Cookie Policy Effective Date: September 8, 2026 Rory Cookie & Tracking Technologies Policy Last Updated: September 8, 2026 Effective Date: September 8, 2026 Entity: Rory LLC ("Rory", "we", "us", or "our") Contact: privacy@joinrory.com Canonical Registry: https://legal.joinrory.com/en-us/cookies This Cookie Policy explains how Rory LLC utilizes cookies, web beacons, local storage, and similar technologies across joinrory.com, app.joinrory.com, rory.page, and rorypay.com. Please read this in conjunction with our Privacy & Data Retention Policy. --- What Are Cookies and Local Storage? Cookies are small data files placed on your browser or device by web servers. They allow websites to remember your device, maintain active authenticated sessions, verify security tokens, and store interface preferences. We also employ web browser local storage and secure HTTP headers to ensure transaction safety and UI state consistency. --- Categories of Cookies We Use 2.1 Strictly Necessary Cookies (Always Active) These cookies are essential for the security, stability, and core operational functions of the Services. You cannot disable these cookies in platform settings, as the Services cannot function without them. | Cookie Name | Purpose | Expiration | Security Flags | |---|---|---|---| | rorysession | Authenticates your active user session across platform requests. | 7 Days (or until logout) | HttpOnly, Secure, SameSite=Lax | | rorycsrf | Cryptographic anti-forgery token protecting forms, coin checkouts, and creator payouts from cross-site attacks (client-readable for CSRF validation headers). | Session | Secure, SameSite=Lax (Non-HttpOnly) | | rorylocale | Stores your selected language preference (e.g., English, Spanish, Chinese). | 1 Year | Secure, SameSite=Lax | 2.2 Payment Gateway Cookies (Checkout Flows) During coin purchases, creator tipping, and payout onboarding, third-party payment providers (including PayPal, Apple Pay, and card processing networks) may set functional cookies on their respective domains to detect fraud, verify compliance, and process payments securely. These cookies are subject to the respective privacy and cookie policies of the payment providers. 2.3 Analytics & Performance Cookies (Optional, joinrory.com Only) On our public landing pages (joinrory.com), we may utilize Microsoft Clarity to evaluate traffic sources, page loading performance, and user interface responsiveness. Clarity collects pseudonymous interaction signals (such as mouse movements and scroll depth) to help us identify broken layouts or performance bottlenecks. Analytics cookies are activated only after you click "Accept" on the cookie banner. We do not use analytics tools to sell your data to data brokers or cross-site advertising networks. --- Cookie Retention and Lifespans Cookies deployed by Rory adhere to strict retention lifecycles: Session Cookies: Expire immediately when you close your browser or log out. Persistent Necessary Cookies: Automatically expire after 7 days (rorysession) or 365 days (rorylocale). Third-Party Analytics: Retained in accordance with Microsoft Clarity retention parameters (typically up to 13 months from collection). --- Managing Your Cookie Preferences 4.1 Cookie Banner Controls When visiting joinrory.com, you can accept or decline non-essential performance and analytics cookies at any time via the cookie settings banner. 4.2 Browser Controls Most web browsers allow you to manage cookie settings, including blocking third-party cookies or deleting existing stored cookies. Please note that if you disable strictly necessary cookies (rorysession and rorycsrf), you will be unable to log in, complete coin transactions, or access creator tools. --- Updates to this Policy We may update this Cookie Policy periodically to reflect technological or regulatory changes. The latest version will always be published at legal.joinrory.com/en-us/cookies. --- Inquiries Questions regarding our cookie practices may be directed to privacy@joinrory.com or legal@joinrory.com.