1. What Are Cookies
Cookies are small text files that are stored on your device (computer, tablet, or mobile phone) when you visit a website or use a web-based application. Cookies allow websites to recognize your device on subsequent visits, remember your preferences, and gather information about how you interact with the site.
Cookies are widely used by websites and web applications to make them work, or work more efficiently, and to provide information to the site owners. In addition to traditional cookies, we use similar tracking technologies including web beacons (also called pixel tags or clear GIFs), local storage objects (LSOs), and session identifiers. In this policy, we use the term "cookies" to refer to all of these technologies collectively.
CompliRun uses cookies on our marketing website at complirun.com and within the CompliRun Platform (app.complirun.com). The types of cookies used and the purposes for which they are used differ between the marketing site and the Platform.
2. Types of Cookies We Use
2.1 Strictly Necessary Cookies
These cookies are required for the website and Platform to function and cannot be switched off. They are usually set in response to actions you take — such as logging in, setting your privacy preferences, or filling in forms. You can set your browser to block these cookies, but some parts of the site will not function properly as a result.
Strictly necessary cookies used by CompliRun include:
| Cookie Name | Purpose | Duration |
|---|---|---|
| cr_session | Maintains your authenticated session in the Platform. Required for login to function. | Session (expires on browser close or after 24 hours of inactivity) |
| cr_csrf | Cross-site request forgery protection token. Required to prevent unauthorized form submissions. | Session |
| cr_cookie_consent | Stores your cookie consent preferences to avoid showing the consent banner on every visit. | 12 months |
| cr_remember_me | Set when you select "Remember me" on the login page. Allows the Platform to recognize your device on return visits without re-authenticating. | 30 days |
2.2 Analytics and Performance Cookies
These cookies collect information about how visitors use our website and Platform — which pages are visited most frequently, how long users spend on each page, and where users come from. This information is used to improve how the website and Platform work. Analytics data is aggregated and does not identify individual users.
These cookies are set only when you accept analytics cookies via the cookie consent banner. You may withdraw this consent at any time.
| Cookie Name | Provider | Purpose | Duration |
|---|---|---|---|
| _ga | Google Analytics | Distinguishes unique users by assigning a randomly generated number. Used to calculate visitor, session, and campaign data for analytics reports. | 2 years |
| _gid | Google Analytics | Distinguishes users. Used to throttle request rate. | 24 hours |
| _gat | Google Analytics | Throttles Google Analytics request rate to reduce impact on site performance. | 1 minute |
| intercom-id-* | Intercom | Identifies returning visitors for the Intercom support widget. Used to link support conversations to user accounts. | 9 months |
2.3 Functional Cookies
Functional cookies enable enhanced functionality and personalization on the website and Platform. They may be set by CompliRun or by third-party providers whose services we have added to the Platform. If you do not allow these cookies, some or all of these features may not work correctly.
Functional cookies used by CompliRun include:
| Cookie Name | Purpose | Duration |
|---|---|---|
| cr_ui_prefs | Stores your Platform UI preferences, such as table column ordering, dashboard layout, and notification settings. | 12 months |
| cr_timezone | Stores your detected or selected timezone to display timestamps in local time within the Platform. | Session |
| intercom-session-* | Maintains your Intercom support chat session state when using the in-Platform support widget. | 1 week |
2.4 Marketing and Targeting Cookies
Marketing cookies may be set on the CompliRun marketing website (complirun.com) to track visitors across websites and to display relevant advertisements. These cookies are not used within the Platform itself (app.complirun.com). Marketing cookies are set only with your explicit consent via the cookie banner.
CompliRun currently uses the following marketing cookies on the marketing website:
| Cookie Name | Provider | Purpose | Duration |
|---|---|---|---|
| _gcl_au | Google Ads | Used by Google Ads to store and track conversion metrics from paid campaigns that direct visitors to complirun.com. | 3 months |
| li_fat_id | LinkedIn member indirect identifier for conversion tracking from LinkedIn ad campaigns. | 30 days |
3. How We Use Cookies
CompliRun uses cookies for the following purposes:
- Authentication and security: To maintain your login session within the Platform, protect against cross-site request forgery, and detect suspicious activity. These are strictly necessary and cannot be disabled without preventing Platform access.
- Preference storage: To remember your UI preferences, timezone, and consent choices so you do not need to re-configure them on each visit.
- Analytics: To understand how visitors use our website and Platform, which features are most valuable, and where users encounter difficulty. This helps us prioritize improvements. Analytics data is aggregated — we cannot identify individual users from analytics cookies.
- Customer support: To provide the in-Platform Intercom support widget and link support conversations to your account for continuity.
- Marketing measurement: On the marketing website only, to measure the effectiveness of our advertising campaigns. Marketing cookies are only set with explicit consent.
4. Managing Your Cookie Preferences
You have several options for managing cookie preferences on CompliRun's website and Platform:
4.1 Cookie Consent Banner
When you first visit complirun.com or the Platform, a cookie consent banner is displayed. You may accept all cookies, decline non-essential cookies, or manage your preferences by category (analytics, functional, marketing). Your choice is stored in the cr_cookie_consent cookie for 12 months. You may change your preferences at any time by clearing the cr_cookie_consent cookie or by clicking the cookie preferences link in the footer.
4.2 Browser Settings
You may configure your browser to block all cookies, accept all cookies, or notify you when a cookie is being set. Instructions for managing cookies in common browsers:
- Google Chrome: Settings → Privacy and security → Cookies and other site data
- Mozilla Firefox: Settings → Privacy & Security → Cookies and Site Data
- Apple Safari: Preferences → Privacy → Manage Website Data
- Microsoft Edge: Settings → Cookies and site permissions → Manage and delete cookies and site data
Note: blocking strictly necessary cookies will prevent you from logging into the Platform. Blocking analytics or functional cookies will not prevent Platform access but may reduce functionality.
4.3 Third-Party Opt-Outs
For third-party cookies used on the marketing website, you may opt out through the following mechanisms:
- Google Analytics: Install the Google Analytics Opt-out Browser Add-on.
- Google Ads: Manage ad personalization at Google Account Privacy settings.
- LinkedIn: Adjust ad preferences at .
- Intercom: The Intercom messenger may be dismissed from the Platform interface. No Intercom cookies will be set if the messenger is not activated.
5. Cookies Set by Third-Party Services Within the Platform
The CompliRun Platform is built using third-party infrastructure services that may set cookies in the course of providing their services. These include:
- Stripe (payment processing): Stripe may set cookies on payment-related pages to detect fraudulent transactions. These cookies are set only when you access the billing section of the Platform.
- Intercom (customer support): When you use the in-Platform support widget, Intercom sets session cookies to maintain the chat state and identify returning users.
- Datadog (application monitoring): Datadog does not set cookies visible to end users. Application performance monitoring occurs server-side.
For information about cookies set by these services, refer to their respective privacy and cookie policies: Stripe Privacy Policy, Intercom Privacy Policy.
6. Cookies and Compliance Monitoring Data
The evidence and compliance data collected from your infrastructure integrations is not stored in cookies. Evidence data is stored server-side in CompliRun's encrypted database infrastructure. Cookies are used only for session management, preference storage, and the analytics and marketing purposes described in this policy. Your infrastructure credentials (API keys, OAuth tokens) are not stored in cookies under any circumstances.
7. Do Not Track Signals
Some browsers have a "Do Not Track" feature that sends a signal to websites indicating that you do not want to be tracked. CompliRun does not currently alter its data collection practices in response to Do Not Track signals, as there is no commonly accepted standard for how websites should respond to such signals. You may use the opt-out mechanisms described in Section 4 to limit data collection.
8. Updates to This Cookie Policy
CompliRun may update this Cookie Policy from time to time to reflect changes in the cookies we use or changes in legal requirements. The "Last updated" date at the top of this page reflects the most recent revision. We will notify you of material changes to this Cookie Policy through the same channels as our Privacy Policy updates — via email or in-Platform notice at least 30 days before changes take effect.
If we add new cookie categories that require consent (such as adding marketing cookies where none existed before), we will present you with a new consent banner rather than relying on prior consent.
9. Contact
For questions or concerns about our use of cookies, contact CompliRun at:
CompliRun, Inc.Attn: Privacy
500 Boylston Street
Boston, MA 02116
United States
Email: contact@complirun.com
Phone: +1 (617) 384-5029
See also our Privacy Policy for a complete description of how we collect, use, and protect your personal data.