HELM Cookies And Tracking Policy
Effective Date: Feb 14, 2026
For Questions: hello@itshelm.com
This Cookie & Tracking Policy explains how HELM (“we,” “us,” “our”) uses cookies, SDKs, pixels, and similar technologies across our website, mobile app, and services (“Platform”). It works together with our Privacy Policy and Terms of Service.
Note: HELM currently operates only in the United States. International rules will apply once we expand globally.
1. What Are Cookies & Similar Technologies?
Cookies
Small files stored in your browser that remember settings, activity, and preferences.
SDKs
Code inside mobile apps enabling analytics, login, and device-level functions.
Pixels / Web Beacons
Tiny images that load to measure views, opens, and engagement.
Local Storage
Browser-based storage for preferences (language, UI settings).
Device Identifiers
IDFA/AAID used for fraud prevention and app attribution.
2. Why We Use Cookies
We use cookies for the following purposes:
Essential & Functional
sign‑in, account security, session continuity, feature enablement, remembering preferences (language, roles, cookie choices).
Security & Fraud Prevention
detecting abuse, preventing unauthorized access, rate‑limiting, and protecting payments (e.g., device fingerprinting for fraud signals).
Payments
facilitating checkout, tokenization, and dispute/chargeback handling through Stripe.
Analytics
measuring traffic and usage, improving features, debugging performance.
Personalization
remembering your settings and tailoring content.
Marketing/Attribution (where permitted)
measuring the effectiveness of campaigns and referrals; cross‑context behavioral advertising where allowed by law and your preferences.
3. Cookie Categories
Category | Purpose | Who Sets it | Examples (non‑exhaustive) | Typical duration |
|---|---|---|---|---|
Essential | Authentication, session management, load balancing, core functionality | HELM (first‑party) | session token, csrf token, consent state | Session up to 12 months |
Security/Fraud | Preventing abuse, account takeover, and payment fraud | HELM + partners | device reputation, rate‑limit flags | Session up to 24 months |
Payments (Stripe) | Card tokenization, checkout flow, fraud prevention (e.g., Radar) | Stripe (third‑party) | may include cookies like __stripe_mid and __stripe_sid or equivalent tokens used to distinguish devices for fraud prevention | 30 minutes to 2 years* |
Analytics | Measure traffic/sources, product performance | HELM + analytics providers | page_view, referral/source, performance metrics | Session to 24 months |
Personalization | Remember preferences, saved filters, locale | HELM | ui prefs, language | Session to 12 months |
Marketing/Attribution | Campaign measurement and, where allowed, cross‑context advertising | HELM + partners | referral code, campaign id | Session to 24 months |
Durations shown are typical. Exact lifetimes depend on the provider and your browser/device settings.
4. Stripe-Related Tracking on HELM
Stripe may set cookies and device signals for:
fraud prevention
checkout functionality
regulatory & PCI compliance
HELM never stores full card numbers or CVV. Stripe’s privacy terms apply.
5. Your Choices & Controls
Cookie Banner & Preference Center
On your first visit (and periodically thereafter), you may see a banner where you can accept, reject, or customize non‑essential cookies. You can revisit preferences via the "Cookie Settings" link in the footer.
Mobile OS settings allow you to reset or limit advertising identifiers (IDFA/AAID) and adjust app tracking permissions.
Browser & Device Controls
You can disable images in your email client or unsubscribe from marketing emails via links in those messages.
Email Pixels
You can disable images in your email client or unsubscribe from marketing emails via links in those messages.
Global Privacy Control (GPC)
Where applicable, we honor GPC signals as an opt‑out of cross‑context behavioral advertising (often termed “sale”/“sharing” under some U.S. state privacy laws). You can also use our Do Not Sell/Share link in the footer to adjust settings.
Do Not Track (DNT)
Our Platform does not currently respond to legacy DNT signals. Use GPC or the cookie preferences instead.
Third-Party Opt Outs
Some providers offer their own opt‑outs/controls. Using those tools does not affect strictly necessary cookies used to provide core services (e.g., payments).
6. Compliance Notes
US State Laws (e.g., CA/CO/CT/UT/VA and similar)
We provide mechanisms to opt out of sale/sharing/targeted advertising and to limit certain processing where required. The cookie banner and preference center are designed to reflect these obligations.
Children
We do not knowingly use cookies to target users under 16, and we do not knowingly sell/share personal information of minors.
Security/PCI
Cookies used for security (including payment fraud detection via Stripe) are considered strictly necessary.
Recordkeeping
We maintain records of consent signals as required by applicable law.
International Appendix (non‑operative until expansion)
If HELM launches outside the U.S., we will adapt our cookie banner and consent flows to the relevant region (e.g., EEA/UK prior consent for non‑essential cookies; granular toggles; clear withdrawal options). See Appendix A below.
7. How we update this Policy
We may update this Cookie Policy to reflect changes in law, technology, or our practices. Material changes will be posted with a new Effective Date. Your continued use after the Effective Date constitutes acceptance of the updated Policy.
