Website preferences
The public website stores the acknowledgement of this notice in browser local storage. Removing that record causes the notice to appear again. It does not enable analytics or advertising.
Account sessions and security
Merchant, administrator and cardholder surfaces use secure session and anti-forgery tokens required to keep a signed-in account working. Cloudflare may use short-lived security mechanisms for Turnstile, abuse prevention, rate limiting, bot detection and traffic integrity.
Blocking necessary storage may prevent sign-in, verification or a protected request from completing. Session tokens are not used to follow users across unrelated websites.
Shopify embedded use
When the embedded Shopify app is opened, Shopify and App Bridge provide session context under Shopify settings and notices. RebateCardX validates that context server-side and does not convert it into an advertising identifier.
Controls and changes
Most browsers let you inspect and delete cookies and local storage. Signing out revokes the applicable platform session; deleting browser storage alone may not revoke a server-side session.
We will update this notice before adding a non-essential category. Contact privacy@rebatecardx.com with a question about browser storage.