Cookie Policy

Saturation.IO Privacy Policy

Last updated on October 31 2025.
Effective as of Nov 30, 2025

1. Introduction

This Cookie Policy explains how Saturation.io, Inc. ("Saturation," "we," "us," or "our") uses cookies and similar tracking technologies when you visit our website at https://saturation.io (the "Website") or use our financial management platform and related services (collectively, the "Services").

This policy should be read in conjunction with our Privacy Policy and Terms of Service.

2. What Are Cookies?

Cookies are small text files that are placed on your device (computer, smartphone, or tablet) when you visit a website. They are widely used to make websites work more efficiently, improve user experience, and provide information to website owners.

Types of cookies we use:

  • Session Cookies: Temporary cookies that expire when you close your browser

  • Persistent Cookies: Cookies that remain on your device for a set period or until you delete them

  • First-Party Cookies: Cookies set directly by Saturation.io

  • Third-Party Cookies: Cookies set by our service providers and partners

Cookie Refresh and Renewal

  • Session cookies are deleted when you close your browser

  • Persistent cookies are refreshed each time you visit to maintain their expiration date

  • Authentication cookies are renewed upon each login

Cookie Storage Location

  • Cookies are stored locally on your device

  • We do not have access to cookies set by third-party services except through the data they share with us per our agreements

Cookie Security Flags

  • Authentication cookies use HttpOnly flag (not accessible via JavaScript)

  • Secure flag ensures cookies only transmitted over HTTPS

  • SameSite flag prevents cross-site request forgery

3. How We Use Cookies

We use cookies and similar technologies for the following purposes:

3.1 Essential Operations

To provide core functionality of our Services, including authentication, security, and platform operations.

3.2 Performance and Analytics

To understand how users interact with our Services, identify technical issues, and improve performance.

3.3 Functionality

To remember your preferences, settings, and previous actions to enhance your experience.

3.4 Communication

To enable customer support features, including our chat functionality.

3.5 Security

To detect and prevent fraud, secure user accounts, and protect against malicious activity.

3.6 Financial Services

To facilitate secure payment processing, charge card services, and financial transaction management.

4. Cookies We Use

4.1 Strictly Necessary Cookies

These cookies are essential for the Website and Services to function and cannot be disabled without severely affecting your ability to use our platform.

Cookie Name

Provider

Purpose

Duration

Type

session_token

Saturation.io

Authenticates users and maintains login sessions

Session

First-party

csrf_token

Saturation.io

Prevents cross-site request forgery attacks

Session

First-party

secure_session

Saturation.io

Maintains secure session state

Session

First-party

user_preferences

Saturation.io

Stores essential user settings and preferences

1 year

First-party

cookie_consent

Saturation.io

Records your cookie consent preferences

1 year

First-party

Legal Basis (GDPR): Legitimate interests (Article 6(1)(f)) - necessary for service delivery and security.

4.2 Performance and Analytics Cookies

These cookies help us understand how visitors interact with our Website and Services by collecting and reporting information anonymously.

Cookie Name

Provider

Purpose

Duration

Type

mp_*

Mixpanel

Tracks user interactions and product usage analytics

1 year

Third-party

ph_*

PostHog

Analyzes user behavior and feature usage

1 year

Third-party

posthog_session

PostHog

Maintains analytics session state

30 minutes

Third-party

sentry_session

Sentry

Error tracking and performance monitoring

Session

Third-party

Legal Basis (GDPR): Consent (Article 6(1)(a)) - you can opt out of these cookies.

What we collect: Page views, button clicks, time spent on pages, navigation paths, browser type, device information, general location (country/city level), error reports, and performance metrics.

Third-Party Privacy Policies:

4.3 Functionality Cookies

These cookies enable enhanced features and personalization.

Cookie Name

Provider

Purpose

Duration

Type

intercom-*

Intercom

Enables customer support chat and messaging

6 months

Third-party

intercom-session

Intercom

Maintains chat session state

7 days

Third-party

dashboard_view

Saturation.io

Remembers your dashboard layout preferences

1 year

First-party

theme_preference

Saturation.io

Stores display theme selection

1 year

First-party

Legal Basis (GDPR): Consent (Article 6(1)(a)) or Legitimate interests (Article 6(1)(f)) for support-related cookies.

Third-Party Privacy Policies:

  • Intercom: https://www.intercom.com/legal/privacy

4.4 Payment and Financial Services Cookies

These cookies are set by our payment processor to facilitate secure financial transactions.

Cookie Name

Provider

Purpose

Duration

Type

stripe_*

Stripe

Processes payments and prevents fraud

Varies

Third-party

__stripe_sid

Stripe

Maintains payment session security

30 minutes

Third-party

__stripe_mid

Stripe

Fraud detection and prevention

1 year

Third-party

Information about CapitalOS cookies can be found in their privacy policy linked below.

Legal Basis (GDPR): Contract performance (Article 6(1)(b)) - necessary to process your payments.

Third-Party Privacy Policies:

4.5 Infrastructure and CDN Cookies

These cookies support content delivery and platform hosting.

Cookie Name

Provider

Purpose

Duration

Type

render_*

Render

Application hosting and delivery

Session

Third-party

cdn_token

DigitalOcean

Content delivery and file access

Session

Third-party

Legal Basis (GDPR): Legitimate interests (Article 6(1)(f)) - necessary for service delivery.

5. Third-Party Services

In addition to cookies, we use the following third-party services that may collect information through other tracking technologies:

5.1 Analytics and Monitoring

  • Mixpanel (US/EU data centers) - Product analytics and user behavior tracking

  • PostHog (US/EU data centers) - Open-source product analytics and session recording

  • Sentry (US/EU data centers) - Error monitoring and performance tracking

  • Drata (US) - Security and compliance monitoring

5.2 Communication and Support

  • Intercom (US) - Customer support chat, messaging, and help desk

  • Postmark (US) - Transactional email delivery

  • Loops (US/EU) - Marketing email campaigns

5.3 Business Operations

  • Attio (UK/EU/US) - Customer relationship management

  • Airtable (US) - Internal business data management

  • Google Workspace (Global) - Email, document storage, and collaboration

5.4 Financial Services

  • Stripe (US/EU) - Payment processing and card services

  • Plaid (US) - Financial data aggregation and bank connectivity

  • CapitalOS (US) - Embedded charge card platform and spend management

Each of these services may use their own cookies and tracking technologies. We recommend reviewing their respective privacy policies (linked above) to understand their data practices.

6. Your Cookie Choices

6.1 Cookie Consent Manager

When you first visit our Website, you will see a cookie consent banner that allows you to:

  • Accept all cookies

  • Reject optional cookies (keeping only strictly necessary cookies)

  • Customize your preferences by cookie category

You can change your cookie preferences at any time by clicking the "Cookie Settings" link in the footer of our Website.

6.2 Browser Settings

Most web browsers allow you to control cookies through their settings. You can typically:

  • View and delete cookies

  • Block all cookies

  • Block third-party cookies

  • Clear cookies when you close your browser

How to manage cookies in common browsers:

  • Google Chrome: Settings → Privacy and Security → Cookies and other site data
    Help: https://support.google.com/chrome/answer/95647


  • Mozilla Firefox: Settings → Privacy & Security → Cookies and Site Data
    Help: https://support.mozilla.org/en-US/kb/enhanced-tracking-protection-firefox-desktop


  • Safari: Preferences → Privacy → Cookies and website data
    Help: https://support.apple.com/guide/safari/manage-cookies-sfri11471/mac


  • Microsoft Edge: Settings → Cookies and site permissions → Cookies and site data
    Help: https://support.microsoft.com/en-us/microsoft-edge/delete-cookies-in-microsoft-edge-63947406-40ac-c3b8-57b9-2a946a29ae09


  • Brave: Settings → Privacy and security → Cookies and other site data
    Help: https://support.brave.com/hc/en-us/articles/360050634931


Important: Blocking or deleting certain cookies may impair your ability to use our Services. Strictly necessary cookies cannot be disabled without significantly affecting platform functionality.

6.3 Opt-Out of Analytics

You can opt out of analytics tracking through the following methods:

Mixpanel Opt-Out: Visit https://mixpanel.com/optout/
PostHog Opt-Out: Available in our Cookie Settings or by setting a "Do Not Track" browser preference
Sentry Opt-Out: Managed through our Cookie Settings

6.4 Do Not Track Signals

Some browsers offer a "Do Not Track" (DNT) signal. While we respect your privacy choices, there is no industry standard for how to respond to DNT signals. Currently, PostHog respects DNT signals automatically. For other services, please use our Cookie Settings to manage your preferences.

6.5 Mobile Device Settings

If you access our Services through a mobile device, you can control tracking through your device settings:

  • iOS: Settings → Privacy → Tracking → Disable "Allow Apps to Request to Track"

  • Android: Settings → Google → Ads → Opt out of Ads Personalization

7. Data Retention

Cookies remain on your device for the durations specified in Section 4 above or until you delete them. When cookies expire or are deleted, we can no longer access the information they contain.

Analytics data collected via cookies is retained according to our Data Retention Policy:

  • Raw analytics data: 2 years from collection

  • Aggregated analytics: Indefinitely (anonymized and cannot identify individuals)

  • Error logs: 30 days

8. International Data Transfers

Some of our third-party service providers are located outside your country of residence. When cookies enable data transfer to these providers:

  • We ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) for transfers from the EU/UK

  • Data transfers comply with GDPR Article 46 requirements

  • Our Data Processing Agreement (DPA) governs all subprocessor relationships

9. Security

Cookies help us maintain the security of our Services by:

  • Authenticating users and preventing unauthorized access

  • Detecting and preventing fraudulent activity

  • Maintaining secure session states

  • Logging security-relevant events for audit purposes

We implement industry-standard security measures to protect cookie data, including:

  • TLS 1.2+ encryption for all data transmission

  • AES-256 encryption for sensitive data at rest

  • Secure, HttpOnly, and SameSite flags on authentication cookies

  • Regular security audits and penetration testing

10. Updates to This Cookie Policy

We may update this Cookie Policy from time to time to reflect changes in our practices, technologies, legal requirements, or business needs. We encourage you to review this Cookie Policy periodically. Your continued use of our Services after changes take effect constitutes acceptance of the updated policy.

11. Your Rights Under Privacy Laws

Depending on your location, you may have rights regarding information collected via cookies:

11.1 GDPR (European Union) Rights:

  • Right to access your data

  • Right to rectification

  • Right to erasure ("right to be forgotten")

  • Right to restrict processing

  • Right to data portability

  • Right to object to processing

  • Right to withdraw consent

  • Right to lodge a complaint with a supervisory authority

11.2 CCPA (California) Rights:

  • Right to know what personal information is collected

  • Right to know whether personal information is sold or disclosed

  • Right to opt-out of the sale of personal information (Note: We do not sell personal information)

  • Right to deletion

  • Right to non-discrimination

11.3 Other State Privacy Laws:

If you reside in Virginia, Colorado, Connecticut, Utah, or other states with comprehensive privacy laws, you may have similar rights. Contact us for specific information about your rights.

To exercise your rights, please contact us using the information in Section 13 below.

12. Contact Us

If you have questions or concerns about our use of cookies, please contact us:

Email: legal@saturation.io

Mail:
Saturation.io, Inc.
Attn: Privacy Officer
7901 4th St N Suite 300, St. Petersburg, FL 33702

We will respond to all requests within 30 days as required by applicable law.