1. Redirected traffic sets nothing
When a visitor follows one of your redirected links, our edge answers with a status code and a Location header. No cookie is written, no script is injected and no pixel is loaded. The visitor's browser goes straight on to your destination, which sets whatever its own policy says. We never follow a visitor from one customer's domain to another.
2. Cookies on the dashboard
All three are first-party, set on app.redirectduck.com, marked Secure, HttpOnly where the browser does not need to read them, and SameSite=Lax.
3. Local storage on the marketing site
The public pages store one item, rd_billing_period, so the pricing table remembers whether you were looking at monthly or yearly prices. It holds a single word, never leaves your browser and can be cleared at any time without breaking anything.
4. Analytics
Page views on the marketing site are counted with a privacy-friendly tool that sets no cookie, uses no fingerprint and keeps no identifier across visits. We see how many people opened the pricing page, not who they were. Product usage inside the dashboard is tied to your account because you are logged in, and is described in section 1 of the privacy policy.
5. Controlling cookies
Every browser can block or delete cookies for a site. Because ours are strictly necessary, blocking them means the dashboard cannot keep you logged in and forms will be rejected as unsafe. The marketing site and your redirects keep working normally.
Since we set nothing that requires consent, there is no preference for you to manage here and no banner to dismiss. If we ever add a cookie that needs consent, we will ask before setting it and update this page 30 days in advance.
6. Contact
Questions about this page go to privacy@redirectduck.com.