Skip to content

Draft for counsel review Counsel has not approved this text yet, so it may change before it is final.

Cookie notice

Rightmark sets six cookies, all first-party and none for advertising. Our analytics set no cookies at all.

Updated

On this page

Six cookies, all first-party, none for advertising

All six cookies are set by rightmark.ai itself. None is used for advertising, and none is shared with another site.

  • Four keep sign-in and forms working safely.
  • One saves an intake form you have not finished.
  • One records which Rightmark Scout introduced you, so the right Scout is credited.

Our analytics set no cookies. This notice explains each cookie and how to remove it; the privacy notice explains the rest of what we collect.

How our cookies are built

Every Rightmark cookie belongs to the exact site that set it. None is shared across domains, so bscout.ai and rightmark.ai never read each other’s cookies.

Every cookie is sent only over HTTPS, and only with requests that start on our site or come from an ordinary link to it.

Five of the six cannot be read by scripts on the page. The one that can holds only a flag, so the header can show "Portal" while you are signed in. No cookie holds your name or email address.

Strictly necessary cookies

These cookies make sign-in and forms work safely. The site cannot work without them, so they are always on.

  • __Host-rm_session

    Strictly necessary
    What it does
    Keeps you signed in.
    What it holds
    A random id. Our database stores only a fingerprint of it.
    How long
    14 days at most, or 7 days without use, for owners, Scouts and buyers. 8 hours at most, or 30 minutes without use, for staff. Signing out removes it.
    Readable by page scripts
    No
  • __Host-rm_pending

    Strictly necessary
    What it does
    Ties a sign-in link to the browser that asked for it, so a forwarded link does not sign anyone else in.
    What it holds
    A random id.
    How long
    15 minutes. Removed when you sign in.
    Readable by page scripts
    No
  • __Host-rm_csrf

    Strictly necessary
    What it does
    Stops another website from submitting our forms in your name.
    What it holds
    A signed random token.
    How long
    Until you close your browser.
    Readable by page scripts
    No
  • rm_hint

    Strictly necessary
    What it does
    Lets the header show "Portal" while you are signed in, without asking our server.
    What it holds
    Only the value 1. No identity and no secret.
    How long
    Ends with your session.
    Readable by page scripts
    Yes

A functional cookie that saves your form

A draft you never submit loses its personal fields after 30 days, whether or not the cookie is still in your browser.

  • __Host-rm_draft

    Functional
    What it does
    Saves an intake form you have started, so a reload or the back button does not lose your answers.
    What it holds
    A random draft id.
    How long
    30 days. Removed when you submit.
    Readable by page scripts
    No

The attribution cookie credits the Scout who introduced you

When you arrive through a Rightmark Scout link, the attribution cookie records that first introduction for 12 months, so the Scout who introduced you is credited if you later submit.

  • __Host-rm_attr

    Scout attribution
    What it does
    Records the Rightmark Scout whose link first brought you here, so that Scout is credited if you later submit.
    What it holds
    A signed id of the click record on our server. Not your name and not the Scout’s name.
    How long
    12 months, the length of the attribution window. A later Scout link does not replace it.
    Readable by page scripts
    No

How it works:

  • A Scout link on bscout.ai or rightmark.ai records the click on our server first. The click record holds the link used, the landing page, a device class, a coarse referrer class and a network address hash that is cleared after 30 days.
  • The cookie is set only on rightmark.ai, and only when you clicked the link yourself. Forced redirects and automated visits do not set it.
  • The first introduction counts. If you later follow another Scout’s link, we record that visit, but the cookie keeps the first one.
  • It lasts 12 months, the length of the attribution window.
  • It is first-party. We do not use it to follow you on other sites, and we do not share it with anyone.

It does not change what an owner is paid. Scouts are paid from Rightmark’s own income. Today the cookie is set on the first real click on a Scout link; whether it should ask for your consent first is part of the counsel review this page is under.

Analytics without cookies

We measure how the site is used with a cookieless analytics service from our hosting provider. It sets no cookie on your device.

The events we send carry no personal data. They record things like "appraisal started" with the data family, or "submission completed" with whether a Scout code was used. They never include names, email addresses or text you typed. The staff console does not load analytics at all.

Bot protection on forms

To stop spam and automated sign-in attempts, we run a bot check from our hosting provider on sign-in, intake, the Scout application, buyer requests, document requests and the partner widget.

The check loads when you first use one of these forms, not on every page. Our server passes it the request headers, never what you typed in the form.

Partner sites that embed our appraisal

Some partners embed our appraisal estimator on their own sites. The embedded estimator reads no Rightmark session, receives no session cookie and collects no personal data. If you ask for a reviewed estimate, it opens rightmark.ai in a new tab, where this notice applies.

The partner’s own site may use its own cookies. Its own notice covers those.

How to remove or block cookies

You can delete or block cookies in your browser settings. If you block the strictly necessary cookies, you cannot sign in or submit forms.

Signing out removes the session cookie and the hint. Submitting a form removes the draft cookie.

Deleting the attribution cookie stops it crediting a Scout from this browser. It does not delete the click record on our server. That record is not linked to you unless you submit, and its network address hash is cleared after 30 days. You can still type a Scout code on the intake form if you want a Scout credited.

Changes to this notice

When we add, remove or change a cookie, we update this notice and the date at the top. The list on this page matches the cookies in our code, and a test keeps the two the same.

Questions about cookies

Ask us about the data behind any cookie. Write with "Privacy" in the subject line.

Our contact inbox opens before launch, and its address will appear here.