1. Scope
This Cookies Policy explains how Scalith, LLC uses cookies, local storage, and similar technologies through the Referral API website, customer dashboard, and SDK. It forms part of our Privacy Policy.
A cookie is a small value a website asks a browser to store and return. Local storage lets a browser retain data for a website without sending it automatically with every request. Similar technologies can include session storage, cached identifiers, and security tokens.
2. Technologies we use
Depending on how the Services are used, browser storage may hold:
- An opaque account-session identifier.
- Security, verification, and fraud-prevention state.
- Short-lived state needed to complete an account action.
- Service preferences needed to present or operate the Website.
- A referral-attribution token and anonymous session identifier set through a Customer’s deployment of the SDK.
These values may be associated with server-side account, security, attribution, usage, and diagnostic records described in the Privacy Policy.
3. Necessary service technologies
We use strictly necessary or functional technologies to authenticate account owners, keep sessions secure, prevent cross-site attacks, rate-limit abusive activity, detect fraud, preserve requested state, and operate the Services. These technologies are not used to build an advertising profile.
Necessary account-session cookies are protected using settings designed to reduce access from browser scripts and cross-site requests. Their duration depends on the account action, session, and security purpose. Server-side security and audit records may be retained separately under the Privacy Policy.
4. Customer SDK storage
When a Customer initializes the Referral API SDK on its website or application, the SDK may store a referral-attribution token and an anonymous session identifier. This storage preserves attribution continuity so later Customer activity can be connected accurately to the referral that preceded it. The standard attribution lifetime may extend for up to approximately 90 days, subject to the Customer’s implementation and service configuration.
The SDK may also send the complete landing-page URL, complete referring-page URL, referral code, time, and related request context to the Services. These are core attribution and diagnostic data, not advertising cookies. Customers should avoid placing secrets or unrelated sensitive information in URLs.
5. Customer-controlled websites
A Customer controls its website, application, SDK initialization, and relationship with its end users. The Customer is responsible for determining whether its deployment requires a notice, consent, or preference control and for providing it before initializing the SDK when required.
Referral API does not operate a universal consent banner on Customer websites. Customers can control when their own software initializes the SDK and should coordinate that choice with their privacy and cookie practices.
6. Advertising and analytics
Scalith does not currently use advertising cookies or technologies that share personal information for cross-context behavioral advertising on its Website. Referral API service analytics, referral reporting, usage measurement, fraud detection, and operational diagnostics are product and security functions, not behavioral advertising.
7. Your choices
Most browsers let a person view, delete, or block cookies and local storage. Browser instructions explain how to do this. Blocking or deleting necessary storage may log an account owner out, prevent verification or security controls from working, break settings, or prevent referral continuity and accurate attribution.
A Customer End User should direct questions or requests about storage on a Customer’s website to that Customer. A verified Referral API Customer may email support@referralapi.dev.
8. Privacy preference signals
Browsers may transmit Do Not Track or Global Privacy Control signals. Because Scalith does not sell personal information or share it for cross-context behavioral advertising, these signals do not change advertising practices on our Website. We will honor a legally binding signal where applicable to a processing activity covered by that law.
These browser signals do not instruct a Customer about the Customer’s own website, and they do not disable strictly necessary security, authentication, or service operation.
9. Changes to this policy
We may update this Policy as the Services or legal requirements change. The “Last updated” date identifies the current version. We will send material changes to the account email when required or reasonably appropriate.
10. Contact
Send cookie and browser-storage questions by email to support@referralapi.dev. Email is our customer communication channel to the fullest extent permitted by law.
Scalith, LLC30 N Gould St Ste N, Sheridan, WY 82801, United StatesEmail: support@referralapi.dev