Cookie policy
This Cookie Policy explains how Tuned Research LLC (“tuned”, “we”) uses cookies and similar local-storage technologies on tunedresearch.com, and the choices you have. Read it alongside our Privacy Policy.
What cookies are
Cookies and local storage are small pieces of data a website saves in your browser. Some are needed for the site to work; others are used for measurement and can be switched off at any time.
How we use them
We group what we use into three categories:
- Essential — required to run the store: keeping items in your cart, remembering your age confirmation, securing checkout, and remembering your cookie choice. These are always on and cannot be switched off, because the site cannot function without them.
- Customer support — Tuned's first-party website chat stores an opaque conversation key in local storage only after you send a message. It restores that thread in the same browser and normally expires after 30 days. The storefront does not load a third-party chat SDK. If you verify an email address, support can continue in the same thread by email.
- Anonymous service measurement — cookie-free page counts through Vercel Web Analytics plus first-party, aggregate storefront telemetry. These signals use no persistent browser ID and send no raw advertising click ID. They show broad funnel stages, exit/scroll/time buckets, performance buckets, and allowlisted error categories so we can operate and improve the store. Only a broad source group and an allowlisted campaign group may remain in session storage while you navigate within the current tab.
- Analytics and advertising measurement — first-party identifiers and detailed browser usage events that help us understand the customer journey, including the Meta Pixel. These run by default and share a deduplication identifier with our server-side delivery so Meta counts each action once. Choosing “Necessary only” disables this category, stops later usage events, and removes its identifiers.
The Google tag (gtag.js) for Google Analytics 4 and Google Ads also runs by default. It sets the Google cookies listed below and shares your browsing session with Google — pages viewed, product/cart/checkout actions, and the page address including any Google ad-click identifier — for analytics and advertising measurement. Other than the Meta Pixel and Google tag described above, we do not load third-party advertising or social-media trackers, and we do not sell your personal information. Website chat is first-party and stored in Supabase; when you verify email continuity, Customer.io processes our functional reply notifications and your emailed replies arrive in our own Proton mailbox, from where our signed first-party service files them into the same thread. No third-party chat SDK is loaded. The Meta Pixel uses the first-party _fbp/_fbc identifiers listed below; both the Meta Pixel and the Google tag are disabled and their identifiers removed when you choose “Necessary only”.
Cookies we use
| Name | Category | Purpose | Retention |
|---|---|---|---|
tuned_consent, tuned_consent_session | Essential | Remembers your explicit Analytics or Necessary-only choice. A host-only session cookie mirrors only that choice when an in-app browser cannot retain local storage; it contains no identity or attribution data. | Local storage · 6 months; cookie fallback · current browser session |
tuned_age_ok | Essential | Remembers your 21+ age confirmation. A host-only session cookie mirrors the same 1 flag so constrained in-app browsers do not repeat the gate while you navigate. | Local storage · persistent; cookie fallback · current browser session |
tuned_internal_telemetry_optout | Preference | Remembers that anonymous service telemetry is disabled. It is a choice flag, not a visitor identifier. A host-only session cookie mirrors the flag when browser storage is unavailable. | Local storage · until you enable it or clear site data; cookie fallback · current browser session |
tuned_internal_source_group, tuned_internal_campaign_group | Anonymous service measurement | Keeps only broad, allowlisted source and campaign categories while you move between pages. No click ID, URL, timestamp, random value, or visitor/session identifier is stored. | Session storage · current tab only |
| Cart storage | Essential | Keeps the items in your cart between pages. | Local storage · persistent |
tuned_support_token | Customer support | Opaque access key that restores the first-party support conversation in this browser. The key contains no name, email, message text, or advertising identifier. | Local storage · up to 30 days, or until site data is cleared |
crisp-client/* | Customer support | Historical only. A cookie created by a previous website-chat session may remain until it expires, but the disabled storefront does not read it or contact Crisp. | Cookie · normally 6 months, renewed when the activated chat returns; conversation records may be retained separately |
_dcid | Analytics | Anonymous first-party visitor ID for performance measurement. | Cookie · up to 2 years |
_fbp | Analytics | First-party browser identifier used by the Meta Pixel and our server-side Meta measurement connection. | Cookie · up to 2 years |
_fbc | Analytics | Preserves the Meta click identifier and its first-visit timestamp after a Meta ad visit. | Cookie · up to 90 days |
_ga, _ga_5X3GZ2VDZ4 | Analytics | Google Analytics visitor and session identifiers set by the Google tag. | Cookie · up to 2 years |
_gcl_au, _gcl_aw, _gcl_gb | Analytics | Google Ads conversion-linker identifiers that connect a Google ad click to later store actions. | Cookie · up to 90 days |
_tt_sid, _tt_attr | Analytics | Session and referral context for measurement. | Session / local storage |
_tt_landing_meta | Limited Meta attribution | Stores only a Meta click identifier and first-seen time from an earlier consent-limited ad landing so a same-tab checkout could retain campaign attribution. No longer created for new visits; cleared by Necessary-only or GPC. | Session storage · current tab only |
Tuned's internal telemetry stores hourly and daily counters only—there is no raw event or page-instance table. Payloads contain strict categories such as page group, privacy mode, broad source/device group, product SKU for commerce actions, allowlisted campaign group, and dwell, scroll, performance, error or result buckets. Error diagnostics are limited to allowlisted origin, coarse error-type, media-type, and optional-tag-state categories. The browser discards raw error messages, filenames and paths, stack traces, browser versions, raw fbclid, gclid and other click IDs, full URLs/query strings/referrers, cookies, browser-storage identifiers, full IP addresses/user-agent strings, customer/order identifiers, and free-form text. Only the broad source and allowlisted campaign categories may remain in session storage for the current tab, and neither value identifies a visitor. The application stores no request IP or user-agent; only a short-lived hashed IP bucket is used to rate-limit abuse. Vercel and Supabase process the service, but these counters are not joined to customer, checkout, order or advertising data, are not used for advertising attribution, audiences, or campaign optimization, and are not sent to an advertising platform. Hourly counters are retained for 90 days and daily counters for no more than 13 months.
Your choices
Analytics and advertising measurement runs by default when you visit Tuned. Choosing Necessary only — on the cookie banner or at any time through Cookie preferences / Do Not Sell or Share in the footer — disables advertising and user-identifying analytics, stops optional analytics and advertising events, and removes _dcid, _fbp, _fbc, _ga, _ga_5X3GZ2VDZ4, _gcl_au, _gcl_aw, _gcl_gb, _tt_sid, _tt_attr, and _tt_landing_meta. That same control is how you opt out of the “sale” or “sharing” of personal information under US state privacy laws such as the CCPA/CPRA. Tuned continues to collect anonymous, aggregate service-performance and storefront-interaction statistics that are not used for advertising or linked to a customer. You can separately ; this immediately clears the current tab's coarse source/campaign context and also suppresses Vercel Web Analytics on future page views. A non-identifying session preference fallback preserves that choice during same-origin navigation when DOM storage is unavailable. Re-enable it with the same control or clear site data.
Global Privacy Control
If your browser sends a Global Privacy Control (GPC) signal, we honour it automatically: we treat it as “Necessary only”, set no analytics cookies, suppress anonymous aggregate service measurement, and block analytics or advertising destination calls from our first-party measurement hub.
Questions
Email support@tunedresearch.com with any questions about this policy.
