Cookie policy

Last updated: 1 September 2026

This Cookie Policy explains how Tuned Research LLC (“tuned”, “we”) uses cookies and similar local-storage technologies on tunedresearch.com, and the choices you have. Read it alongside our Privacy Policy.

What cookies are

Cookies and local storage are small pieces of data a website saves in your browser. Some are needed for the site to work; others are used for measurement and can be switched off at any time.

How we use them

We group what we use into three categories:

The Google tag (gtag.js) for Google Analytics 4 and Google Ads also runs by default. It sets the Google cookies listed below and shares your browsing session with Google — pages viewed, product/cart/checkout actions, and the page address including any Google ad-click identifier — for analytics and advertising measurement. Other than the Meta Pixel and Google tag described above, we do not load third-party advertising or social-media trackers, and we do not sell your personal information. Website chat is first-party and stored in Supabase; when you verify email continuity, Customer.io processes our functional reply notifications and your emailed replies arrive in our own Proton mailbox, from where our signed first-party service files them into the same thread. No third-party chat SDK is loaded. The Meta Pixel uses the first-party _fbp/_fbc identifiers listed below; both the Meta Pixel and the Google tag are disabled and their identifiers removed when you choose “Necessary only”.

Cookies we use

NameCategoryPurposeRetention
tuned_consent, tuned_consent_sessionEssentialRemembers your explicit Analytics or Necessary-only choice. A host-only session cookie mirrors only that choice when an in-app browser cannot retain local storage; it contains no identity or attribution data.Local storage · 6 months; cookie fallback · current browser session
tuned_age_okEssentialRemembers your 21+ age confirmation. A host-only session cookie mirrors the same 1 flag so constrained in-app browsers do not repeat the gate while you navigate.Local storage · persistent; cookie fallback · current browser session
tuned_internal_telemetry_optoutPreferenceRemembers that anonymous service telemetry is disabled. It is a choice flag, not a visitor identifier. A host-only session cookie mirrors the flag when browser storage is unavailable.Local storage · until you enable it or clear site data; cookie fallback · current browser session
tuned_internal_source_group, tuned_internal_campaign_groupAnonymous service measurementKeeps only broad, allowlisted source and campaign categories while you move between pages. No click ID, URL, timestamp, random value, or visitor/session identifier is stored.Session storage · current tab only
Cart storageEssentialKeeps the items in your cart between pages.Local storage · persistent
tuned_support_tokenCustomer supportOpaque access key that restores the first-party support conversation in this browser. The key contains no name, email, message text, or advertising identifier.Local storage · up to 30 days, or until site data is cleared
crisp-client/*Customer supportHistorical only. A cookie created by a previous website-chat session may remain until it expires, but the disabled storefront does not read it or contact Crisp.Cookie · normally 6 months, renewed when the activated chat returns; conversation records may be retained separately
_dcidAnalyticsAnonymous first-party visitor ID for performance measurement.Cookie · up to 2 years
_fbpAnalyticsFirst-party browser identifier used by the Meta Pixel and our server-side Meta measurement connection.Cookie · up to 2 years
_fbcAnalyticsPreserves the Meta click identifier and its first-visit timestamp after a Meta ad visit.Cookie · up to 90 days
_ga, _ga_5X3GZ2VDZ4AnalyticsGoogle Analytics visitor and session identifiers set by the Google tag.Cookie · up to 2 years
_gcl_au, _gcl_aw, _gcl_gbAnalyticsGoogle Ads conversion-linker identifiers that connect a Google ad click to later store actions.Cookie · up to 90 days
_tt_sid, _tt_attrAnalyticsSession and referral context for measurement.Session / local storage
_tt_landing_metaLimited Meta attributionStores only a Meta click identifier and first-seen time from an earlier consent-limited ad landing so a same-tab checkout could retain campaign attribution. No longer created for new visits; cleared by Necessary-only or GPC.Session storage · current tab only

Tuned's internal telemetry stores hourly and daily counters only—there is no raw event or page-instance table. Payloads contain strict categories such as page group, privacy mode, broad source/device group, product SKU for commerce actions, allowlisted campaign group, and dwell, scroll, performance, error or result buckets. Error diagnostics are limited to allowlisted origin, coarse error-type, media-type, and optional-tag-state categories. The browser discards raw error messages, filenames and paths, stack traces, browser versions, raw fbclid, gclid and other click IDs, full URLs/query strings/referrers, cookies, browser-storage identifiers, full IP addresses/user-agent strings, customer/order identifiers, and free-form text. Only the broad source and allowlisted campaign categories may remain in session storage for the current tab, and neither value identifies a visitor. The application stores no request IP or user-agent; only a short-lived hashed IP bucket is used to rate-limit abuse. Vercel and Supabase process the service, but these counters are not joined to customer, checkout, order or advertising data, are not used for advertising attribution, audiences, or campaign optimization, and are not sent to an advertising platform. Hourly counters are retained for 90 days and daily counters for no more than 13 months.

Your choices

Analytics and advertising measurement runs by default when you visit Tuned. Choosing Necessary only — on the cookie banner or at any time through Cookie preferences / Do Not Sell or Share in the footer — disables advertising and user-identifying analytics, stops optional analytics and advertising events, and removes _dcid, _fbp, _fbc, _ga, _ga_5X3GZ2VDZ4, _gcl_au, _gcl_aw, _gcl_gb, _tt_sid, _tt_attr, and _tt_landing_meta. That same control is how you opt out of the “sale” or “sharing” of personal information under US state privacy laws such as the CCPA/CPRA. Tuned continues to collect anonymous, aggregate service-performance and storefront-interaction statistics that are not used for advertising or linked to a customer. You can separately ; this immediately clears the current tab's coarse source/campaign context and also suppresses Vercel Web Analytics on future page views. A non-identifying session preference fallback preserves that choice during same-origin navigation when DOM storage is unavailable. Re-enable it with the same control or clear site data.

Global Privacy Control

If your browser sends a Global Privacy Control (GPC) signal, we honour it automatically: we treat it as “Necessary only”, set no analytics cookies, suppress anonymous aggregate service measurement, and block analytics or advertising destination calls from our first-party measurement hub.

Questions

Email support@tunedresearch.com with any questions about this policy.