Legal
Cookie Policy
Last updated: 5 August 2026
This Cookie Policy explains which cookies and similar technologies the Seltara application (provider / controller: Hevrora) uses, for which purposes, and on which legal bases. It supplements our Privacy Policy.
What are cookies and similar technologies?
Cookies are small text files stored on your device. We also use comparable technologies such as browser localStorage, IndexedDB, and HTTP-only session cookies. Where we refer to “cookies”, these technologies are included unless stated otherwise.
Consent and management
Non-essential analytics and marketing technologies (Google Tag Manager / Google Analytics and tags configured in that container) are used only after your explicit opt-in per category. We store your choice in browser localStorage under the key seltara.cookie-consent as a small versioned JSON object (fields: v policy version, analytics, marketing, optional updatedAt) — not as a separate opt-in cookie. Necessary storage is always allowed and is not turned off by “Reject non-essential”.
When you save a choice (accept all, reject non-essential, or save preferences), we also write a privacy-preserving consent receipt to our application server logs as evidence of consent under Art. 7(1) GDPR: consent version, analytics/marketing flags, client timestamp, optional UI language, and a server receive time with an opaque receipt id. The receipt is not linked to an account, email, or user id, and we do not store your full IP on the receipt. It is a server-side record in application logs (not a user-facing database collection). Browser localStorage remains the control that gates optional tags; if the server log request fails, your choice still applies in the browser.
You can accept all optional categories, reject non-essential categories, or manage preferences (Analytics / Marketing) in the consent banner. Change your decision anytime via “Cookie Settings” in the site footer. If you withdraw optional consent after tags were loaded, we reload the page so already-injected scripts are cleared. A bump of the stored v version may ask you to choose again after a policy change.
Legal bases: consent (Art. 6(1) sentence 1 lit. a GDPR) for analytics/marketing; legitimate interests or necessity for the service you requested (Art. 6(1) sentence 1 lit. f or b GDPR) for strictly necessary storage.
Strictly necessary storage
| Name / storage | Purpose | Type / duration | Provider |
|---|---|---|---|
__session | Authenticated server session (Firebase session cookie, httpOnly) | HTTP cookie, session / limited max-age per server configuration | Seltara / Hevrora (first party) |
| Firebase Auth client storage | Session persistence for the sign-in UI on the marketing shell (header auth, pricing) and the authenticated app — Firebase Authentication IndexedDB / localStorage when Auth UI is present. Framed as strictly necessary for the authentication service you request; not gated behind optional analytics/marketing consent. | IndexedDB / localStorage, per Firebase Auth configuration | Google / Firebase (SDK) + Seltara / Hevrora |
seltara.cookie-consent | Stores your category consent decision (versioned JSON: analytics / marketing) | localStorage, until you change or clear it | Seltara / Hevrora (first party) |
| Theme / UI preferences | Presentation (e.g. light/dark mode), dashboard navigation state | localStorage, until you clear it | Seltara / Hevrora (first party) |
This storage is required to operate the application, provide sign-in where Auth UI is shown, or to record your consent decision and is set without separate marketing consent.
Analytics and marketing (consent only)
| Technology | Purpose | When loaded | Provider |
|---|---|---|---|
| Google Tag Manager (GTM) | Container that delivers analytics tags (e.g. Google Analytics) when configured | Only after optional category opt-in (Analytics and/or Marketing); in production and only with a valid NEXT_PUBLIC_GTM_ID | Google Ireland Limited / Google LLC |
| Google Analytics (via GTM, if configured in the container) | Reach measurement and usage analysis (pseudonymous) | Only when Analytics is opted in and via the GTM container | Google Ireland Limited / Google LLC |
Without optional consent, GTM and dependent tags are not loaded. Google Consent Mode defaults to “denied” for analytics and advertising storage until you opt in to the matching category.
Further information: Google’s privacy policy and opt-out options (e.g. Google Ad Settings).
Payments (Stripe)
For checkout and the customer portal we redirect you to Stripe. Stripe may set its own cookies and similar technologies on stripe.com domains. Those are subject to Stripe’s privacy policy: https://stripe.com/privacy. We do not set Stripe analytics cookies on our first-party pages outside the payment flow.
Sign-in (Firebase / Google)
Authentication uses Firebase Authentication (Google). On pages that present Auth UI in the marketing shell (header sign-in, pricing) or the app login flow, the Firebase Auth SDK may set necessary client storage (IndexedDB / localStorage) for session persistence before or during sign-in; after a successful sign-in we may set the first-party __sessioncookie. That stack is treated as strictly necessary for the authentication service you request and is documented above under necessary storage — it is not deferred behind the optional analytics or marketing categories. Google sign-in may also involve cookies and storage on Google account domains. See Google’s privacy notices and our Privacy Policy (registration and single sign-on sections).
Browser settings
You can delete or block cookies in your browser. Strictly necessary cookies and localStorage entries may be required for login and presentation; blocking them can limit functionality.
Contact
Hevrora, c/o Smarvo 234, Südstraße 31, 47475 Kamp-Lintfort
Email: [email protected]
Legal notice: /legal-notice