Legal
Cookie & Tracking Policy
Last updated: September 9, 2026
HELM, Inc., a Delaware corporation (“HELM,” “we,” “us,” “our”). This Cookie & Tracking Policy explains how HELM uses cookies, SDKs, pixels, and similar technologies (collectively, “cookies”) on our website, apps, and services (the “Platform”), and the choices you have. It works together with our Privacy Policy and Terms of Service.
Scope note (US-only for now). HELM currently offers services only in the United States. An International Appendix will apply if/when HELM launches outside the U.S.
1. What cookies and similar technologies are
- Cookies are small text files placed on your browser or device that store information.
- SDKs are code libraries within mobile apps performing similar functions.
- Pixels / web beacons are small images or snippets that load when a page or email is viewed, enabling measurement and analytics.
- Local storage (including HTML5) stores data in your browser.
- Device identifiers (e.g., IDFA/AAID) are OS-level IDs used in apps.
2. Why we use cookies
- Essential & functional — sign-in, account security, session continuity, remembering preferences.
- Security & fraud prevention — detecting abuse, preventing unauthorized access, rate-limiting, protecting payments.
- Payments — facilitating checkout, tokenization, and dispute handling through Stripe.
- Analytics — measuring traffic and usage, improving features, debugging performance.
- Personalization — remembering your settings and tailoring content.
- Marketing/attribution (where permitted) — measuring the effectiveness of campaigns and referrals.
3. Cookie categories we use
- Strictly necessary — authentication, session, load balancing, core functionality. Always on.
- Security & fraud — preventing abuse, account takeover, payment fraud.
- Payments — card tokenization, checkout flow, fraud prevention (Stripe).
- Analytics — measuring traffic/sources and product performance. Off unless you choose “Accept all”. When on, HELM uses Google Analytics 4 (Google LLC) for acquisition reporting and PostHog (PostHog Inc., United States region) for product funnels. Google Signals, advertising personalization, and Ads linkage are disabled; PostHog session recording and autocapture are off; PostHog requests are served from a HELM-owned first-party path that does not forward your IP address.
- Preferences — remembering saved filters and locale.
- Marketing — campaign measurement and, where allowed, cross-context advertising.
Durations are typical; exact lifetimes depend on the provider and your browser/device settings.
4. Stripe-related tracking
We use Stripe for payments and payouts. Stripe may set cookies and use device signals to operate checkout, prevent fraud, and meet regulatory obligations (e.g., PCI DSS). HELM does not store full card numbers or CVV. Your payment data and associated tracking are subject to Stripe’s terms and privacy notices.
5. Analytics cookies and identifiers
When analytics is on, Google Analytics 4 sets cookies named “_ga” and “_ga_” plus a stream identifier, and PostHog sets a cookie whose name begins “ph_”, each holding a random device identifier. If you are signed in, PostHog also receives a one-way hashed version of your HELM account ID — never your email address, name, or phone number. HELM sends only a fixed catalogue of events (pages viewed, searches run, booking and application steps) whose properties are limited to categories, counts, and yes/no values; free text is not collected. Login, reset, and invitation links are stripped of their tokens before any page address is recorded.
Analytics retention — PLACEHOLDER — counsel to confirm. The proposed configuration is Google Analytics 4 user-and-event data retention of 2 months and PostHog event retention per that project's settings. These values are a proposal until counsel confirms them.
6. Your choices
HELM's first-party campaign-attribution cookie and all analytics cookies are optional and stay off until you select “Accept all” in our cookie controls. The attribution cookie expires after 30 days. Your cookie choice is remembered for up to one year and can be changed at any time through “Cookie preferences” in the site footer; choosing “Essential only” stops analytics immediately and deletes the analytics cookies from your browser. Blocking strictly-necessary cookies may break core functionality. Global Privacy Control (GPC) overrides a stored preference and disables both attribution and analytics tracking, as does a browser “Do Not Track” setting.
7. Changes
We may update this Policy. The “last updated” date reflects the latest revision.
8. Contact
Questions: hello@itshelm.com.
