Cookies Policy
Last updated: November 2025
This Cookie Policy explains what cookies are, how we use them on niboto, who places them, which categories we use, and how you can manage your choices. We use cookies and similar technologies to ensure smooth operation of the service, security, preference storage, and —with your consent— usage analytics to improve the product. You can change/withdraw your choices at any time via the link “Manage cookies” in the footer.
1) What are cookies?
Cookies are small text files stored on your device (computer, mobile, tablet) when you visit a website. They are used to “remember” information between visits so the website works properly, is more secure, and provides a better user experience.
2) Who sets cookies?
- First-party cookies : set by our own domain (niboto) for core functionality, login, language, security, and storing your choices.
- Third-party cookies : set by third-party providers we use (e.g., Stripe for payments, Google Analytics for analytics, possibly an anti-bot/proxy provider).
How do we use cookies? Like many online services, we use first-party and third-party cookies to:
- ensure the website and dashboard work properly (e.g., login, tenant portal, uploads),
- maintain security (e.g., CSRF, anti-bot, abuse prevention),
- store basic preferences (e.g., interface language),
- understand, with your consent, how the product is used so we can improve it (statistics/analytics).
3) Categories cookies & legal basis (GDPR)
- Strictly necessary : Required to provide the requested service (account login, security, payment flow, consent management). Legal basis: Article 6(1)(b) (performance of a contract) and/or 6(1)(f) GDPR (legitimate interest).
- Preferences/Functionality : Remember settings such as language or specific interface choices so you don’t have to set them every time. Legal basis: consent, unless they are strictly necessary for the specific function you requested (in which case they may fall under the previous category).
- Analytics/Statistics : Anonymous and/or aggregated usage measurement (e.g., Google Analytics 4) so we can see which features are used most and how the website performs. Legal basis: consent (Article 6(1)(a) GDPR).
- Advertising/Targeting : Not currently used on niboto. If such cookies are added in the future, we will update this policy and request explicit consent before enabling them.
4) Cookies we use
Below are the main cookie categories (indicatively), including name, provider, purpose, duration, and legal basis. The table may be updated periodically (e.g., if providers change or cookies are added/removed).
4.1 Strictly necessary (first-party)
- session — Provider: our own domain. Purpose: maintain the session/login, tenant context, and core functionality (dashboard, uploads, settings). Duration: until the browser is closed, or a short persistent period depending on security settings. Legal basis: Article 6(1)(b)/(f) GDPR.
- csrf_token — Provider: our own domain. Purpose: protection against CSRF attacks in forms/POST requests. Duration: usually up to ~2 hours. Legal basis: Article 6(1)(f) GDPR (system security).
- cookie_consent / cookie_preferences — Provider: our own domain. Purpose: store the user’s choices for cookie categories (e.g., whether consent was given for analytics). Duration: up to 12 months. Legal basis: Article 6(1)(c) and 6(1)(f) GDPR (compliance and proof of consent).
4.2 Preferences/Functionality (first-party)
- lang (or equivalent) — Provider: our own domain. Purpose: remembers the website/app interface language so you don’t have to select it each time. Duration: about 6–12 months. Legal basis: consent (Article 6(1)(a) GDPR), unless it is deemed strictly necessary for the requested function.
4.3 Third-party — Necessary for payments (Stripe)
During redirect and/or use of Stripe Checkout, security/functional cookies may be set (e.g.,
__stripe_mid, __stripe_sid
) by Stripe for fraud prevention, device recognition, compliance with security standards, and proper operation of the payment process.
Legal basis: Article 6(1)(b) and/or 6(1)(f) GDPR. The exact settings/durations are determined by Stripe under its own policies.
4.4 Third-party — Protection/anti-bot (if applicable)
If a protection provider is used (e.g., a CDN/anti-bot service), cookies such as
__cf_bm, cf_clearance
or similar, to distinguish between human traffic and bots and protect against attacks (e.g., DDoS).
Legal basis: Article 6(1)(f) GDPR (network and systems security).
4.5 Analytics/Statistics (Google Analytics 4)
Google Analytics (GA4)
— cookies such as the following may be used
_ga, _ga_<container-id>, _gid.
Purpose:
anonymous/aggregated measurement of traffic and basic behavior to improve the product, its features, and site performance.
Indicative durations:
_ga up to 24 months,
_gid up to 24 hours,
_ga_<container-id> up to 24 months.
Legal basis: consent (Article 6(1)(a) GDPR).
These cookies are only loaded if you explicitly choose to accept analytics cookies via the consent banner/mechanism.
Current practice: Before statistics consent, we keep only aggregate page views without visitor_id or a persistent analytics cookie. Visitor journey, product analytics with visitor_id and Google Analytics are activated only if you choose statistics cookies.
We currently do not use a separate optional preferences cookie. Language selection is kept in the application?s necessary session cookie.
| Name | Provider | Category | Purpose | Duration | Legal basis |
|---|---|---|---|---|---|
session |
First-party | Necessary | Login/session, core functions | Session | 6(1)(b)/(f) GDPR |
csrf_token |
First-party | Necessary | CSRF protection | ~2 hours | 6(1)(f) GDPR |
cookie_consent / cookie_preferences
|
First-party | Necessary (consent) | Store user choices for cookies | up to 12 months | 6(1)(c)/(f) GDPR |
__stripe_mid, __stripe_sid
|
Stripe | Third-party necessary | Security & payment checkout operation | as per Stripe’s policy | 6(1)(b)/(f) GDPR |
_ga, _ga_<id>, _gid
|
Analytics | Usage analytics (GA4) | 24 months / 24 hours (indicative) | Consent (6(1)(a) GDPR) | |
__cf_bm, cf_clearance (if applicable)
|
Protection provider (CDN/anti-bot) | Third-party necessary | Anti-bot / DDoS and service protection | as per the provider’s policy | 6(1)(f) GDPR |
5) Cookie consent management
- On your first visit, an information banner appears where you can: Accept all, Reject non-essential or Customize your choices by category (e.g., Analytics).
- You can change/withdraw your choices at any time via the link “Manage cookies” in the website footer.
- For compliance purposes, we may keep a consent log (date/time, banner version, basic choices) in accordance with the Privacy Policy.
6) Disable via browser settings
In addition to the “Cookie settings” mechanism, you can configure your browser to block or delete cookies from specific websites or from all websites. Completely disabling necessary cookies may affect core functions (account login, forms, payments, security) and may make some services unavailable.
Below you can find indicative links with instructions for managing cookies in the most popular browsers:
- Chrome — https://support.google.com/accounts/answer/32050
- Safari — https://support.apple.com/guide/safari/sfri11471/mac
- Firefox — https://support.mozilla.org/kb/clear-cookies-and-site-data-firefox
- Microsoft Edge — https://support.microsoft.com/windows/manage-cookies-in-microsoft-edge...
- Internet Explorer — https://support.microsoft.com/topic/how-to-delete-cookie-files-in-internet-explorer...
If you use a different browser, look up the relevant instructions on its official support page.
7) International transfers & third-party providers
Some third-party providers (e.g., Google, Stripe, a protection/CDN provider) may process data outside the EEA. Where required, we rely on appropriate legal bases and safeguards (such as the EU Standard Contractual Clauses and supplementary measures) to ensure an adequate level of protection under the GDPR. For more information, you can refer to the privacy and cookie policies of the respective providers.
8) Cookie retention period
- Session cookies : are stored temporarily and are automatically deleted when you close your browser.
- Persistent cookies : remain on your device for the period stated in the table, or until you delete them manually via your browser settings or withdraw your consent via “Manage cookies”.
- The exact duration of third-party cookies (e.g., Google, Stripe, CDN/anti-bot) is determined by the respective providers and may change according to their policies.
9) Changes to this policy
We may update this Cookie Policy, for example due to new legislation, guidance from data protection authorities, or changes to the providers/features we use. The “Last updated” indication at the top of the page will be updated accordingly.
In case of significant changes (e.g., adding new cookie categories), a banner or notice may be shown again so you can be informed and, where required, provide renewed consent.
10) Contact and more information
If you have questions about cookie use or data processing on niboto, you can contact us at hello@niboto.ai. For more general information about personal data processing, see also the Privacy Policy.
Note: Scripts for non-essential cookies (such as Google Analytics) are loaded only after your explicit consent via the banner or the “Manage cookies” mechanism. You can change or withdraw your choices at any time.