1. What Cookies Are
Cookies are small text files stored on your device by your browser. This policy covers equivalent technologies too — localStorage and sessionStorage — because Romanian law (Law 506/2004, implementing the ePrivacy Directive) governs any storage on your terminal equipment, not only cookies. Where that storage also involves personal data, the GDPR applies as well.
2. Categories We Use
Until you grant the matching category, the corresponding cookie is not written, the script is not loaded and the embed is not rendered — a blocked embed shows a placeholder telling you which third party it would contact.
Strictly necessary items are never optional, and are the only ones active if you reject everything.
| Category | Purpose | Legal basis | Examples |
|---|---|---|---|
| Strictly necessary | Sign-in session, CSRF protection, SSO state, live/test environment switch, your language choice, and the record of this consent decision itself | Exempt — Law 506/2004 art. 4(5): required to deliver a service you requested | authjs.session-token, authjs.csrf-token, NEXT_LOCALE, brivio_cookie_consent |
| Functional | Display preferences kept between visits — theme, density, layout, marketing skin, saved drafts | Consent | brivio-mk-skin, brivio-appearance, brivio-* interface keys |
| Analytics | Aggregated audience measurement (self-hosted Umami, no cookies), storefront visit statistics, and Sentry session replay on error inside the app | Consent | brivio_sf_sid (session only), Sentry replay |
| Marketing | Campaign and referral attribution, and third-party embeds such as Google Maps or a video player | Consent | brivio_utm (90 days), brivio_ref (referral window), third-party embed cookies |
3. How Consent Works
On your first visit you can accept everything, reject everything, or decide category by category directly in the banner. Rejecting is exactly as easy as accepting.
Your decision is stored in the brivio_cookie_consent cookie for 6 months, scoped to .brivio.ro so that one answer covers the whole platform — the main site, the app, the documentation and any storefront — instead of asking you again on each. After 6 months, or whenever we change what we use cookies for, we ask again.
You can change or withdraw your decision at any time from the cookie icon at the bottom of the page or the "Cookie settings" link in the footer. Withdrawing is as easy as consenting (GDPR art. 7(3)); it takes effect immediately and blocks anything you have removed.
So we can demonstrate consent as art. 7(1) requires, we keep a server-side record of each decision: the date, the policy version, the categories chosen, the site you were on, your browser's user-agent, and an irreversible hash of your IP address. We never store the address itself.
4. Third-Party Cookies
Payment pages set cookies from our payment processor, Stripe, strictly for fraud prevention and completing checkout. These are necessary to pay and are not used for advertising.
Google Maps on public company profiles and video players embedded by merchants in their storefronts are loaded only with marketing consent, because they set their own cookies once loaded.
Sentry error monitoring runs without cookies and without consent, because it is how we detect breakdowns and security problems — a legitimate interest under GDPR art. 6(1)(f). Session replay, which records how a page was used, is separate and runs only with analytics consent.
We do not use advertising networks and we do not sell or share your data with data brokers.
5. Browser Controls
You can also delete or block cookies from your browser settings, and most browsers let you do this per site. Blocking strictly necessary cookies will break sign-in and core functionality.
If you believe we have handled your data incorrectly, you may complain to the Romanian supervisory authority, ANSPDCP (dataprotection.ro).