Cookie Policy
Version 1.2 · Last updated: September 25, 2026
This Cookie Policy explains how GoRefer.io ("Company," "we," "us," or "our") uses cookies and similar tracking technologies when you visit our website and use our Service. This policy should be read alongside our Privacy Policy.
1. What Are Cookies?
Cookies are small text files that are placed on your device (computer, smartphone, or tablet) when you visit a website. They are widely used to make websites work more efficiently, provide information to website owners, and enable certain features.
Cookies can be "session cookies" (which are deleted when you close your browser) or "persistent cookies" (which remain on your device for a set period or until you delete them).
2. How We Use Cookies
We use cookies for the following purposes:
- Essential cookies: Required for the Service to function properly (authentication, security)
- Analytics: Help us understand how visitors interact with our website
- Functional cookies: Remember your preferences and settings
- Attribution cookies: Credit the affiliate or referral link that introduced you to us
3. Types of Cookies We Use
3.1 Essential Cookies
These cookies are strictly necessary for the operation of our Service. They enable core functionality such as security, authentication, and session management. You cannot opt out of essential cookies.
| Cookie Name | Purpose | Duration | Provider |
|---|---|---|---|
| refresh_token / sa_refresh_token | Authentication cookies used by the separate GoRefer application, not required to browse this public website | Authentication-session policy | GoRefer.io application |
| auth_role / auth_status | Application authentication and role-routing indicators | Authentication-session policy | GoRefer.io application |
3.2 Analytics Cookies
We use two analytics systems on this marketing website, and we do not load Google Analytics anywhere. First, our own first-party measurement stores two identifiers in your browser's local and session storage and sends page views, referrer, screen size, language, and time zone to our own servers. Second, we use HeyCatch, a third-party product-analytics processor, which stores its own identifiers and receives page views and interaction events at in.heycatch.ai. If your browser sends a "Do Not Track" or Global Privacy Control signal, neither system is loaded: no identifier is created and nothing is sent.
The Meta Pixel loads on this public marketing website when marketing measurement is enabled, and on our own public webinar registration pages at app.gorefer.io/webinar/. Marketing-site page views are blocked when your browser sends Do Not Track or Global Privacy Control. See section 3.4 for advertising measurement details.
Neither analytics system runs inside the GoRefer application. Once you sign in at app.gorefer.io, no third-party analytics script is loaded and no product-analytics events are sent — not page views, not interactions, and no identifier for you or your firm. The signed-in application handles taxpayer data, so we keep third-party measurement out of it entirely rather than trying to filter what it collects. Error monitoring (Sentry) still runs there; it is described in our subprocessor list. The webinar registration pages on that same domain are public pages you reach before signing in, and also use the Meta Pixel described in section 3.4.
| Cookie Name | Purpose | Duration | Provider |
|---|---|---|---|
| gr_vid (local storage) | First-party visitor identifier used to distinguish new from returning visitors | Until you clear site data | GoRefer.io |
| gr_sid (session storage) | First-party session identifier used to group page views into one visit | Session | GoRefer.io |
| HeyCatch analytics storage | Third-party product analytics on this marketing website only — never inside the signed-in application. Distinguishes visitors and groups page views into sessions. Not created at all when your browser sends Do Not Track or Global Privacy Control. | Until you clear site data | HeyCatch (in.heycatch.ai) |
3.3 Functional Cookies
These cookies enable enhanced functionality and personalization, such as remembering your preferences.
| Cookie Name | Purpose | Duration | Provider |
|---|---|---|---|
| gorefer_chat_session (local storage) | Restores an active support-chat session when chat is used | 24-hour application expiry | GoRefer.io |
| chatWidgetPosition / chatLeadForm (local storage) | Remembers chat placement and form details when those controls are used | Until you clear site data | GoRefer.io |
| gorefer_exit_popup_dismissed (local storage) | Remembers dismissal of the newsletter popup | Until cleared; dismissal timing is checked by the popup | GoRefer.io |
3.4 Marketing and Advertising Cookies
On this marketing website, a first-party attribution cookie remembers an affiliate or referral link so that it can be credited if you sign up. The Meta Pixel can also set the advertising identifiers listed below when marketing measurement is enabled.
We also advertise GoRefer on Meta's platforms, and we measure which of those ads lead to a webinar registration. Marketing page-view measurement runs on this website. Webinar measurement runs at app.gorefer.io/webinar/. Neither runs inside the signed-in application where your clients' tax data lives. The webinar flow has two halves:
- In your browser. Meta's Pixel script loads on the page. It sets the "_fbp" cookie listed below, stores the "_fbc" click identifier if you arrived from a Meta ad, and reports the page view and, if you register, the registration.
- From our servers. We send Meta a matching copy of the same events through its Conversions API, so the pair is counted once rather than twice. For a page view that copy carries only the "_fbp" and "_fbc" identifiers, your IP address and your browser user agent. For a webinar registration it also carries your email address, phone number and first and last name — hashed with SHA-256 before they leave our servers, which is the form Meta requires in order to match them.
Nothing about your tax situation is ever sent to Meta: no income, refund, filing status or document content, and nothing at all from inside the signed-in application. You can block the Pixel with your browser's tracking protection or an ad blocker, and we make no attempt to work around either.
| Cookie Name | Purpose | Duration | Provider |
|---|---|---|---|
| gorefer_affiliate_ref | Remembers which affiliate or referral link brought you to us, so the referral is credited if you sign up | 90 days | GoRefer.io |
| _fbp | Set by the Meta Pixel on this marketing website and our public webinar registration pages. Identifies your browser so that a registration can be matched back to the ad that produced it. | 90 days | Meta Platforms (public marketing and webinar pages) |
| _fbc | Set by the Meta Pixel on this marketing website and public webinar registration pages if you arrived from a Meta ad. Stores that ad's click identifier. | 90 days | Meta Platforms (public marketing and webinar pages) |
4. Third-Party Cookies
Some cookies are placed by third-party services that appear on our pages. We do not control these cookies. The third parties are:
- Stripe: Payment processing, on checkout and billing pages - Privacy Policy
- Meta Platforms: Advertising measurement on public marketing and webinar registration pages (section 3.4) - Privacy Policy
For the full list of vendors that process data on our behalf, see the Trust Center sub-processor register.
5. Managing Cookies
5.1 Cookie Consent
We do not currently show a cookie consent banner. On this marketing website the cookies and browser storage described above are either strictly necessary, set to remember a preference you chose, or measurement — first-party and HeyCatch alike — that is not loaded at all when your browser sends a "Do Not Track" or Global Privacy Control signal. The marketing-site Meta Pixel is covered by the same DNT/GPC check. The Meta Pixel on the separate public webinar pages (section 3.4) is not behind a consent banner and does not currently check these signals. You can remove any of these at any time using your browser settings, as described below, and browser tracking protection or an ad blocker will stop the Pixel loading at all. For privacy questions or requests, contact privacy@gorefer.io. This public website does not have an account-level consent setting.
5.2 Browser Settings
Most web browsers allow you to control cookies through their settings. You can:
- Block all cookies
- Block only third-party cookies
- Delete cookies when you close your browser
- Browse in "private" or "incognito" mode
Please note that blocking essential cookies may prevent our Service from functioning properly.
5.3 Browser-Specific Instructions
To manage cookies in your browser, please refer to:
6. Do Not Track
Some browsers have a "Do Not Track" (DNT) feature, and newer ones send a Global Privacy Control (GPC) signal, requesting that your browsing behavior not be tracked. Our website analytics and marketing-site Meta Pixel honour both: when either signal is present, our first-party measurement, HeyCatch SDK and marketing-site Meta Pixel are not initialised, so no visitor or session identifier is created and no page-view data is sent. The signed-in application runs no product analytics at all, with or without the signal. Essential and preference cookies still apply, because the Service cannot function without them.
The separate webinar advertising tag does not yet honour these signals. The Meta Pixel described in section 3.4 currently loads on our webinar registration pages whether or not your browser sends DNT or GPC. We would rather say so plainly than let the paragraph above be read as covering it. Browser tracking protection and ad blockers do stop it, and we make no attempt to work around them.
7. Similar Technologies
In addition to cookies, we may use similar technologies such as:
- Web beacons (pixels): Small graphic images used to track user behavior
- Local storage: Data stored in your browser for functionality purposes
- Session storage: Temporary data stored during your browsing session
8. Changes to This Policy
We may update this Cookie Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date.
9. Contact Us
If you have questions about this Cookie Policy, please contact us at:
GoRefer.io
Email: privacy@gorefer.io
Website: https://gorefer.io