Cookie Notice
In plain language: a small amount of information is stored in your browser so that you stay signed in and your application is not lost. Everything beyond that is optional, off by default, and reversible in one click.
1 · What cookies and similar technologies are
A cookie is a small file a website asks your browser to keep. Similar technologies — local storage, session storage and pixels — do comparable jobs. Together they let a website recognise your browser between one page and the next.
2 · Why VisaOS uses them
To keep you signed in, to make sure a half-finished application is still there when you return, to keep the service secure, to remember your privacy choices — and, only if you agree, to understand how the product is used.
3 · Strictly necessary
Sign-in, session integrity, security, form protection, your application draft state, payment completion, and the record of your consent. These cannot be switched off, because without them the service cannot do the thing you came for. They do not require consent, but you should still know they exist.
4 · Functional
Conveniences such as remembering interface choices or your last-viewed section. Off by default, and requested through consent where the law requires it. Refusing them costs you nothing except a little convenience.
5 · Analytics
Aggregate measurement of which sections people find difficult, so we can make them clearer. Off by default. Never used to build an advertising profile, and never combined with the contents of your documents.
This category is provided by Google Analytics 4. Its script is not requested at all until you switch analytics on: refusing analytics means the tag is never loaded, rather than loaded and asked to behave. We switch off Google Signals and advertising personalisation, and we grant Google no advertising storage, because this measurement exists to improve the pages and not to advertise to you.
What we send is bounded to how the site was used: which page was viewed, which button was pressed and where it sits, which guide sections were opened, and campaign labels from the link you arrived on. We never send your name, your email address, your answers, your financial figures, your documents or their file names, or any account identifier.
6 · Marketing
Measurement of which pages brought people to VisaOS. Off by default. Whether we use these at all is still being decided, and if we do not, this category will be removed rather than left switched off.
7 · Local storage and session storage
Local storage holds your application draft state and privacy choices in your own browser until cleared. Session storage holds short-lived interface state and is discarded when you close the tab. Neither is transmitted to advertising networks.
8 · Security technologies
Some storage exists purely to protect you: detecting an unusual sign-in, resisting automated abuse of forms, and preventing cross-site request forgery. These sit inside strictly necessary and remain active.
9 · Payment-provider technologies
When you pay at Export, Stripe or PayPal set their own storage to process the payment and prevent fraud. That processing is described in their own notices, and VisaOS never receives your card details.
10 · Inventory by purpose
This inventory is organised by purpose rather than by individual cookie. Names differ between providers and durations are the maximum we set for each purpose, so listing every name would be less accurate, not more. We have not listed storage we do not set.
- Session and authentication — keeps you signed in and your session valid.
- Strictly necessary · Session — up to 30 days
- Security and abuse prevention — detects suspicious sign-in and protects forms.
- Strictly necessary · Up to 12 months
- Consent record — remembers your privacy choices, the date and the policy version.
- Strictly necessary · Up to 3 years
- Application draft state — keeps your place in an application so nothing is lost.
- Strictly necessary · Local storage — until cleared
- Interface preferences — remembers non-essential choices such as layout or last-viewed section.
- Functional · Up to 12 months
- Product analytics — which sections people find difficult, in aggregate. Set by Google Analytics.
- Analytics · Up to 13 months
- Marketing measurement — which pages brought people to VisaOS.
- Marketing · Up to 13 months
- Payment provider — set by Stripe or PayPal during checkout to complete payment securely.
- Strictly necessary · Set by provider
11 · Third-party access
Where a category is provided by a third party, that party can read the storage it sets. Our payment providers do so to complete payment. Google does so, once you have switched analytics on, to return aggregate measurement to us. No third party is given access to the documents in your application.
12 · Changing your mind
Use Privacy preferences, reachable from the footer of every page, or clear storage in your browser settings. Withdrawing consent carries no penalty and changes nothing about your application — though blocking strictly necessary storage will stop sign-in from working.