Cookie Policy
Effective Date: 2026-09-21
Table of Contents
- What Are Cookies and Similar Technologies
- How We Use These Technologies
- Cookie Inventory — Website
- Cookie Inventory — Mobile Application
- Third-Party Services
- Consent Mechanism — Website
- Consent Mechanism — Mobile Application
- Global Privacy Control (GPC)
- Do Not Track (DNT)
- Managing Cookies in Your Browser
- Opt-Out Links
- Impact of Disabling Cookies
- Changes to This Policy
- Contact
1. What Are Cookies and Similar Technologies
Cookies are small text files that a website places on your device when you visit, storing information such as your preferences or session state so the site can recognize you on return visits.
Local storage is a browser-based mechanism that holds data on your device without an expiration date, used for persistent preferences. Session storage functions similarly but is cleared when the browser tab or window is closed.
Pixels (also called tracking pixels or web beacons) are tiny, invisible images embedded in a page or email that signal to a third-party server when content has been loaded, allowing that server to record a visit or interaction.
SDKs (software development kits) are code libraries embedded in mobile applications that collect data about app usage, device characteristics, and user interactions, and transmit that data to third-party analytics or attribution services.
This policy covers all such technologies used on https://www.kaijumechanic.com ("the Website") and in the Kaiju Mechanic mobile application for iOS and Android ("the App"). Together, these are referred to as "the Service."
For our full data practices — including how we collect, use, and protect personal information — please see our Privacy Policy.
2. How We Use These Technologies
Security and Infrastructure
We use strictly necessary cookies and infrastructure-level protections to defend the Website against automated abuse, distributed denial-of-service attacks, and other malicious traffic. These technologies are essential to the operation and availability of the Service and cannot be disabled.
Analytics
We use analytics technologies to understand how visitors interact with the Service — which pages or screens are visited, how long sessions last, which features are used, and where users navigate from. This helps us identify usability issues, measure the impact of changes, and improve the product experience.
On the Website, analytics are provided by Google Analytics 4, which the Website loads directly from Google (the Google tag, gtag.js) only when your choice allows it. In the United States, analytics is on by default and measures page views and interaction events, such as button clicks, until you opt out. Everywhere else, analytics starts only after you accept it in our cookie banner. Analytics never runs while your browser sends a Global Privacy Control signal (see Section 8).
On the App, analytics are collected through Firebase Analytics (which feeds Google Analytics 4) and PostHog. Both SDKs are initialized in a disabled state and only begin collecting data after you grant explicit opt-in consent within the App.
Email Open Tracking
Lifecycle emails sent through Customer.io — onboarding, maintenance reminders, re-engagement, and billing-recovery messages — contain an open-tracking pixel: a small, invisible image hosted by Customer.io. When your email application loads that image, Customer.io records that the message was opened and when, and receives the IP address and mail-client information your email application sends with that request. We use this to measure whether lifecycle emails are opened and how a campaign performed. Individual open events are discarded by our reporting webhook and are not stored in our systems.
This is an email pixel — not a cookie. It is not set by the Website and not set by the App. It loads only when you open a lifecycle email in your email application, and only if you have granted the Personalized Messaging opt-in in the App (Settings → Data & Privacy). Transactional account notices are sent through Resend and are not routed through Customer.io, so they do not carry this pixel.
| Technology | Provider | Purpose | Consent Mechanism | How to Stop It |
|---|---|---|---|---|
| Email open-tracking pixel | Customer.io | Records that a lifecycle email was opened, the time of the open, and the IP address and mail-client information sent when the pixel loads. Used for open-rate and campaign performance measurement — never for advertising, retargeting, or cross-context behavioral advertising. | Delivered only to recipients of lifecycle email, which requires the Personalized Messaging opt-in in the App. Off by default. | Turn off Personalized Messaging in the App (Settings → Data & Privacy). This stops all lifecycle email and deletes your Customer.io profile. |
Consent Record-Keeping
On the Website, we log your consent choices to an audit trail via our server-side consent logging endpoint. When you interact with the consent banner, a server-side API call logs your consent decision along with a pseudonymized visitor identifier (a keyed HMAC-SHA256 value scoped to this website — not your IP address, and not recomputable without a secret key we hold), the consent action you took, the categories you selected, your detected region and the applicable consent regime, whether Global Privacy Control was active (detected both in your browser and at our server), the version of the consent banner you responded to, and a timestamp. Your name and email address are not included in these records. This processing is necessary to demonstrate valid consent under GDPR Article 7(1) and to comply with US state privacy law record-keeping obligations.
On the App, consent choices are logged to the same audit trail, but the record is built for an app rather than a browser: it uses a different identifier, and there is no cookie banner, no region-based consent mode, and no Global Privacy Control signal involved. See Section 7, Consent Record-Keeping, for what an App consent record contains.
Advertising and Retargeting
We do not use cookies, pixels, SDKs, or any other technology for advertising, retargeting, cross-site behavioral profiling, or the sale or sharing of personal data for advertising purposes. No advertising network technologies are deployed on the Website or in the App.
3. Cookie Inventory — Website
3.1 Strictly Necessary Cookies
These cookies are required for the Website to function. They cannot be disabled. No consent is required to set them.
| Cookie Name | Provider | Purpose | Duration |
|---|---|---|---|
cc_cookie |
Kaiju Mechanic (RB ZILLA LLC) | Stores your cookie consent preferences (accepted/rejected categories and banner revision number). Required to honor your choices on return visits. Set when you make a choice in the banner, or on your first page if your browser sends a Global Privacy Control signal. | 366 days (a choice stored on or before 17 September 2026 may instead expire after 182 days) |
cf_clearance |
Cloudflare | Records that you have passed a Cloudflare security challenge, so you are not challenged again on every page. Only set if Cloudflare shows you a security challenge. | 30 minutes |
3.2 Analytics Cookies
Outside the United States, these cookies are set only after you accept analytics in the cookie consent banner. In the United States, analytics is on by default, so they are set from your first page view unless you opt out. They are never set while your browser sends a Global Privacy Control signal. They collect pseudonymized usage data and are never used to identify you personally.
If you revoke analytics consent, these cookies are automatically cleared from your browser by our consent management platform. They are not HttpOnly, so the Website can delete them as soon as you opt out.
| Cookie Name | Provider | Purpose | Duration |
|---|---|---|---|
_ga |
Distinguishes unique visitors by assigning a randomly generated client ID. Used to calculate visitor and session counts in analytics reports. | 2 years (some browsers, including Chrome, keep cookies for at most 400 days). Safari, and other browsers on iPhone and iPad, may delete this cookie after 7 days. | |
_ga_<container-id> |
Persists session state for Google Analytics 4. The <container-id> suffix corresponds to the GA4 measurement ID. |
2 years (some browsers, including Chrome, keep cookies for at most 400 days). Safari, and other browsers on iPhone and iPad, may delete this cookie after 7 days. |
3.3 Technologies That Do Not Set Cookies
The following technologies are used on the Website but do not set cookies on your device:
| Technology | Provider | Purpose | Why No Cookies |
|---|---|---|---|
| Codex Titan Widget | RB ZILLA LLC | In-page support and assistance widget loaded from cdn.codextitan.com. |
Loaded via a script tag with lazyOnload strategy. Does not set cookies. It connects to Codex Titan directly from your browser and uses browser storage instead, as described in Section 3.4. |
| Consent Audit Log | RB ZILLA LLC | Server-side endpoint (/api/consent-log) that records consent actions for GDPR Art. 7 compliance. |
Processing occurs entirely server-side. No cookies are set. Subject identity is a keyed HMAC-SHA256 visitor identifier scoped to this website — not your IP address, and not recomputable without a secret key we hold. |
3.4 Local Storage and Session Storage
The Website's own code does not use localStorage or sessionStorage. Your consent preferences are stored only in the cc_cookie cookie.
The Codex Titan support widget (Section 3.3) uses browser storage for its own operation:
- On every page: it keeps a copy of its display settings for that page in
sessionStorage(keys beginningct_wc_) for up to 5 minutes, so it does not fetch them again on each page view. These entries contain no personal data and are deleted when you close the tab. If you dismiss a message the widget shows you, it also storesct_proactive_dismissedinsessionStorage, so the message does not return during that visit. - Only if you use the widget: when you open your conversations or start one, it stores a random anonymous identifier in
localStorage(ct_widget_anon) so that you can return to them later. If you start a conversation and enter your email address, it also stores the name and email address you entered (ct_widget_user). It records which conversations you have read (keys beginningct_unread_) and, if you move the widget button, where you put it (keys beginningct_lpos_). Safari, and other browsers on iPhone and iPad, may delete these entries after 7 days without interaction with the Website, so earlier conversations may no longer appear in the widget.
Clear my conversations in the widget's menu deletes the identifier, the stored name and email address, and the read markers. Clearing this site's data in your browser deletes all of the entries above.
4. Cookie Inventory — Mobile Application
The Kaiju Mechanic mobile application does not use browser cookies. It uses the following SDKs and on-device storage mechanisms, all of which require your explicit opt-in before data collection begins:
4.1 Analytics SDKs (Require Opt-In)
| SDK | Provider | Purpose | Data Collected | Opt-In Mechanism |
|---|---|---|---|---|
| Firebase Analytics / Google Analytics 4 | Measures feature usage, screen views, session duration, and user flows to improve app functionality. | Pseudonymized usage events, screen names, session metadata, device type, OS version. | Firebase setConsent() defaults to denied; enabled only after explicit user opt-in within the App. |
|
| PostHog | PostHog Inc. | Product analytics measuring feature adoption, user flows, and retention metrics; session replay for debugging when you opt in; billing and subscription observability. | Pseudonymized usage events, feature flag evaluations, session metadata, (when enabled) session replay recordings, and subscription and entitlement records received from RevenueCat, keyed to the app user identifier. | Initialized with opt_out_capturing_by_default: true; enabled only after explicit user opt-in within the App. The RevenueCat subscription stream is server-to-server and is not governed by that in-app opt-in; it is processed under legitimate interest for billing and subscription observability. |
4.2 Error Tracking and Crash Reporting (Functional — No Consent Required)
| SDK | Provider | Purpose | Data Collected | Legal Basis |
|---|---|---|---|---|
| Sentry | Functional Software Inc. | Error tracking to identify and resolve bugs. | Crash reports, stack traces, device metadata (model, OS version), breadcrumb events. No PII. sendDefaultPii is set to false. |
Legitimate interest in maintaining app stability and resolving errors that affect user experience. |
| Firebase Crashlytics | Crash reporting to identify and resolve application crashes. | Crash reports, device info (model, OS version), app state at time of crash. No PII. | Legitimate interest in maintaining app stability and resolving crashes that affect user experience. |
4.3 Subscription Management
| SDK | Provider | Purpose | Data Collected |
|---|---|---|---|
| RevenueCat | RevenueCat Inc. | Manages in-app subscriptions and purchase entitlements across iOS and Android. | Subscription status, product identifiers, transaction timestamps, anonymous app user IDs. No payment card data — card processing is handled entirely by Apple App Store and Google Play. |
4.4 Messaging SDK (Requires Opt-In)
| SDK | Provider | Purpose | Data Collected | Opt-In Mechanism |
|---|---|---|---|---|
| Customer.io | Customer.io | Lifecycle messaging — onboarding, reminders, re-engagement, and billing-recovery messages delivered by email, push, and in-app. Identified (not anonymous). Lifecycle emails additionally carry an open-tracking pixel — an email technology, not a cookie and not an App SDK signal; see Section 2, Email Open Tracking. | Account email, app user ID, vehicle year/make/model, subscription tier and status, notification preferences, locale, platform, and activity timestamps. | Initialized only after you grant the Personalized Messaging opt-in within the App (Settings → Data & Privacy, also offered on first launch). Withdrawing it deletes your Customer.io profile. |
4.5 On-Device Storage
The App uses standard platform storage mechanisms (iOS Keychain, Android SharedPreferences/EncryptedSharedPreferences) to store authentication tokens, consent preferences, and app settings locally on your device. This data is not transmitted to third parties.
5. Third-Party Services
The following third-party providers may set cookies on the Website or process data in connection with your use of the Service:
| Provider | Role | Cookies Set (Website) | Privacy Policy |
|---|---|---|---|
| Cloudflare | CDN, DDoS protection, edge computing, and security infrastructure. Processes all Website traffic as a reverse proxy. | cf_clearance (only after a security challenge) |
Cloudflare Privacy Policy |
Web analytics (GA4) on the Website, loaded directly with the Google tag (gtag.js); Firebase Analytics in the App. |
_ga, _ga_<container-id> (Website only) |
Google Privacy Policy | |
| PostHog | Product analytics and optional session replay in the App only (requires analytics opt-in). | None (App SDK, no cookies) | PostHog Privacy Policy |
| Customer.io | Lifecycle messaging (email, push, in-app) in the App only — onboarding, reminders, re-engagement. Identified; requires the Personalized Messaging opt-in. | None. The App SDK sets no cookies; lifecycle emails carry an open-tracking pixel (see Section 2, Email Open Tracking) | Customer.io Privacy Policy |
| Sentry | Error tracking and crash reporting in the App only. | None (App SDK, no cookies) | Sentry Privacy Policy |
| RevenueCat | Subscription and entitlement management in the App only. | None (App SDK, no cookies) | RevenueCat Privacy Policy |
| Codex Titan | Backend API, AI engine, support widget, and consent audit logging. First-party service operated by RB ZILLA LLC. | None. The support widget uses browser storage instead (see Section 3.4) | Kaiju Mechanic Privacy Policy |
6. Consent Mechanism — Website
How We Obtain Consent
When you first visit https://www.kaijumechanic.com, a cookie consent banner is displayed. The banner's default behavior depends on your detected region:
Visitors in the United States (opt-out mode): Analytics is on by default. Page views and interaction events are measured with Google Analytics 4 from your first page until you click Opt Out or turn analytics off in Manage Preferences. A Global Privacy Control signal turns analytics off instead (see Section 8).
All other visitors, including the EEA, the UK and Switzerland (opt-in mode): All non-essential cookies are off by default. The banner remains visible until you make an active choice. Non-essential cookies are only set after you click Accept All or enable specific categories via Manage Preferences. This also applies when we cannot determine your region.
Region detection uses the country Cloudflare reports for the request. Only the United States is opt-out. Every other country, and a country code Cloudflare cannot place, is opt-in. When that country is absent, we fall back to the browser time zone, and only time zones in the United States use opt-out mode. That fallback can be wrong when you use a VPN or travel. The consent log records whether the decision came from the edge country or from that fallback.
Banner Controls
The consent banner presents the following options with equal visual prominence — no option is hidden, pre-selected to a non-default state, or styled to discourage refusal:
- Accept All — Enables all cookie categories (necessary + analytics).
- Reject All / Opt Out — Disables all non-essential cookies immediately. Label adapts to region ("Reject All" in opt-in mode, "Opt Out" in opt-out mode).
- Manage Preferences — Opens a granular panel where you can enable or disable individual categories.
Updating or Withdrawing Consent
You can review and change your cookie preferences at any time by clicking the "Consent Preferences" button in the footer of the Website. Your updated choice takes effect immediately:
- If you revoke analytics consent, analytics cookies (
_gaand_ga_<container-id>) are automatically cleared from your browser and analytics collection stops. - If you grant analytics consent after previously declining, analytics collection begins from that page onward. Nothing from before your choice is kept or sent.
Your updated choice is saved in the cc_cookie cookie and kept for at least 12 months.
Withdrawing consent does not affect the lawfulness of any processing that occurred before you withdrew it.
Consent Records
Each consent action (grant, deny, or revoke) is logged server-side for compliance purposes. The log entry includes a pseudonymized visitor identifier (a keyed HMAC-SHA256 value scoped to this website — not your IP address, and not recomputable without a secret key we hold), the action taken, categories accepted or denied, the consent mode (opt-in or opt-out), whether a GPC signal was detected, whether the region was decided from Cloudflare's country or from the browser time zone, the version of the consent banner you responded to, and a timestamp. Your name and email address are not included in consent logs.
When we make material changes to our cookie practices (see Section 13), we increment the banner revision number, which triggers a new consent prompt on your next visit regardless of your prior choice.
7. Consent Mechanism — Mobile Application
How We Obtain Consent
The Kaiju Mechanic mobile application initializes all analytics SDKs in a disabled state by default. No analytics data is collected until you grant explicit opt-in consent:
- Firebase Analytics: Consent signals are set to
deniedat initialization viasetConsent(). Collection begins only after you opt in. - PostHog: Initialized with
opt_out_capturing_by_default: true. Capturing begins only after you opt in. - Advertising identifiers / ATT: We do not collect the Apple Identifier for Advertisers (IDFA) or the Android Advertising ID (AAID). Because we do not access the advertising identifier, we do not display the iOS App Tracking Transparency (ATT) prompt.
Updating or Withdrawing Consent
You can review and change your analytics preferences at any time from the Settings screen within the App. Withdrawing consent immediately stops analytics collection for the remainder of your session and all future sessions until consent is re-granted.
Consent Record-Keeping
Consent choices you make in the App are recorded to the same server-side audit trail described in Section 2, in records kept separately from Website records. Each time you grant, deny, or revoke a consent in the App, the App sends the choice to our servers, which write an entry containing:
- A pseudonymized subject identifier — a keyed HMAC-SHA256 value derived from your app account identifier under a scope specific to the App. It is not your name, email address, IP address, or an advertising identifier, and it cannot be recomputed without a secret key we hold. It is a different value from the Website visitor identifier described in Sections 2 and 6, derived from a different input under a different scope. If no account identifier is available when the entry is written, a random one-time value is used in its place and that entry is not linked to your account.
- The action taken — grant, deny, or revoke.
- The consent category — analytics, crash reporting, personalized messaging, AI data processing, or the OBD safety acknowledgment (an acknowledgment record, not a tracking consent).
- The in-app surface where you made the choice — the first-launch consent prompt, Settings → Data & Privacy, the AI data consent screen, or the OBD safety notice.
- The revision of the in-app consent copy you responded to.
- A timestamp, applied when the entry is received.
Your name and email address are not included in these records, and your device's IP address is not sent with them — an App consent entry reaches the audit trail from our servers, not directly from your device. No cookies are involved, and Global Privacy Control (Section 8) is a browser signal that does not apply to App consent records. This processing is necessary to demonstrate valid consent under GDPR Article 7(1) and to comply with US state privacy law record-keeping obligations.
Error Tracking
Sentry crash reporting operates independently of analytics consent. It collects only technical crash data (stack traces, device metadata) with sendDefaultPii set to false (no personal data is transmitted). This processing is based on our legitimate interest in maintaining app stability and is disclosed in our Privacy Policy.
8. Global Privacy Control (GPC)
We honor the Global Privacy Control (GPC) signal as a valid opt-out of all non-essential tracking on the Website.
How We Detect GPC
GPC signals are detected through two methods:
- Client-side: We check the
navigator.globalPrivacyControlJavaScript property when the consent banner initializes. - Server-side: Our consent logging endpoint reads the
Sec-GPC: 1HTTP request header.
What Happens When GPC Is Detected
When a GPC signal is detected, analytics and all other non-essential cookies are automatically declined and the consent banner is suppressed — in all regions, including the opt-out region (United States) and opt-in regions (everywhere else). In opt-in regions, analytics cookies are already off by default, so GPC produces the same outcome as the default behavior. A deny action is logged to the consent audit trail in all cases. Users with GPC enabled can still open the consent preferences panel via the "Consent Preferences" link in the Website footer, but analytics stays off while the GPC signal is on, even if it is switched on there. To allow analytics, turn off Global Privacy Control in your browser first.
GPC Compliance Declaration
We publish a machine-readable GPC compliance signal at https://www.kaijumechanic.com/.well-known/gpc.json confirming that we honor the GPC specification.
Applicable US States
If you are a resident of one of the following states, your GPC signal is processed as a legally binding opt-out under applicable state privacy law:
California (CCPA/CPRA), Colorado (CPA), Connecticut (CTDPA), Delaware (DPDPA), Maryland (MODPA), Minnesota (MCDPA), Montana (MCDPA), Nebraska (NDPA), New Hampshire (SB 255), New Jersey (NJDPA), Oregon (OCPA), and Texas (TDPSA).
Residents of these states have a statutory right to opt out of the sale or sharing of personal data and targeted advertising. A valid GPC signal satisfies that right automatically on our platform.
9. Do Not Track (DNT)
We do not respond to the Do Not Track (DNT) browser signal.
DNT lacks a universally accepted technical standard, has no consistent legal definition, and has no established compliance framework. The World Wide Web Consortium (W3C) discontinued its DNT working group in 2019. As a result, there is no reliable way to implement DNT in a manner that is meaningful or verifiable across browsers and platforms.
If you wish to opt out of non-essential tracking, we recommend using Global Privacy Control (GPC) (see Section 8), which is a standardized, legally recognized signal supported by applicable US state privacy laws and honored by our platform.
10. Managing Cookies in Your Browser
You can control or delete cookies directly through your browser settings. Note that disabling strictly necessary cookies may impair the functionality of security protections (such as Cloudflare bot management and challenge verification) on the Website.
Google Chrome
Go to Settings > Privacy and security > Cookies and other site data. You can block all cookies, block third-party cookies only, or clear existing cookies. You can also create exceptions for specific sites.
Mozilla Firefox
Go to Settings > Privacy & Security > Cookies and Site Data. Firefox allows you to block all cookies, block cross-site tracking cookies, or manage cookies on a per-site basis. Click Manage Data to delete cookies from specific sites.
Apple Safari
Go to Settings > Safari > Privacy & Security (iOS) or Safari > Preferences > Privacy (macOS). You can block all cookies or enable "Prevent Cross-Site Tracking." Use Manage Website Data to view and delete cookies from individual sites.
Microsoft Edge
Go to Settings > Cookies and site permissions > Cookies and data stored. You can block third-party cookies, clear cookies on browser close, or manage exceptions for specific sites.
11. Opt-Out Links
| Service | Opt-Out Method | Link |
|---|---|---|
| Google Analytics | Browser add-on from Google that stops websites using Google Analytics JavaScript (gtag.js or analytics.js) from sending data about your visits to Google Analytics. The Website uses gtag.js, so the add-on works here. Available for Chrome, Safari, Firefox and Microsoft Edge. |
Google Analytics Opt-Out Add-On |
| Google (account-level) | Adjust your Google account's data sharing and ad personalization settings. | Google Privacy Controls |
| PostHog (App only) | Disable analytics in the App's Settings screen. This immediately stops PostHog data collection. | In-app: Settings > Privacy > Analytics |
| Firebase Analytics (App only) | Disable analytics in the App's Settings screen. This sets Firebase consent signals to denied. | In-app: Settings > Privacy > Analytics |
| Cloudflare | Cloudflare operates as security and CDN infrastructure. It processes traffic at the network level to protect site availability. Opt-out is not applicable — Cloudflare cannot be bypassed without blocking access to the Website entirely. | Cloudflare Privacy Policy |
12. Impact of Disabling Cookies or Tracking
Website
| Category | If Disabled |
|---|---|
| Strictly Necessary | Cloudflare security protections (bot detection, challenge verification) may not function correctly. You may be repeatedly challenged or blocked from accessing the Website. The Website does not use authentication cookies — there is no login functionality on the Website. |
| Analytics | Google Analytics will not collect data about your visit. This has no impact on any Website features — all content and functionality remains fully available. |
Mobile Application
| Category | If Disabled |
|---|---|
| Analytics (Firebase + PostHog) | No usage analytics are collected. All App features remain fully functional. |
| Error Tracking (Sentry + Crashlytics) | Enabled by default. You may disable crash reporting at any time in the App's Settings → Data & Privacy. When disabled, Sentry and Firebase Crashlytics stop sending crash/error reports. |
| Subscription Management (RevenueCat) | Cannot be disabled independently. Required for the App to verify your subscription status and unlock paid features. |
| Personalized Messaging (Customer.io) | Off by default. When disabled, no lifecycle emails are sent, no Customer.io profile exists, and no email open-tracking pixel is delivered to you. All App features remain fully functional. |
13. Changes to This Policy
The Effective Date at the top of this document identifies the current version. Prior versions are available upon request by contacting privacy@kaijumechanic.com.
Material Changes
A material change is one that:
- Introduces a new cookie category or tracking technology
- Adds a new third-party provider that sets cookies or collects data
- Materially expands the purposes for which cookies or similar technologies are used
- Changes the default consent behavior (e.g., switching from opt-out to opt-in)
For material changes, we will:
- Update the Effective Date.
- Increment the consent banner revision number on the Website.
- Re-prompt all Website visitors for consent on their next visit, regardless of their prior choice.
- Update the App's consent screen if app-side tracking is affected.
Non-Material Changes
Non-material updates — such as correcting cookie durations, updating provider privacy policy links, clarifying existing descriptions, or reformatting — are reflected in the Effective Date only. No new consent prompt is triggered.
We encourage you to review this policy periodically. Continued use of the Service after the Effective Date constitutes acknowledgment of the updated policy.
14. Contact
If you have questions about this Cookie Policy or wish to exercise your privacy rights, please contact us:
RB ZILLA LLC Product: Kaiju Mechanic Email: privacy@kaijumechanic.com Website: https://www.kaijumechanic.com Mailing Address: 116 E Main St, Suite 201, Rock Hill, SC 29730
To submit a data subject access request (access, deletion, correction, or portability), use our Data Request Form.
For full details on how we collect, use, and protect your personal information — including your rights under GDPR, CCPA/CPRA, and other applicable privacy laws — please review our Privacy Policy.
RB ZILLA LLC | Rock Hill, SC | https://www.rbzilla.com