Cookie Policy
Sylvent Corporation, trading as effect.com
Last updated: August 22, 2026
1. Who this policy is from, and what it covers
This Cookie Policy is issued by Sylvent Corporation, a Delaware corporation with its registered office at 131 Continental Drive, Suite 301, Newark, DE 19713, United States, trading as effect.com (“Effect”, “we”, “us”, “our”). Sylvent Corporation is the entity responsible for the processing described here. As a matter of Mexican law this document, read together with our Privacy Policy, forms part of our aviso de privacidad.
It covers every host we operate: the website at effect.com, the writing at blog.effect.com, and the client workspace at app.effect.com. One answer covers all three. You are asked once, on whichever host you reach first, and the answer you give is honoured on the other two without asking again.
It explains, without abbreviation: what a cookie is; the three optional purposes we ask you about and the vendor behind each; the two things that run without asking and why; every cookie and storage key by name, with who sets it, where it lands and how long it lasts; how to change your mind and precisely what changes when you do; and what we record about the answer you gave.
Effect sells analytics software to non-bank lenders. We do not advertise, we do not sell personal information, and we do not share personal information for cross-context behavioural advertising. No control on this website can switch advertising on, because there is nothing to switch on.
2. What a cookie is, in plain terms
A cookie is a small text file that a website asks your browser to keep and to send back on your next request. It is how a site recognises that two page views came from the same browser. Related technologies do the same job by other means: local storage and session storage keep values inside the browser without sending them automatically, and a pixel or beacon is a request whose only purpose is to report that something happened. Where this policy says “cookie” it means all of these, and the tables in section 6 say which is which.
A first-party cookie is set on our own domain. A third-party cookie is set on somebody else’s domain by content we placed inside our page. We can delete the first kind for you. We cannot delete the second kind, and we say so wherever it applies.
3. Strictly necessary. Always on, never asked about
These make the site and the workspace work. They carry no measurement, they build no profile, and there is no version of this site that functions without them. Under Mexican and European rules they do not require consent, because they are what delivers the service you asked for.
Three of them exist only because you were asked a question. A record of a consent answer is the one category that never needs consent of its own: if it did, refusing would erase the proof of the refusal and you would be asked again on every page.
4. The three optional purposes
Everything that measures you waits for your answer. The card asks about three purposes, not three vendors, and you may grant one while refusing another.
Analytics, counting what is read. How many people opened a page, how far down an article they scrolled, which control they pressed, whether a form was submitted and on which page. It answers how many. Three tools serve this purpose: Google Analytics 4 loaded through Google Tag Manager, PostHog, and Vercel Speed Insights.
Recording, replaying one visit. Mouse movement, scrolling and clicks during your visit, plus aggregated heatmaps built from many visits. It answers why a page works or does not. One tool serves it: Microsoft Clarity. We keep this apart from counting, and ask about it separately, because a replay of one visit is a materially larger amount of information about you than a tally is.
Embeds, third-party content inside our pages. Today that is the Zoom booking calendar and nothing else. Refusing it costs you the calendar and nothing else. A button in its place will fetch the calendar for that visit alone, without changing your stored answer, because asking to see a calendar is not the same as agreeing to be measured.
Before you answer, nothing has been contacted
Until you grant the purpose that carries it, a page of ours requests nothing from Google, Microsoft, PostHog, Vercel or Zoom, and none of their cookies is written. Refusing changes nothing about that: after you press Reject, the only cookies you carry from us are the record of the refusal and the identifier that ties a future withdrawal to it, both named in section 6.
What each tool does, named individually
Google Analytics 4, through Google Tag Manager. Counts pages viewed, page changes made without a full reload, opening the demo panel and the wording of the control that opened it, which calendar you chose, file downloads, links out to other sites, and the fact that a form was submitted together with its type and the page it sat on. It never receives a field you typed. Scroll depth is enabled in the tag manager container rather than in our own code, so we name it here rather than pointing you at a line in our repository. Advertising and personalisation signals are denied permanently rather than conditionally.
PostHog, on servers in the United States. Counts named product steps rather than watching a screen. The dictionary of those steps lives in our own repository at src/lib/events.js. They cover the journey through the site and the workspace and nothing else: opening the demo panel; submitting a contact or demo form, recording its type and page but never a field you typed; reaching, submitting and confirming registration; an account approved or refused; signing in and failing to sign in; a password reset asked for and completed; a profile saved; a colleague invited, accepted or removed; the steps of the first-run guide; a workspace opened, a lender opened, a document or data extract requested; a document opened and how far into it somebody read; and what our own email did. Two further events come from the PostHog library itself rather than from that list, and we would rather name them than let you find them: a page view carrying the address of the page you are on, and a page-leave event the library emits by itself. Nothing is captured merely because it happened: no click, keystroke or form event is collected unless it is one of the named steps. When you are signed in, PostHog stores a coded reference to your account rather than your name or your email address.
Vercel Speed Insights. Measures how quickly the page rendered for you. It writes nothing to your browser.
Microsoft Clarity. Records how the site is used and builds heatmaps. We load it on the marketing website only, and the loader tests both the path and the hostname, so it never starts inside the workspace at app.effect.com. Clarity publishes no call that ends a session, which means a recording begun on the marketing site would keep running if you moved into the workspace without a page reload. That is why the entire product tree is marked data-clarity-mask, which masks what reaches the recorder at the element itself rather than relying on where the recorder started.
The Zoom booking calendar. A page of Zoom’s placed inside one of ours. Once it is there, Zoom sets its own cookies on its own domains, under Zoom’s notice rather than ours, and Zoom receives your IP address and basic device information.
What a recording never contains
The contents of form fields are masked before anything leaves your browser. What you type into a name, company, email, phone or message field is never recorded and never transmitted. This rests on two independent grounds rather than one setting: Microsoft Clarity masks the contents of input fields in every masking mode, and we additionally mark our own forms as masked in the page itself, which overrides any console setting.
5. Two things that do not wait for your answer, and neither is measurement
We would rather name them than leave them out.
Sentry, on servers in the United States, receives a technical error report when our own software fails: the error, the page it happened on with the query string removed, and the software version. It carries no cookie, no advertising identifier and no account, it writes nothing to your browser, and it is sent only when something breaks.
Cloudflare Turnstile runs on the sign-in and registration screens at app.effect.com as an anti-abuse check. It receives your IP address and returns a token proving a person filled in the form. It receives no field you typed. It is not behind the cookie card because it is what protects the sign-in itself.
Neither is used to build a profile of you, and neither advertises anything.
6. Every cookie and storage key, by name
A lifetime shown as the vendor’s own is one we have not set ourselves and do not control; it is governed by that vendor’s notice.
6.1 Strictly necessary, always on
| Name | Set by | Where it lands | Lifetime |
|---|---|---|---|
| effect-consentYour answer to the cookie card. It sits on the parent domain so one answer is honoured on effect.com, app.effect.com and blog.effect.com without asking three times. | Effect | .effect.com | 1 year |
| effect-consentA copy of the same answer, kept for visitors who answered before the cookie existed. | Effect | Local storage | Until cleared |
| effect-consent-idA random identifier whose only job is to tie a withdrawal to the answer it withdraws. It is never sent to any measurement tool and it is cleared with the answer. | Effect | .effect.com | 1 year |
| effect-internalMarks one of our own browsers so our visits load no measurement tool. It can only switch measurement off. | Effect | .effect.com | 1 year |
| sb-<project>-auth-tokenKeeps you signed in to the workspace. Host-only, HttpOnly, Secure, SameSite=Lax, so it is never sent to the marketing site and no script can read it. A long session is split across numbered cookies of the same name. | Supabase, for us | app.effect.com | The session |
| Turnstile checkThe anti-abuse check on the sign-in and registration screens. It receives your IP address and no field you typed. We set no cookie for it; anything Cloudflare sets is on its own domain and under its own notice. | Cloudflare | challenges.cloudflare.com | Cloudflare’s own |
Conclusion. Six entries, and only two of them are about you at all: the session that keeps you signed in, and the record of the answer you gave. Refusing everything leaves you carrying the refusal and nothing else.
6.2 Analytics, only if you grant it
| Name | Set by | Where it lands | Lifetime |
|---|---|---|---|
| _gaTells one browser from another so visits can be counted. | .effect.com | About 13 months | |
| _ga_QJE8KHKRL7Holds the session state for the one Google Analytics property we run. | .effect.com | About 13 months | |
| ph_phc_<key>_posthogThe PostHog identifier for this browser. The same value is kept in local storage under the same name, and three further keys go to session storage, which your browser discards when the tab closes. | PostHog | .effect.com | About 12 months |
| Speed InsightsA measurement of how quickly the page rendered for you. It writes nothing to your browser. | Vercel | No cookie | Nothing stored |
Conclusion. Counting costs you two Google cookies and one PostHog identifier, all first-party, all deletable by you in your browser.
6.3 Recording, only if you grant it
| Name | Set by | Where it lands | Lifetime |
|---|---|---|---|
| _clckTies this browser to its Clarity identifier so repeat visits are read as one visitor. | Microsoft Clarity | .effect.com | About 1 year |
| _clskJoins the pages of a single visit into one replay. | Microsoft Clarity | .effect.com | About 1 day |
| CLIDIdentifies the browser to Clarity’s own service. | Microsoft | .clarity.ms | Microsoft’s own |
| MUIDMicrosoft’s browser identifier, set by the recorder’s service rather than by us. | Microsoft | Microsoft’s own domains | Microsoft’s own |
Conclusion. Two of these four are on our domain and we can clear them; two are on Microsoft’s and we cannot. Withdrawing consent sends Clarity its documented eraser signal, which clears the two on our domain.
6.4 Embeds, only if you grant it or ask to see the calendar
These are set by Zoom and by Zoom’s own providers from inside the booking calendar, on their own domains. We do not read them and we cannot delete them for you.
| Name | Set by | Where it lands | Lifetime |
|---|---|---|---|
| __cf_bmThe anti-bot check Zoom runs on its own scheduling page. | Cloudflare, for Zoom | .scheduler.zoom.us | Zoom’s own |
| _sp_id.f650Zoom’s persistent visitor identifier, for the analytics Zoom runs on that page. | Zoom | scheduler.zoom.us | Zoom’s own |
| _sp_ses.f650The session half of the same Zoom analytics. | Zoom | scheduler.zoom.us | Zoom’s own |
| mA device signal Stripe sets from inside Zoom’s page rather than from ours. We receive nothing from it. | Stripe | m.stripe.com | Stripe’s own |
Conclusion. Every cookie in this group belongs to somebody else. This is the whole reason the calendar is a separate question rather than part of analytics: granting it hands a third party a direct relationship with your browser that we cannot end on your behalf.
7. Changing your mind, and exactly what changes
Select Cookie preferences in the footer of any page of this website, or in the foot of the workspace at app.effect.com, to reopen the card and change your answer at any time. One answer covers all our hosts, so changing it in either place changes it everywhere. You can also control cookies through your browser settings; disabling some cookies may affect how the site works.
Saying that withdrawal stops everything would not be true. Tool by tool, here is what actually happens.
- Google Analytics 4
- What withdrawal does: The tag manager is told analytics storage is denied and collection stops.
- What it does not do: The _ga and _ga_QJE8KHKRL7 cookies already in your browser are not deleted by us. They expire on the schedule in section 6.2, and you can delete them yourself.
- Microsoft Clarity
- What withdrawal does: Both documented signals are sent: consent withdrawn, which ends the session, and the eraser, which clears the Clarity cookies on our domain.
- What it does not do: Cookies on Microsoft’s own domains are outside our reach.
- PostHog
- What withdrawal does: Opted out and reset. Collection stops, and the identifier this browser was carrying is dropped and replaced.
- What it does not do: The cookie itself is not deleted; what changes is the value inside it.
- Vercel Speed Insights
- What withdrawal does: Measurement stops.
- What it does not do: Nothing to delete; it never stored anything.
- Zoom calendar
- What withdrawal does: Not placed in any further page.
- What it does not do: Cookies Zoom already set on its own domains remain, under Zoom’s notice.
Conclusion. Withdrawal stops collection from that moment forward. Nothing that was already sent can be unsent, and we will not pretend otherwise.
8. The record of your answer
Every answer you give the cookie card is also sent to our own server and stored in a table we control. That includes a refusal, and it includes a change of mind.
Each record holds: the random identifier from the effect-consent-id cookie; what you chose; which purposes were granted; the version of this policy that was on your screen; which of our hosts you answered on; the path of the page you answered from; whether it was a first answer or a change; the IP address the answer arrived from; the user-agent string your browser sent; the time; and, only if you happened to be signed in as you answered, your account.
The table is append-only. Changing your mind writes a new record; nothing is edited or deleted. Records are kept for three years and then deleted by a scheduled job.
We keep it because the burden of demonstrating consent falls on us, and a value that exists only inside your own browser demonstrates nothing. The identifier is random, is generated by your browser, is never sent to any measurement tool, and is cleared when the answer it carries is cleared. The IP address is stored for provenance and is shown to our own staff only coarsened to its first three octets. If sending this record fails, your answer still stands: your browser stores it and acts on it first, and the record is the part we are prepared to lose.
9. Your rights over what is described here
Withdrawing consent is a right, not a courtesy, and section 7 is how you exercise it. Withdrawal does not affect the lawfulness of anything done while consent stood.
If you are in Mexico, the ARCO rights (acceso, rectificación, cancelación, oposición) apply to the data described in this policy, and the procedure for exercising them, including who to write to and how long we take to answer, is set out in the Privacy Policy under “Your rights”. If you are in the European Economic Area or the United Kingdom, the rights of access, rectification, erasure, restriction, portability and objection apply in the same way. If you are a California resident, you have the rights to know, delete and correct, and the right to opt out of the sale or sharing of personal information, which we do not engage in.
10. Changes to this policy
We may update this policy. The updated version is posted with a new “Last updated” date, and that date is recorded against your cookie answer, so a decision can always be read against the words that were on screen when you made it.
11. Contact
Sylvent Corporation, 131 Continental Drive, Suite 301, Newark, DE 19713, United States.
For anything in this policy, including a request to exercise a right over the data it describes: legal@effect.com. For general enquiries: info@effect.com.