Back to home

Cookie & Tracking Technologies Policy

This Cookie & Tracking Technologies Policy explains how Foundry & Grit, LLC (“Foundry & Grit,” “we,” “us,” or “our”) uses cookies, browser storage, and related technologies on foundryandgritllc.com, fossaris.com, and the authenticated Fossaris application. It should be read together with our Privacy Policy.

Effective September 8, 2026

1. What Are Cookies and Similar Technologies?

Cookies are small data files stored by a web browser. Similar technologies, such as local browser storage and recipient-specific links, can remember settings, support application functions, or measure engagement. Not every technology described in this Policy is a cookie.

2. Our Public Websites

At the effective date of this Policy, our review of the Foundry & Grit public website and the public Fossaris website identified no implemented non-essential analytics cookies, advertising cookies, remarketing pixels, session-recording tools, or comparable third-party tracking integrations.

In particular, our current implementation does not include Google Analytics or Google Tag Manager, Meta/Facebook Pixel, Microsoft Clarity, Hotjar, HubSpot tracking, Vercel Analytics or Speed Insights, advertising or remarketing SDKs, or third-party video or chat widgets that were identified as browser tracking technologies.

3. Strictly Necessary Fossaris Cookies

The authenticated Fossaris application uses first-party cookies that are necessary to provide sign-in, authentication, security, session management, onboarding, and related application functions. Blocking these cookies may prevent Fossaris from working properly.

Supabase authentication cookies. Fossaris uses Supabase authentication technology to persist authenticated sessions and support sign-in and multi-factor authentication flows. Cookie names are generated from the applicable Supabase project reference and may be divided into multiple cookie chunks. The underlying SDK may assign a cookie maximum age of up to 400 days. That technical cookie maximum is not the permitted Fossaris authenticated-session duration.

PKCE sign-in verification cookies. Fossaris uses temporary sign-in verification information for PKCE authentication flows. These cookies support secure completion of pending sign-in requests and may be removed earlier through authentication flow cleanup.

fossaris_session. This signed first-party cookie records device classification and sign-in timing so Fossaris can enforce its session policy. The configured session duration is 12 hours for a shared device and 72 hours for a personal device. It is cleared on logout.

fossaris_device_intent. This first-party cookie temporarily remembers the selected device type and intended destination during sign-in. Its configured lifetime is 30 minutes and it is removed after successful confirmation or logout.

fossaris_invite. This first-party cookie temporarily carries encrypted invitation information during employee onboarding. Its configured lifetime is 30 minutes, it is restricted to the onboarding flow, and it is cleared when consumed or on logout.

4. Functional Browser Storage

Fossaris uses limited first-party local browser storage to remember interface preferences. The platform administration interface stores whether the sidebar is expanded or collapsed under the key “fossaris.sidebar.collapsed.” This value is a simple interface preference and is not used for advertising or cross-site tracking. No application expiration is currently assigned to this preference; it remains until replaced or removed through browser controls.

5. Recipient-Specific Communication Link Measurement

Fossaris may create recipient-specific links in SMS communications. When a recipient opens one of these links, Fossaris may record the request and related technical information, such as the request method and user-agent classification, to measure communication engagement and then redirect the recipient to the intended destination.

This measurement is URL-based and server-side; our current implementation does not require a tracking cookie or local browser storage on the recipient’s device for this purpose. Raw click records are subject to a configured 400-day retention sweep. Aggregated or other records may be retained as described in our Privacy Policy, applicable agreements, or as reasonably necessary for reporting, compliance, security, and legal obligations.

6. Categories of Technologies We Currently Use

  • Strictly Necessary · Current use: Yes · Authentication, secure sign-in, sessions, invitations, and application operation.
  • Functional / Preference · Current use: Yes · Remembering limited Fossaris interface preferences.
  • Analytics / Campaign Measurement · Current use: Yes, limited · Recipient-specific communication-link engagement measurement.
  • Advertising / Remarketing · Current use: No verified current use · No advertising or remarketing technology is currently identified in our implementation.

7. No Current Advertising or Cross-Site Tracking Cookies

At the effective date of this Policy, we do not identify the use of advertising or remarketing cookies, cross-site behavioral advertising pixels, fingerprinting technologies, or comparable third-party marketing trackers in the reviewed Foundry & Grit or Fossaris implementations.

8. Your Browser Controls

Most browsers allow you to view, block, or delete cookies and site data. You may also clear local browser storage through browser or site-data controls. Blocking strictly necessary Fossaris cookies may prevent you from signing in or using authenticated features. Removing functional storage may reset interface preferences, such as the sidebar setting.

9. Consent and Future Non-Essential Technologies

We do not use a general cookie-consent banner merely for the strictly necessary technologies described above. Where applicable law requires consent or another choice mechanism for a non-essential technology, we will implement an appropriate control before or in connection with its use.

If we later introduce material non-essential analytics, advertising, remarketing, or similar browser tracking technologies, we will update this Policy and, where required, provide appropriate consent or preference controls.

10. Third-Party Services

Fossaris relies on third-party service providers to operate portions of the service. A provider’s role in our infrastructure does not necessarily mean that the provider sets browser cookies or tracks visitors. This Policy describes browser-side technologies that are implemented or used through our services; our Privacy Policy provides broader information about service providers and processing of personal information.

11. Changes to This Policy

We may update this Policy as our services, technology, or legal obligations change. We will post the updated version with a revised effective date. Material changes may also be communicated through the service or by other appropriate means.

12. Contact Us

Questions about this Policy or our use of cookies and similar technologies may be directed to:

Foundry & Grit, LLC
138 Bryant Street
Gadsden, AL 35901
United States
team [at] foundryandgritllc [dot] com