Legal
Cookie Policy
Renaro uses no cookies at all on this marketing site, and only strictly necessary cookies and browser storage in the signed-in product. This policy lists every category, what it does, and what happens if you block it.
What this policy covers
This policy explains how Renaro ("Renaro", "we") uses cookies and similar technologies - including browser local storage and software development kits in our mobile apps - across the surfaces we operate: the marketing site at renaroapp.com, the operator dashboard at app.renaroapp.com, hosted booking and tracking pages served under app.renaroapp.com for operators' customers, and the Renaro Driver and Renaro passenger mobile apps.
It should be read together with the Privacy Policy, which explains what personal data we process and why. Where an operator embeds or links to Renaro-hosted booking pages from their own website, the operator's own cookie notice governs their site; this policy governs the Renaro-hosted pages themselves.
What cookies and similar technologies are
Cookies are small text files a website asks your browser to store and send back on later requests, typically to keep you signed in or remember choices. Browser local storage serves a similar purpose but is only readable by the site that wrote it and is not sent with every request. Mobile apps do not use browser cookies; they keep equivalent state in app storage on the device.
The marketing site sets no cookies
renaroapp.com - the site you are reading now - sets no cookies of any kind. There is no analytics script, no advertising pixel, no session identifier, no consent banner because there is nothing to consent to. Fonts are self-hosted and pages are static files.
- No first-party or third-party cookies are set by any page on renaroapp.com.
- No analytics, tag managers, advertising pixels, fingerprinting, or cross-site tracking run on this site.
- Contact links open your own email client; nothing is submitted through the site itself.
Strictly necessary cookies in the operator dashboard
The operator dashboard at app.renaroapp.com is a signed-in product. Authentication is provided by WorkOS AuthKit, which sets session cookies (served via auth.renaroapp.com) that prove who you are on each request. Without them, sign-in does not work. These cookies are strictly necessary, are not used for advertising or cross-site tracking, and expire on the schedule configured for your organization's sessions.
The dashboard also uses browser local storage for interface state - for example your theme choice, dismissed hints, and cached session context that lets the app resume quickly. This data stays in your browser, is scoped to your account and organization, and is cleared when you clear site data.
| Category | Set by | Purpose | Type |
|---|---|---|---|
| Authentication session | WorkOS AuthKit (auth.renaroapp.com) | Keeps you signed in; proves your identity on each request | Strictly necessary cookie |
| Interface preferences | Renaro dashboard | Theme, layout, and dismissed-hint state | Local storage |
| Session cache | Renaro dashboard | Lets the app resume your signed-in context quickly | Local storage |
| Payment session | Stripe (js.stripe.com) | Fraud prevention and payment-session integrity on pages with payment forms | Strictly necessary cookie |
| Product analytics | PostHog (us.i.posthog.com) | Pseudonymous usage analytics and feature flags for signed-in operators | Local storage (no cookies) |
Product analytics in the dashboard
The signed-in operator dashboard uses PostHog to understand which screens are used and to control feature rollouts. It is configured conservatively: automatic event capture is off, session recording is disabled, and it identifies you only by internal account and organization identifiers plus your role - never by name, email, or phone. It stores its identifier in browser local storage and sets no cookies. Page-view events include the page path, and PostHog records the originating IP address on its servers as part of receiving the request.
This analytics storage is the one thing Renaro sets that is not strictly required to deliver the service. It exists to make the product better for the operators using it, it is never used for advertising, and clearing site data for app.renaroapp.com removes it. If you want it disabled for your organization, contact support@renaroapp.com.
Payment pages load Stripe
Screens that collect a card or bank account - saving a passenger payment method, corporate direct-debit setup, and hosted booking checkout - load Stripe's payment library from js.stripe.com. Card and bank details are entered into fields Stripe hosts and go directly to Stripe; Renaro never sees full card numbers. Stripe sets its own cookies on those pages for fraud prevention and payment-session integrity, as described in Stripe's own cookie and privacy notices.
Maps and fonts make network requests
Map views in the dashboard load tiles from Mapbox, and the dashboard loads its typefaces from Google Fonts. Address search uses Google's services through Renaro's own servers rather than from your browser. When your browser fetches tiles or fonts, the provider receives the network request - including your IP address - under its own privacy terms. These requests are how the content loads; they are not advertising trackers.
- Mapbox serves the map canvas used on dispatch and tracking views.
- Google Fonts serves the dashboard typefaces; the marketing site self-hosts its fonts and makes no such request.
- Stripe, Mapbox, and Google process these requests under their own published privacy policies.
Hosted booking and tracking pages
Operators can offer Renaro-hosted booking pages and live trip-tracking links to their customers. These pages use the same approach as the dashboard: a strictly necessary session identifier when a customer signs in or confirms a booking, Stripe on payment steps, map tiles where a map is shown, and nothing else. No advertising or analytics cookies are set on hosted pages.
Mobile apps
The Renaro Driver and passenger apps do not use browser cookies. They keep sign-in state and preferences in device app storage, and register a push-notification token with the device platform so trip updates can reach you. Push tokens and app permissions are covered in the Privacy Policy and in the permission prompts shown on the device.
Why there is no cookie banner
Consent rules for cookies, including the UK Privacy and Electronic Communications Regulations, exempt storage that is strictly necessary to provide a service the user asked for. The marketing site sets nothing at all, and every cookie in the signed-in product is strictly necessary for sign-in or payment, so no banner is shown there. The one non-essential item - the pseudonymous product-analytics identifier described above - is disclosed here, kept to internal identifiers, and can be disabled on request; if Renaro ever expands analytics or introduces optional cookies, this policy will be updated first and consent collected where the law requires it.
Your choices
You can block or delete cookies and site data through your browser settings at any time. Because everything Renaro sets is strictly necessary, blocking cookies for app.renaroapp.com will prevent sign-in, and clearing site data signs you out and resets interface preferences. The marketing site is unaffected by cookie settings because it sets none.
Changes and contact
Material changes to this policy will be posted here with a new effective date, and operators will be notified through the platform or by email where changes affect the signed-in product. Questions about cookies or this policy: support@renaroapp.com, or write to Renaro, Privacy Desk, London, United Kingdom.