The Monopaly marketing page and application use different technologies. The marketing page does not run application analytics. The app uses sign-in cookies, analytics and browser storage for features such as calling sessions and message drafts.
1. Cookies and similar technologies
A cookie is a small value stored by your browser and sent with requests to the relevant website. Local storage keeps data in a browser until it is removed by the application, you or the browser. Session storage is normally limited to a tab session, though browser restoration can affect how long it remains available.
This policy covers monopaly.com and the Monopaly application at app.monopaly.com, operated by Gravitate Software Incorporated. Cookies on hosted Google or WorkOS sign-in pages are governed by those providers’ notices.
The homepage can ask the app whether you have a valid signed-in session and send you directly to your dashboard. Your browser sends the existing sign-in cookie to the app for this check; the homepage receives only a signed-in status. This feature does not create a new tracking cookie.
2. Authentication and security cookies
These support sign-in, authentication security and protection of the service. Cookies may only be created when you use the corresponding sign-in flow. The lifetimes shown are configured defaults; browser restrictions, session settings and sign-out can shorten them.
| Cookie | Purpose | Typical lifetime |
|---|---|---|
wos-sessionWorkOS AuthKit | Maintains a protected authentication session for the app. | Up to 400 days by SDK default. The authenticated session itself may expire sooner. |
wos-auth-verifier-<hash>WorkOS AuthKit | Verifies a standard sign-in request using PKCE. | 10 minutes. |
monopaly-google-oauth-<state>Monopaly | Protects the Google sign-in flow and preserves the intended return path. | 10 minutes; cleared during callback handling. |
Cloudflare provides website hosting and security. Depending on the security features and challenges applied to a request, it may use cookies such as __cf_bm, cf_clearance or _cfuvid. These are conditional security cookies, not cookies every visitor necessarily receives. See Cloudflare’s cookie descriptions for their purposes and lifetimes.
3. Application analytics
PostHog helps us understand use of the app, diagnose errors and, where enabled, review session activity. It uses a first-party cookie named ph_<project_token>_posthog, with a default lifetime of 365 days, along with local and session storage. Stored identifiers can be associated with your account and workspace. Local storage does not have the cookie’s automatic expiry.
Analytics initializes on app pages, including before login. The app currently does not present a cookie-consent preference panel. The marketing landing page does not initialize PostHog, although a parent-domain cookie created while using the app can accompany later requests to monopaly.com.
PostHog may store additional session and feature state using keys beginning with ph_, including tab/window identifiers. See PostHog’s persistence documentation and our Privacy Policy for more information.
4. Functional browser storage
| Storage | Purpose | Duration |
|---|---|---|
monopaly.calling.client-instance.v2monopaly.calling.power-start-command.v2monopaly.calling.power-session.v1 | Identifies a calling tab and helps start or recover its calling session. | Session storage; may also be cleared as the calling workflow progresses. |
dialer:add-contacts:<workspaceId> | Preserves selected contacts while moving to the cadence editor. | Session storage; removed when the selection is resumed. |
monopaly:conversation-draft:<workspaceId>:<threadId> | Saves message draft text and the selected sending number. | Local storage; no fixed expiry. Removed by application logic or when browser data is cleared. |
manager-dashboard-columns:<workspaceId> | Remembers dashboard column preferences. | Local storage; no fixed expiry. |
Draft text can remain on a shared device. Clearing cookies alone may not remove local storage; use your browser’s site-data controls if you want to remove both.
5. Mapping features
When you use a Mapbox-powered map, its SDK can store map-usage and telemetry state in local storage under mapbox.eventData:, mapbox.eventData.uuid: and mapbox.eventData.uuidTimestamp: key prefixes. This supports map-event reporting and related service operation.
The SDK refreshes its anonymous identifier after 24 hours when accessed. This is not a 24-hour expiry for all Mapbox storage. Map searches and requests also send information needed to deliver the map or address result.
6. Your controls
You can inspect, block or remove cookies and site data through your browser settings. Controls differ by browser, and blocking third-party cookies alone may not block first-party analytics storage. Removing data can sign you out, erase drafts and preferences, or interrupt calling features. Clearing browser data does not delete information already held on our servers or by a provider.
For a privacy request or questions about analytics, email thomas@gravitateinc.com. Available rights depend on your location and applicable law; see the Privacy Policy. Agreeing to the Terms of Service is not a substitute for cookie consent where separate consent is required.
7. Updates and contact
We may update this notice as technologies and features change. The date at the top shows when it was last updated. Contact Gravitate Software Incorporated at thomas@gravitateinc.com with questions.