Cookie Policy
Effective Date: July 27, 2026
This Cookie Policy explains how Raileon LLC (“Raileon,” “we,” “our,” or “us”) uses cookies and similar technologies on our website at raileon.com and in the Raileon platform. It sits alongside our Privacy Policy, which covers everything else we do with your data.
1. What Cookies Are
A cookie is a small text file that a website asks your browser to store and send back on later visits. Cookies are how a site remembers that the request it just received came from the same browser as the last one — which is what makes staying signed in possible.
“Similar technologies” means anything that reads or writes data in your browser for the same purpose, such as local storage, session storage, and pixels. We describe those in Section 3.
How cookies are categorised
- Strictly necessary: the site cannot deliver the service you asked for without them. Signing in is the clearest example. Under GDPR and the ePrivacy rules these do not require consent.
- Functional: remembers a preference you set. Useful, but the site still works if it is missing.
- Analytics: measures how the site is used. We use analytics, but we do it without cookies (Section 3).
- Advertising and tracking: builds a profile of you across sites for targeting. We do not use these at all.
2. Every Cookie We Set
This is the complete list. If you inspect your browser and find a cookie on a Raileon domain that is not below, we want to know about it — email privacy@raileon.com.
| Cookie | Set by | Purpose | Category | Duration |
|---|---|---|---|---|
__session | Clerk (our authentication provider) | Holds your signed session token so the platform knows who you are on each request. | Strictly necessary | Refreshed continuously while you are signed in; cleared when you sign out. |
__client_uat | Clerk (our authentication provider) | Records when your session was last updated so pages can tell whether you are signed in before the session token is read. | Strictly necessary | Persists while you remain signed in; reset when you sign out. |
raileon_impersonation | Raileon | Marks a support session in which an authorised Raileon staff member is viewing your workspace to help with a request. Only ever set on the staff member’s browser, never on yours. | Strictly necessary | 10 minutes |
sidebar_state | Raileon | Remembers whether you left the dashboard sidebar expanded or collapsed. Set only after you sign in. | Functional preference | 7 days |
None of these cookies contain your business content, and none of them are readable by any other website.
3. What We Do Not Do
We want to be specific rather than reassuring, so here is the list of things that are simply absent:
- No advertising or marketing cookies. We do not run ad pixels, retargeting tags, or conversion trackers.
- No cross-site or third-party tracking. Nothing on our site profiles you across other websites, and we do not sell or share browsing data with data brokers or advertisers.
- No social media tracking widgets. Links to our social accounts are plain links.
- No session-replay or heatmap tools. We do not record your mouse movements, keystrokes, or screen.
Our analytics is cookieless
We use Vercel Web Analytics to see aggregate page views and traffic sources. It sets no cookies and stores no identifier in your browser. It does not follow you between visits or between sites, and it produces counts, not profiles.
Why there is no cookie banner
Consent banners exist so that you can refuse non-essential cookies. We have none to refuse: three of our four cookies are strictly necessary for authentication, and the fourth is a display preference set only after you have signed in and asked for it by toggling the sidebar. Showing you a banner with nothing to switch off would be theatre. If we ever introduce a cookie that genuinely requires consent, we will ask for it before setting the cookie — not after.
Other browser storage
The platform uses your browser’s local and session storage for short-lived interface state, such as an unsent draft or a panel you have open. That data stays in your browser, is not transmitted to us as a cookie, and is cleared when you clear your site data.
4. Controlling Cookies
Cookies are controlled from your browser, and you do not need our permission to change them. Every major browser lets you view the cookies a site has set, delete them, block them for a specific site, or block them everywhere. Look for cookies or site data under Settings, Privacy, or Preferences — in Chrome, Edge, Firefox, Safari, and Brave alike.
Deleting cookies for raileon.com signs you out. Blocking them stops you from signing in at all.
Blocking sidebar_state specifically is harmless. Your sidebar will simply open in its default position every time.
5. Do Not Track and Global Privacy Control
Some browsers send a Do Not Track (DNT) header or a Global Privacy Control (GPC) signal to tell sites you do not want to be tracked or have your personal information sold or shared. There is no agreed industry standard for how sites must respond to DNT, so many ignore it.
Our position is straightforward: we do not change our behaviour based on these signals because there is nothing for them to switch off. We do not track you across sites, we do not sell or share your personal information, and our analytics is cookieless. A GPC signal asks us to stop doing something we already do not do. If that ever changes, we will honour GPC and say so here.
6. Changes to This Policy
If we add, remove, or change the purpose of a cookie, we will update the table in Section 2 and revise the Effective Date at the top of this page in the same change. For material changes — in particular, introducing any cookie that is not strictly necessary or functional — we will notify account holders by email or through the platform at least 15 days before the change takes effect, and we will obtain consent where the law requires it.
We apply this policy the same way to everyone. Rather than deciding what you are entitled to based on where you happen to be, we extend the protections described here to all users regardless of location.
7. Contact Us
Questions about this Cookie Policy, or about a cookie you have found that is not listed here:
Raileon LLC
Miami, Florida
privacy@raileon.com— data-protection matters
admin@raileon.com— general enquiries
For the full picture of what we collect and why, see our Privacy Policy.