1. What are cookies
Cookies are small text files stored in your browser. We use necessary cookies for app sessions and local preferences. On the marketing site, Google Tag Manager / Analytics 4 and Microsoft Clarity may set measurement cookies — only after you accept analytics in the privacy banner. Clarity masks form inputs in session recordings.
2. Cookie categories
- Strictly necessary App: session (httpOnly cookie), CSRF. Site: local preferences (language, currency, privacy choice) in localStorage. No consent needed. access_token, cw_cookies
- Functional App: dashboard settings, purchase-flow continuation. Full register in the app: Settings → Privacy. cw_checkout_intent
- Analytics Google Tag Manager, Google Analytics 4 and Microsoft Clarity on the marketing site — only after consent in the privacy banner. Measurement cookies and UX session replay; Clarity masks form inputs. No ads / Google Signals. Optional Plausible remains cookie-less. _ga, _ga_*, _clck, _clsk, _gcl_*
- Marketing None. Zero adtech. —
3. Third-party cookies
Stripe (payments) — required for checkout. Google Tag Manager / Analytics 4 and Microsoft Clarity — marketing site only, after consent (IP approximation; ads and Google Signals off; Clarity masks form inputs). No Facebook Pixel or Hotjar.
4. Managing cookies
The privacy banner appears on first visit. You can change your choice anytime via the floating "Privacy" button in the bottom-right corner. You can also clear cookies in your browser settings.
5. Retention
Strictly necessary — session up to 7 days. Functional — 30 days. Analytics (GTM / GA4 / Clarity) — per vendor retention (typically up to 2 years for _ga / Clarity cookies unless you clear cookies or revoke consent).
Document version 4.2 · Effective from 2026-07-21