Cookie Policy
Last updated: August 28, 2026
Introduction
This Cookie Policy explains how OneArbitrage ("we," "us," or "our") uses cookies and similar technologies when you use our public marketing website, complete sign-up or sign-in, use our customer dashboard and related subscription software on the web (including when you open billing or brokerage features for RSA), or open legal pages from our native iOS and Android apps. Read it together with our Privacy Policy, which describes how we handle personal information more broadly.
Cookies are small text files stored on your device. Similar technologies include local storage, session storage, pixels, and on mobile apps, secure device storage used in place of browser cookies for sign-in. We use cookies and similar technologies where described below.
Our native iOS and Android apps generally do not use browser cookies for core product sign-in; they use secure storage on the device and open Cognito, Stripe, and supported brokerage flows in the system browser, where those providers may set their own cookies. See also the "Native mobile apps" section below.
What we use and why
- Theme preference (local storage). Our marketing site stores your light or dark theme choice in browser local storage so the page can apply the correct appearance before scripts load. This is a preference, not essential for sign-in. The customer dashboard may use its own theme or layout preferences where the product exposes them.
- Sign-in flow (session storage). When you sign in, we use standard OAuth with PKCE. Short-lived values (such as the PKCE verifier and OAuth state) may be kept in session storage on our marketing site until the flow completes. If you arrive with a referral code in the URL (for example ?ref=), we may store that value in session storage on the marketing site for the same browser session until your customer account is first provisioned or the session ends. These are not HTTP cookies, but we describe them here for transparency.
- Session cookie (customer dashboard). When you use our customer dashboard on its own domain, we may set an HttpOnly session cookie so you stay signed in securely. That cookie is scoped to our customer application origin. The marketing site does not read that cookie directly; it may send a credentialed request to check whether you already have a session.
- Identity provider (third-party domain). When you authenticate, our identity provider (for example, Amazon Cognito Hosted UI) may set cookies on its domain as part of login, session, or security. Those cookies are managed under the provider's policies.
- Payments (Stripe third-party domain). When you subscribe or manage billing through Stripe Checkout or the Stripe Customer Portal, Stripe may set cookies on Stripe's domains. Those cookies are managed under Stripe's policies, not ours.
- Legal pages opened from the app (session storage). When our iOS or Android app opens this marketing site for Privacy, Terms, or similar pages, the URL may include ?from=app. We may store a short-lived flag in browser session storage on our marketing origin so footer links between legal pages keep an app-appropriate layout until you close that browser tab or session.
- Discord community status (third-party API). Our marketing homepage may request public server stats from discord.com when you scroll to the community section. We display an approximate total member count and a join link only; we do not list individual Discord usernames on this site. Discord may set or read cookies on its domains if you follow an invite link, under Discord's privacy policy.
Native mobile apps
- Sign-in (secure storage). After you complete Cognito Hosted UI in the system browser, the OneArbitrage app stores authentication tokens in the device's secure storage (for example, the iOS keychain or Android encrypted keystore), not in browser cookies on our marketing site.
- Referral capture (secure storage). If you open the app from an invite deep link (for example onearbitrage://join?ref=), we may hold the referral code in secure storage until your customer account is first provisioned, consistent with our web referral rules described above.
- Onboarding preferences (app storage). The app may use on-device storage (for example AsyncStorage) for product preferences and to avoid duplicate onboarding analytics beacons within a session. This is separate from marketing-site browser cookies.
- Stripe and broker flows (third-party browser). Subscription checkout, billing portal, and supported brokerage authorization open in the system browser. Stripe, your broker, and Cognito may set cookies on their domains under their policies, the same as when you use those flows on the web.
Analytics and marketing technologies
Our public marketing site loads Google Analytics 4 (Google LLC) to measure site usage (for example, pages viewed and general traffic patterns). Google may set or read cookies and similar identifiers on its domains as part of that service. When we run Meta (Facebook/Instagram) advertising, we may load the Meta Pixel (Meta Platforms, Inc.) on the marketing site to measure ad performance and site actions such as starting sign-up. Meta may set or read cookies and similar identifiers on Meta domains as part of that service.
On production builds of our iOS and Android apps, we may use the Meta App Events SDK to measure onboarding and subscription actions (for example, paywall views or checkout starts). Those events are paired with server-side Conversions API calls that share an event identifier for deduplication, as described in our Privacy Policy. The SDK does not use browser cookies on our marketing site; it uses Meta's app measurement libraries subject to Meta's policies. On iOS, we may request permission through Apple's App Tracking Transparency prompt before enabling certain advertising measurement.
Where required by law, we will obtain consent before non-essential analytics or advertising cookies (web) or equivalent measurement (app) are used.
Your choices
You can control cookies and similar storage through your browser settings (for example, blocking or deleting cookies and clearing site data). If you block essential cookies or storage needed for sign-in, checkout, or your dashboard session, parts of the Services may not work correctly. On the marketing site you can change theme in the UI where offered; clearing local storage may reset the theme to the default until you choose again.
On iOS and Android, you can clear app data or reinstall the app to reset on-device storage; sign out in the app before clearing data if you want to end your session cleanly. On iOS, you can change tracking permission in Settings after an App Tracking Transparency prompt. On Android, you can limit ad personalization or reset your advertising ID in system settings.
Changes
We may update this Cookie Policy from time to time. We will post the updated version on this page and revise the "Last updated" date when we make material changes.
Contact
Questions about this Cookie Policy or our use of cookies and similar technologies: privacy@onearbitrage.com. For general product or account help (including if sign-in, checkout, or billing stops working after you change browser storage), see our Contact page, including support@onearbitrage.com.
This page describes our current practices; it is not legal advice. Have your counsel review before relying on it for regulatory or contractual purposes.