Draft — to be reviewed by counsel before publication

Cookie policy

Draft for the marketing site and the dashboard of MB Tobuli. Contact [Contact email]. Company code [Company code]. Address [Registered address]. VAT [VAT number].

The API does not use a browser cookie. Callers send Authorization: Bearer. Do not describe the API key as a cookie.

Strictly necessary

These cookies run without a consent banner. They are required to serve a page or to keep a signed-in session.

Dashboard sign-in is implemented. These are the cookies that code sets.

The sign-in bot check, when configured, loads a Cloudflare Turnstile challenge from challenges.cloudflare.com. The Turnstile Privacy Addendum (accessed 2026-10-07) does not name a cookie for that challenge. It directs readers to Cloudflare's cookie policy and the Turnstile developer docs. This draft does not claim that the challenge sets or omits a cookie.

This list does not include better-auth.session_data, better-auth.account_data, or better-auth.dont_remember. Cookie cache and account-cookie storage are off, and sign-in does not ask to skip remembering the session. better-auth.trust_device has a max age of 0, so it does not persist. st-invite and st-return are not set on main. The dashboard reads st-tenant and does not set it. st-mock and st-live-script are not set by the dashboard. st-mock-session is set only while the API mock is on, with no Max-Age, Path=/, and SameSite=Lax.

Do not place analytics or advertising in this category.

Consent categories

The banner offers two optional categories. Use these ids in the product and in this policy:

Both stay off until the visitor opts in. The first layer has equally sized Reject all and Accept all actions. Customize opens the category choices, unchecked on the first visit. The primary button then reads Save choices. A reject control is as available as an accept control. Counsel reviews whether those labels are sufficient. Do not load the tags for a category the visitor has not accepted. Do not treat a closed banner as a yes. Escape on a reopened panel closes it and does not record a choice.

What each category does

analytics loads Google Analytics on the public marketing and documentation pages, and only when a measurement id is configured and the visitor has opted in. It grants analytics_storage. It does not grant advertising storage. Cloudflare Web Analytics, when a beacon token is configured, is cookieless and does not use this grant. See Subprocessors and ADR-0021 (docs/adr/0021-analytics-and-consent.md).

advertising loads Google advertising measurement on the public marketing and documentation pages, and only when an ads id is configured and the visitor has opted in. It grants ad_storage, ad_user_data, and ad_personalization. The site does not serve ads. The measured action is the start of signup, and only when a signup label is also configured. Do not use this category on the dashboard or on the API host.

The dashboard and the API host do not load analytics or advertising.

How to change the choice

Cookie settings in the marketing footer or documentation sidebar reopens the banner. The visitor can turn analytics or advertising off. Turning a category off stops later loads, removes the cookies this site can access for that category, and reloads the page so a tag that already started stops. It does not delete data already sent to Google. That deletion path is to confirm by counsel.

How long

The consent cookie lasts six calendar months from the choice timestamp. The theme preference lasts one year and is stored only after the visitor chooses a theme. It is not measurement. The signed-in dashboard session lasts 30 days. Other dashboard cookie lifetimes are in the list above. Do not publish a Google cookie duration until it is read from the live Set-Cookie header. The implemented names are in Current site storage below.

Current site storage

This inventory describes the implemented site behavior. The draft policy above still needs counsel review.

We remember your cookie choices and theme. Google tags load only after you grant a category. Use Cookie settings in the footer to change or withdraw your choice.

Strictly necessary

Preferences

Analytics (optional)

Advertising (optional)

When configured, Cloudflare Web Analytics measures visits without cookies. Google tags are omitted when their environment IDs are empty. Withdrawing Analytics consent removes the measurement cookies this site can access and clears attribution storage. Withdrawing Advertising consent removes the advertising cookies this site can access. Withdrawing either category reloads the page to stop its tags.