Legal

Cookie Policy

Last updated: August 9, 2026

This Cookie Policy explains how Compliance Platform uses cookies and similar browser storage on the public website and platform application.

Essential cookies

The platform uses essential cookies and browser storage for authentication, session continuity, security checks, CSRF/session protection, routing users to the correct workspace, and remembering interface preferences required for normal use.

These cookies are necessary to provide the service and protect accounts. They are not used for advertising.

Security and authentication providers

Authentication and security providers, including Supabase and Cloudflare Turnstile where enabled, may set or use cookies and similar technologies to keep users signed in, verify legitimate traffic, prevent abuse, and support account recovery.

Disabling essential cookies may prevent login, password recovery, registration, security checks, or workspace access from working correctly.

Analytics

The public website loads Google Analytics 4, and only after you accept the analytics category in the consent banner. It counts visits and shows which pages and campaigns bring people to us. If you reject the banner or ignore it, the tag is never loaded and no analytics cookie is set. The platform application carries no analytics at all: the tag is placed on the public pages only, so it does not follow you into your workspace, where addresses identify cases and reports.

What we send is limited to what counting visits needs. The page address is sent without its query string, apart from campaign parameters such as utm_source, so anything else a page may carry in the address bar stays out. Advertising storage, ad personalisation and Google Signals are switched off, so the data is not used to build advertising profiles. There are still no advertising pixels, marketing cookies, heatmaps or session replay on the public site or in the platform. Withdrawing consent deletes the analytics cookies from your browser.

Cookies and storage we use

Authentication (sb-…-auth-token, sometimes split into several numbered parts): keeps you signed in and loads the right workspace. Set by our authentication provider Supabase, refreshed while you stay active, and removed when you sign out.

Language (locale, cp_locale, cp_locale_manual): remembers the interface language and whether you chose it yourself instead of having it detected. Stored for 12 months and shared across our subdomains, so the choice survives when you move between the public site and the platform.

Consent (cookie_consent): stores your own cookie choice so the banner does not ask again. Stored for 6 months, after which we ask once more.

Anti-abuse (Cloudflare Turnstile): used on sign-in, password recovery and confirmation resend to tell legitimate visitors from automated traffic. Set by Cloudflare, short-lived, and only on those pages.

Browser storage (taric-password-recovery): lets a password recovery link finish in the browser where it was opened. Held in local storage and cleared once recovery is complete.

Analytics (_ga, and _ga_ followed by the measurement ID): tells returning visits from new ones so visitor counts are not inflated. Set by Google Analytics only after you accept the analytics category, kept for 13 months rather than Google's default two years, and deleted when you withdraw consent.

Everything above except the analytics entry is needed to provide the service or to keep accounts secure. The analytics cookie is optional and is set only with your consent. None of them are used for advertising or profiling.

Managing cookies

You can control cookies through your browser settings. Blocking all cookies may break core platform features.

We show a cookie banner where accepting and rejecting analytics are equally available, and the preferences panel can be reopened at any time. Analytics cookies are set only after consent. We do not currently use advertising cookies; if that changes, we will describe the specific purpose and providers and request a new, separate versioned choice before loading them.