so this site can be shown in a partner’s colours. One year.
em_locale: your interface language. One year.
em_region: which region’s markets are surfaced first. One year.
All four are set by the server when you use the corresponding control, are SameSite=Lax, carry a single short value from a fixed list, and identify nobody. Clearing site data removes them and the interface returns to its defaults.
Visitor identification cookies
These come from the RB2B tag described in the privacy policy. Every name and lifetime below was measured by loading the real script and reading what it actually wrote, not copied from a vendor page.
_reb2buid: a random identifier for your browser. The same value is also kept in your browser’s own storage, so clearing one without the other leaves you identifiable by the survivor. 360 days.
_reb2bsessionID: a random identifier for a single visit. About thirty minutes.
_reb2bgeo: the result of an IP address lookup the tag performs on you. It holds your city, region, country, postal code, timezone and internet provider. 20 days.
_lc2_fpi: an identifier set by LiveIntent, an identity-resolution partner the tag loads a second script from. 400 days. _lc2_fpi_js holds the same value for the browser session, and _li_dcdm_c is a session cookie set by the same partner.
Three more are set on the partners’ own domains rather than on this one: tuid on a.usbrowserspeed.com and uuid on alocdn.com, both 365 days, and lidid on liadm.com, 400 days. Clearing this site’s data does not remove those; clearing your browser’s third-party cookies does.
The opt-out link in the first section is the route out of the advertising these feed. It is the vendor’s, not ours, and it is the only opt-out this page can currently offer you.
The sign-in cookie
parity_session: set only after a successful sign-in to the Parity admin or operator portal. It is HttpOnly, so page scripts cannot read it, and it carries a random token rather than any information about you; the server stores only a hash of that token.
A session lasts at most twelve hours and expires after an hour of inactivity. Signing out clears it, along with predicta_session, the name this cookie was set under before the rebrand, still read so that a deploy does not sign everyone out mid-task, and never written.
The demonstration cookie
parity_demo_session: set by our server the first time you ask for a quote in the self-guided demonstration. It holds a random token, derived from nothing about you, that keeps your demonstration quotes, orders and suggestions apart from other visitors’. It is HttpOnly, so page scripts cannot read it, and SameSite=Lax. The server stores only a hash of the token.
It lasts at most thirty days and ends after seven days without use. Clearing site data ends it early. Hiding the demonstration’s suggestions with their X does not affect it. It is never set in the embedded interface an operator’s customers use.
Not cookies
An embed session token is deliberately not stored in a cookie, in browser storage, or in a URL. It is held for the life of one frame and is meant to outlive nothing.
The self-guided demonstration keeps its illustrative wallet and daily streak in your browser’s own storage rather than in a cookie.
The session clock and reality-check prompt keep two values in per-tab storage: how long you have been actively using the page, and which prompt you last acknowledged. They are discarded when the tab closes and are never sent anywhere.
Hiding the demonstration’s suggestions with their X keeps one more value in per-tab storage, saying they are hidden. It is discarded when the tab closes, so the suggestions return on your next visit, and it is never sent anywhere.
Clearing site data removes all of these.
