Cookie Policy#

Last Updated: July 25, 2026 | Version: 1.2


About This Policy

This Cookie Policy explains how Romarket uses cookies and similar storage technologies when you visit our website. It describes what these technologies are, why we use them, and your options for controlling them.


What Are Cookies#

Cookies are small text files stored on your device when you visit a website. They help websites function properly, remember your preferences, and provide information to site owners.

Cookies can be:

  • Session cookies: Deleted when you close your browser
  • Persistent cookies: Remain on your device until they expire or you delete them

Cookies We Use#

Essential Cookies#

Required for the website to function

These cookies are strictly necessary and cannot be disabled:

CookiePurposeDuration
better-auth.session_tokenMaintains your authenticated session7 days
better-auth.csrf_tokenProtects against cross-site request forgerySession

Analytics Cookies#

Help us understand how you use our site

We use PostHog for privacy-focused analytics:

CookiePurposeDuration
ph_phc_*PostHog distinct user identifier1 year
ph_*_posthogPostHog session dataSession

PostHog helps us understand:

  • Which pages are visited most frequently
  • How users navigate through the platform
  • Where users encounter errors
  • General usage patterns

PostHog loads only after marketing consent. It can record anonymous events with an anonymous distinct identifier, but person_profiles: "identified_only" prevents PostHog from creating a person profile unless the user is identified.

Advertising Cookies#

Measure whether our ads work

We use the TikTok Pixel to measure the results of our TikTok advertising:

CookiePurposeDuration
_ttpTikTok identifier used to match your visit to an ad you saw13 months

The pixel loads only after marketing consent and reports actions such as viewing a listing, searching, saving a listing, contacting a seller, creating an account, and completing a purchase.

These events are also sent from our server through TikTok's Events API, carrying the same information plus your IP address and browser user agent. Both copies share one event identifier so TikTok counts the action once. If you are signed in, your email address and account identifier are irreversibly hashed (SHA-256) before they are sent -- TikTok receives the hash, never the address itself. Nothing is sent from the browser or the server without marketing consent.

Preference Cookies#

Remember your settings

StoragePurposeDuration
themeYour dark/light mode preferencePersistent

Local Storage#

We also use browser localStorage (not cookies) for:

KeyPurposeCleared
listing-draft-*Saves your listing form progress so you don't lose workWhen you submit or manually clear
romarket_ttclid_v1Stores the TikTok ad click identifier from your landing URL, after marketing consent, so a later signup or purchase can be credited to the adAfter 30 days, or when marketing consent is withdrawn
romarket_signup_reported_v1:*Records that your account creation has already been counted, so a page reload does not count it twiceWhen you clear site data

Session Storage#

After you grant marketing consent, we use browser sessionStorage for first-touch attribution:

KeyPurposeCleared
romarket_acquisition_v1Remembers the consented acquisition channel, landing path, referrer hostname, and campaign fields for the current sessionWhen the browser session ends or marketing consent is withdrawn

The attribution record stores the referring hostname, not the full external referring URL.


Third-Party Services#

PostHog#

We use PostHog for product analytics. They:

  • Process data in compliance with GDPR
  • Do not sell user data to third parties
  • Provide privacy-focused analytics

Learn more: PostHog Privacy Policy

TikTok#

We use the TikTok Pixel and TikTok's Events API to measure our advertising. TikTok receives the events described above, along with hashed identifiers when you are signed in, and may use them to attribute conversions and improve ad delivery.

Learn more: TikTok Privacy Policy

Roblox OAuth#

When you sign in with Roblox, Roblox may set their own cookies during the OAuth flow. See Roblox's Privacy Policy.

Escrow.com#

During payment processing, Escrow.com may set their own cookies. See their privacy policy for details.


Managing Cookies#

Browser Settings#

Control cookies through your browser:

  • Chrome: Settings → Privacy and security → Cookies
  • Firefox: Settings → Privacy & Security → Cookies
  • Safari: Preferences → Privacy → Manage Website Data
  • Edge: Settings → Privacy, search, and services → Cookies

What Happens If You Disable Cookies#

  • Essential cookies disabled: You won't be able to stay logged in
  • Analytics cookies disabled: Your usage won't be tracked (we'll still function normally)
  • Advertising cookies disabled: No events are sent to TikTok from your browser or from our server
  • Preference cookies disabled: You'll need to set dark/light mode each visit

Do Not Track#

Our consent manager honors a browser Do Not Track value of 1 by treating non-essential consent categories as disabled.


Updates#

We may update this Cookie Policy when our practices change. Check the "Last updated" date for the current version.


Contact#

Questions about cookies? Email us at hello@romarket.app.