A cookie is a small file a site keeps in your browser so it can recognize you from one page to the next. The law treats them as personal data when they can identify you, which is why you have a right to know which ones exist and to refuse the ones that are not necessary.
The same goes for local storage, the service worker and the cache of an installed application. They are not cookies, they store information on your device all the same, and this document counts all of them.
1. On this site
Today ofivia.com sets no analytics, advertising or cross-site tracking cookies. There are no
social pixels, no heat maps, no campaign identifiers stored in your browser and no error reporting
tools. We checked that against the site’s source before publishing this version, not from memory.
What does get stored is this, and only if you use the form that produces it:
| What it stores | What for | How long |
|---|---|---|
| Site session cookie | Holding the signup form together between the page and the submission, with the marker that stops one submission being replayed | 2 hours |
| Signup cookie | Carrying your name, your email and the plan you picked to the confirmation page, so it can greet you without putting your email in the address bar | 30 minutes |
| Newsletter address, in local storage | Remembering the address you typed into the blog form. There is no mailing list behind it today and that address does not leave your browser | Until you clear it |
Both cookies are server-only: the page’s JavaScript cannot read them.
The server does keep the ordinary technical logs any web server keeps: the IP address, the page requested and the time. Those logs stay on our own servers, which are in Ecuador. That is described in the privacy policy and does not depend on a cookie.
Typefaces are served from our own domain, so opening a page makes no request to a font provider and discloses your IP address to no one.
2. The European consent standard
For visitors in the European Union, what governs is Article 5(3) of Directive 2002/58/EC: storing information on your device, or reading what is already there, requires your prior informed consent, unless it is strictly necessary to provide the service you explicitly asked for.
Everything in this document falls inside that exception. It holds up the session you opened, completes the form you submitted, delivers the notification you turned on, or protects the payment you started. That is why there is no consent banner: there is nothing to consent to.
The day analytics arrives, the exception stops applying. That day this document will say so before it happens, a control will appear to accept or refuse it, the refusal will actually work, and analytics will stay off until you say yes. The same would hold for any advertising or measurement pixel, which does not exist today and is not planned.
3. When you go to pay
Card payment happens on a page hosted by Stripe, not in a form on this site. When you start the
payment your browser leaves ofivia.com, and the cookies stored from that point on belong to
Stripe’s domain. Stripe uses them to hold the payment session together and to detect fraud: without
that signal, anyone can test stolen cards against the form.
Two things that concern you:
- Those cookies appear only once you start a payment. Until you do, this site loads nothing from Stripe: no script, no cookie, no connection.
- For what happens on its own page, Stripe answers on its own account and applies its own privacy policy. What comes back to us is set out in the privacy policy: the customer identifier, the last four digits, the card brand and the invoice, never the card number.
Under the standard in section 2, holding a payment together and detecting fraud in a payment you
just started is strictly necessary for the service you asked for, so there is no banner there
either. If we ever move the payment form inside this site instead of sending it to Stripe, Stripe’s
script would start loading on ofivia.com and this document gets rewritten before that happens.
4. In the application
app.ofivia.com does need to store information in your browser to work. Without it there is no
session.
| What it stores | What for | How long |
|---|---|---|
| Access token | Keeping the session open between requests | 15 minutes |
| Refresh token | Renewing the session without asking for your password again | 7 days, or until you log out |
| Application session | Letting you into the /app pages without revalidating on each one |
7 days |
| Active company | Knowing which of your companies you are working in | The session |
| Temporary password | Showing once the password the admin console has just generated | Minutes, and it clears as it is shown |
| Workspace state, in local storage | Remembering open tabs, recent documents, expanded folders, bookmarks and the last company | Until you clear it |
| Agent engine per conversation, in local storage | Remembering which engine you opened that conversation with | Until you clear it |
The first three are server-only and the application’s JavaScript cannot read them. Logging out invalidates that account’s tokens on every device immediately.
None of these are used for advertising or to follow you across sites. One clarification about third
parties, because the short sentence would be false: when you open one of the embedded consoles from
the application, such as conversations, automations or webmail, that console stores its own session
cookie on its own domain. They are applications running on our own infrastructure in Ecuador and not
a third party’s, but the cookie does not belong to app.ofivia.com and we would rather you did not
learn that from your browser.
An honest caveat about the standard in section 2, because one row is arguable. Workspace state is not indispensable for the application to work: without it the session stays open and you keep working, just without your tabs. We treat it as part of the desk you asked for, it is stored in your browser and also in your account so it follows you to another device, and it clears from the application or from the browser. If that state were ever used for anything other than handing your desk back, it would move to asking for consent.
5. Notifications and the installed application
If you turn notifications on, your browser registers a push subscription tied to that device. One row is stored per device and it deletes itself when the push service reports the subscription is dead. You can revoke it from the site permissions in your browser.
The application installs a service worker and it does the minimum: it receives the notice, opens the right screen when you tap the notification, and tells an open tab so the bell updates. It stores no copy of your pages and intercepts none of your requests. This marketing site installs none at all.
6. How to control all of this
Every browser lets you inspect, block and clear per-site storage, usually under privacy settings.
Bear in mind that if you block storage for app.ofivia.com, the application will not be able to
keep you logged in, and that if you block it on ofivia.com the signup form will stop completing.
7. Who answers for this
What this site stores is the responsibility of [legal entity name], a Delaware company, which is the party that contracts with every client, wherever they are. The team, the day-to-day operation and the servers are in Ecuador: that is where the technical logs stay and where the application that issues the session cookies runs. Which data crosses which border, and under what safeguard, is set out in the privacy policy.
If you have questions about this document, write to hola@ofivia.com or call +593 96 175 0101.