What is a cookie?
A cookie is a small text file stored on your device by your browser when you visit a website. Cookies (and the closely related technologies of local storage and session storage) allow a site to remember things between visits, like whether you are signed in, what currency you prefer, or whether you have already dismissed a banner. This policy uses “cookies” as shorthand for all of these technologies.
The cookies we use
We aim to use the smallest set of cookies that still lets the product work well. We group them into three categories:
- Essential, needed for the Service to function. These keep you signed in, remember your base currency and theme, and protect against cross-site request forgery. Without them, core features will not work.
- Preference, remember non-critical UI choices, such as which dashboard scope you last viewed, whether you dismissed a coachmark, or your collapsed sidebar state. Used purely to make 2120 feel familiar to you on return.
- Analytics and performance, used primarily on the public website (2120.money) to understand which pages people read, how long they stay, and where the experience breaks. We use this in aggregate; we do not build advertising profiles. Tools currently in this category include PostHog (product analytics) and Cloudflare Web Analytics. The signed-in app currently does not load analytics tooling.
Your choices
On the public website, the first time you visit, you will see a cookie banner with “Accept” and “Decline” buttons. Your choice is remembered and the banner will not reappear on that browser unless you clear cookies. You can also manage or delete cookies at any time using your browser’s settings.
Inside the signed-in 2120 app, the essential and preference cookies described above are needed for the product to function. If you decline them, the app will not work properly.
Do Not Track and Global Privacy Control
We currently treat a Global Privacy Control (GPC) signal the same as clicking “Decline” on our cookie banner: non-essential analytics will be disabled for that browser. We do not honour the legacy “Do Not Track” (DNT) header because it is no longer broadly supported, but we are happy to revisit this as standards evolve.
Third-party cookies
Some sub-processors we use may set their own cookies when their tools are loaded. The main ones today are:
- Supabase, may set an authentication cookie when you sign in.
- Razorpay / Stripe, may set cookies during a payment checkout flow for fraud prevention.
- PostHog and Cloudflare Insights, set cookies only on the public website and only after consent (where required).
Changes to this policy
If we add or remove a category of cookie in a material way, we will update this page and (where required) re-prompt for consent. The “Last updated” date at the top of this page reflects the most recent revision.
Contact
Questions about how we use cookies? Email privacy@2120.money.


