Legal

Cookie policy

A plain-English inventory of every cookie and third-party script that this site sets today, what each one does, and how long it lives. Written for an EU SME audience — GDPR-aligned, no legalese, no micro-print.

Last updated: . Material changes get a 30-day notice — see §4.

§1

What this page is

This page lists every cookie and every localStorage entry that the Sigila domain sets, plus every third-party script that loads in the browser while you use the site. We do not set marketing, advertising, retargeting or social-tracking cookies today, and the policy below makes that commitment auditable: each row is a concrete, current fact that we keep timestamped to the “Last updated” line above.

The short version: the only first-party identifier used to keep the site working is a sign-in session cookie set on the sigila domain. Everything else is localStorage, which your browser keeps under your control and which you can clear at any time.

§2

The consent banner

The first time you visit a public marketing page on this site, a consent banner appears at the bottom of the viewport. It is not a third-party widget — it is a small first-party React island built into the layout and it does not itself load any additional script. Its entire purpose is to give you a working Accept / Reject choice and to record that choice in localStorage so the banner does not reappear on reload.

  • Accept. We record cookie-consent = accepted in localStorage on the Sigila domain. The banner hides. No cookie is set to you as a marketing or analytics identifier; the value is a single word that we read on the next page load to decide whether to render the banner again.
  • Reject. We record cookie-consent = rejected in localStorage on the Sigila domain. The banner hides. The cookie-consent key itself is still written, because the wall-clock fact “this visitor answered the banner on this device” is what stops the banner from reappearing and pestering you on every page load.
  • Withdraw. Clear your browser’s localStorage for the Sigila domain (Settings → Privacy → Clear site data, or the equivalent in your browser) and the banner will reappear on your next page load so you can answer again. There is no server-stored consent record on our side; we would not be able to retaliate against a “Reject” because nothing is recorded anywhere other than your own browser.

The banner is hidden on authenticated routes (sign-in, dashboard, payment success) — those pages load under a session cookie that the banner cannot affect, and consent for first-party analytics on the marketing surface does not apply there.

§3

Full inventory

Below is the full table of everything set today. Each row is auditable against the “Last updated” date at the top of this page. The last row is a stub for an analytics script that is not yet loaded — we publish the row today so that the moment we add a script, this policy already lists it under the same heading.

NameTypeDomainSet byPurposeLifespan
cookie-consentlocalStorageSigila (first-party)Cookie consent bannerPersist the visitor’s accept / reject choice so the banner does not reappear on the next page load.Until the visitor clears browser storage.
polsia_vidlocalStorageSigila (first-party; sent to polsia.com as a query string)<PolsiaAnalytics/> on the Sigila domainAnonymous visitor UUID for the Polsia platform beacon (a 1×1 image loaded via /api/beacon/pixel). The beacon does not itself set cookies.Until the visitor clears browser storage.
themelocalStorageSigila (first-party)next-themes ThemeProvider mounted in the root layoutPersist the visitor’s light / dark preference across reloads.Until the visitor clears browser storage.
better-auth.session_token (name follows your better-auth configuration)HttpOnly, Secure cookieSigila (first-party)Better-auth sign-in flowKeep the visitor signed in across requests.Session (rotates / expires per better-auth configuration).
__stripe_mid, __stripe_sid, and other __stripe_* cookies and localStorage entriesCookies + localStoragecheckout.stripe.com (third-party)Stripe Checkout on the hosted page that the visitor is redirected toFraud and AML signals that Stripe processes under its own legitimate-interest basis. Stripe is a separate data controller; its privacy notice is at stripe.com/privacy.Per Stripe’s retention schedule — not set or read by the Sigila app.
_pola_analytics (stub)Not yet set — no third-party analytics script is loaded today.Privacy-friendly analytics, planned for a future iteration. We will publish the actual vendor name and the exact rows set here the moment a script is added.

No third-party advertising, retargeting, social-tracking or audience-profiling cookies are set on this site. If a future feature changes that, this page is the place where the new rows will land and the “Last updated” date will move.

§4

Changes to this policy

  • Material changes (a new script that sets marketing or analytics cookies, or any change to who the Sigila domain shares data with) get a 30-day notice via the email on your Stripe customer record, and we’ll bump the “Last updated” line above.
  • Non-material changes (typos, link fixes, clarifications) get a refreshed “Last updated” line and no email.
  • Continued use of the site after a change takes effect counts as acceptance of the updated notice. If you want to act on the change, clear your browser’s localStorage for the Sigila domain and the consent banner will reappear on the next visit.

Contact

Contact

Questions about cookies or local storage entries on this site go to sigila@polsia.app. The operator reads and answers each request — no chatbot, no ticket queue.