Legal
Cookie Policy
Last Updated: August 28, 2026
This Cookie Policy explains how Ontario Engineering Solutions Inc., doing business as FieldWorks, uses cookies and similar technologies on our websites and application. It should be read together with our Privacy Policy.
1. Consent Model
FieldWorks presents two consent choices in a cookie banner:
- Necessary: permits only cookies and similar technologies required to operate the Service.
- All: permits necessary technologies plus analytics, performance, and marketing-attribution tooling.
We store your choice in a cookie (fw_cookie_consent) so we can remember it. Analytics, performance, and marketing-attribution technologies do not load until you choose All. You can change your choice at any time through the cookie banner or by clearing the cookie in your browser.
2. Cookies and Similar Technologies We Use
Necessary (always active)
These are required for the Service to function and generally cannot be disabled without impairing it.
| Name | Purpose | Type / Duration |
| --- | --- | --- |
| fw_cookie_consent | Records your cookie choice (all or necessary) | First-party cookie; persistent |
| Session and authentication cookies | Keep you signed in and protect account access (set by our authentication layer, Better Auth) | First-party cookies; session and short-lived persistent |
| __fw_access | Grants access past an optional site-wide password gate. Only set when a site password is enabled for the environment. Stores a hashed value, not the password | First-party cookie; persistent until it expires or is cleared |
Marketing Attribution (only when you choose "All")
| Name | Purpose | Type / Duration |
| --- | --- | --- |
| fw_attribution | Stores campaign parameters (UTM values) and the Google click identifier (gclid) from the link that brought you to our site, as JSON, so we can attribute a later signup to the correct marketing campaign | First-party cookie; up to 60 days. Written only after you consent to all cookies |
Affiliate Referral
| Name | Purpose | Type / Duration |
| --- | --- | --- |
| fw_ref | Records a one-way token identifying the affiliate who referred you, so commission is credited correctly if you sign up. Rolling 60-day lifetime; overwritten on every referral click, so the most recent affiliate link wins | First-party, HTTP-only cookie; up to 60 days |
| fw_ref_slug | A human-readable version of the referring affiliate's display name, paired with fw_ref | First-party cookie; up to 60 days |
Important interaction with consent. The affiliate referral cookies (fw_ref, fw_ref_slug) are set by the referral redirect (a /r/... link) at the moment you arrive through an affiliate link, before and independently of the cookie banner. They exist only to attribute affiliate commissions and to detect abuse of the affiliate program. They are not used for advertising or cross-site tracking. If you do not want them, you can remove them through your browser after clicking a referral link, or avoid using affiliate links.
Analytics and Performance (only when you choose "All")
If you choose All, FieldWorks loads analytics and performance tooling to understand usage and measure reliability. This currently includes:
- Google Analytics 4 (website analytics), which may set Google analytics cookies (for example,
_gaand related identifiers). - Google Ads conversion measurement.
These tools help us understand service performance and feature usage. They are not used for cross-site behavioral advertising against your FieldWorks project content.
Vercel Web Analytics and Vercel Speed Insights (cookieless page-view, custom-event, and performance measurement) run independently of your consent choice: they collect anonymous page-view and custom-event counts and page-performance metrics (Core Web Vitals such as load and responsiveness timings) with no cookies, no persistent identifiers, and no cross-page or cross-site tracking, so we can keep the Service fast and understand aggregate usage. They cannot identify you and cannot be turned off by the cookie banner.
3. Not a Cookie: Share-Link Password Storage
When an external visitor enters the password for a project share link, the password is held in that browser tab's sessionStorage, scoped per share token, so the visitor does not have to re-enter it on every page. This is not a cookie, is not transmitted to us as a cookie, and is discarded when the tab is closed.
4. Server-Side Affiliate Click Log
Separately from cookies, FieldWorks keeps a server-side log of clicks on affiliate referral links (/r/...). That log stores the affiliate, a one-way SHA-256 hash of your IP address (no raw IP address is stored), a truncated user-agent string, the referring page, and a country code derived from the request. We use it to reconcile commission payments and detect abuse. When you have consented to all cookies, the same click may also be recorded as a Vercel analytics event so we can cross-check our internal log.
5. Managing Choices
You can control cookies through:
- the FieldWorks cookie banner
- your browser settings
- device-level privacy controls
If you block or remove necessary cookies, parts of the Service may not function correctly.
6. Do Not Track
Some browsers transmit "Do Not Track" signals. There is no universally accepted standard for responding to those signals, so FieldWorks does not currently respond differently to them, but it limits tracking as described in this Cookie Policy and our Privacy Policy.
7. Changes
Cookie names, durations, and vendors may change as the Service evolves, and we may update this Cookie Policy accordingly. Material changes will be reflected here with a revised "Last Updated" date.
8. More Information
For more information about how we process personal information, see our Privacy Policy. If you have questions about cookies or tracking technologies used by FieldWorks, contact support@fieldworkshq.com.
