Cookie policy
Cookies & analytics at CANNY.
This page is maintained by the CANNY team to describe cookies and analytics behavior that are visible in the app. It is not a legal certification or third-party audit.
What are we talking about?
CANNY uses browser local storage and, when you sign in, a session token to keep you logged in. We do not use third-party advertising cookies and we do not sell your data. The only optional data collection is anonymous product analytics you can turn on or off at Privacy & analytics settings.
Categories
- Strictly necessary. Sign-in session token, CSRF, and the consent record itself (
cookie_consent,cookie_consent_metain localStorage). These are always on because the site cannot function without them. No opt-in is required by law for strictly necessary storage. - Analytics (optional). Only recorded after you click Accept. Anonymous product usage counters that help us understand which sections and listings people use. See examples below.
What we track (examples)
When analytics is enabled, these are the exact events we record. Each event is stamped with the consent snapshot that authorized it (status, categories, version, decision timestamp) so we can audit later that it was captured with your permission.
| Event | Fields recorded | Why |
|---|---|---|
page_view | URL path only (e.g. /directory) | Count which sections are used most so we can prioritize improvements. |
share_preview_opened | Path of the item whose share menu opened | Understand how often visitors consider sharing a listing. |
share_channel_clicked | Path + channel name (facebook, twitter, linkedin, whatsapp, email, copy, native) | See which sharing channels users actually pick so we can keep the useful ones. |
We do not record: your name, email, IP address, device fingerprint, mouse movements, keystrokes, session replays, form contents, or any advertising identifiers. There is no third-party ad network on the site.
How long we keep it
- Consent decision (localStorage): kept on your device until you clear it or change your choice.
- Consent audit log (server): kept per user account so we can prove compliance with your preferences over time.
- Analytics events: aggregated for product decisions. We do not use them to profile individual users.
Change or withdraw your consent
You can change your choice any time from the Privacy & analytics settings page. Declining stops all analytics event recording immediately; existing events continue to exist only as anonymized counters.