Review Canopy
Home How It Works Testimonials FAQ About
Get Started Login

Legal

Cookie and Browser Storage Policy

Effective date: August 13, 2026
Last updated: August 20, 2026

This policy explains the first-party cookies and browser storage used by the current Review Canopy application. It should be read with the Privacy Policy.

Essential server session cookie

Review Canopy uses the PHP server session cookie configured by the hosting environment. It supports login sessions, account security, CSRF protection, public-form security, success messages, and OAuth state, nonce, and PKCE transactions. The cookie contains a random session identifier rather than the account password or form contents.

The application configures this cookie as HttpOnly and SameSite=Lax, with Secure enabled in HTTPS production. Its browser lifetime is the current browser session, although associated authenticated server sessions are also subject to configured idle and absolute expiration limits.

Notice acknowledgement records

rs_cookie_consent
Uses the legacy value accepted after the visitor dismisses the activity-cookie notice. It remembers that the notice was acknowledged; it does not control analytics or marketing permission. It is first-party, readable by page JavaScript, SameSite=Lax, Secure on HTTPS, and configured for approximately 12 months.
cookie_consent in local storage
Mirrors the notice acknowledgement so the site can avoid showing the notice again. It remains until browser storage is cleared.

Review activity identifiers

rs_vid
A random first-party visitor identifier used to associate review-page and attribution activity. It is HttpOnly, SameSite=Lax, Secure on HTTPS, and configured or refreshed for approximately 365 days. The application stores an HMAC hash of the identifier in database activity records rather than the raw cookie value.
rs_sid
A random first-party activity-session identifier. It is HttpOnly, SameSite=Lax, Secure on HTTPS, and configured or refreshed for approximately 30 minutes. The application stores an HMAC hash of the identifier in database activity records.

When activity identifiers are used

Review Canopy records business-page visits, form and modal activity, durations, review-link clicks, coupon activity, direct-review activity, and embedded-widget activity without requiring the activity-cookie notice to be acknowledged. These measurements create or refresh rs_vid and rs_sid when cookies are available. Blocking those cookies does not prevent an individual event from being counted, but it can prevent accurate visitor and session grouping.

The follow-up and marketing checkbox on a customer form is separate from analytics. Its stored value applies to future follow-ups, newsletters, coupons, updates, and offers; selecting or clearing it does not enable or disable activity measurement.

Temporary interface storage

Business pages use session storage to remember temporary coupon-prompt dismissal, coupon-claim, and marketing-signup interface state for the current browser tab. The direct-review modal uses local storage keyed to the business page to remember that a review was submitted and avoid immediately showing the form again. These interface values do not contain the submitted review, name, email, or coupon code.

External-provider cookies and requests

If Google or Microsoft sign-in is enabled and selected, the browser leaves Review Canopy for that provider. The provider can use cookies or other storage under its own policy. Third-party review sites, business links, Google Fonts, and hosts serving business-supplied images can also receive ordinary browser requests when their resources or pages are loaded. Review Canopy does not control third-party cookies.

Your controls

You can clear or block cookies and site storage in browser settings. Blocking activity identifiers can reduce the accuracy of unique-visitor and session measurements, while blocking the essential session cookie can prevent login, protected forms, OAuth callbacks, and other security-dependent functions from working. Clearing rs_cookie_consent and the matching local-storage value causes the activity-cookie notice to appear again.

Contact

Cookie-policy questions can be sent to feed@elleon.ai.

Product and legal review required

Confirm the classification and lawful basis for rs_vid and rs_sid in each supported region; whether a decline or settings control is required; the treatment of embedded widgets and direct reviews; production cookie names and durations; and the effective date.

© 2026 Review Canopy - Powered by El Leon
Privacy Terms Cookies Accessibility About

Review Canopy uses an essential session cookie and first-party identifiers to measure visits and review activity. See how they work.