Legal
Cookie Policy
This policy explains the storage and trackers TransferOps uses, and how your choices control them. The short version: strictly necessary storage keeps you signed in; analytics and session replay run only if you say yes; and you can change your mind anytime.
1. What cookies and storage are
Cookies are small records a website stores in your browser. "Local storage" is a similar browser facility. Sites use them to keep you signed in, remember preferences, and — with your consent — measure how the product is used. This policy covers both.
2. Strictly necessary (always on, no consent needed)
Sign-in session — an authentication cookie set by our auth provider so you stay signed in securely. Without it the application cannot function. Interface preferences — your theme (light/dark) and sidebar state, stored locally in your browser. Consent record — your privacy choice itself ("votra.consent.v1" in local storage), so we don't ask you on every visit and so your refusal is respected persistently. Wizard drafts — an offboarding form in progress is kept in session storage so an accidental refresh doesn't lose your work. None of these track you across other sites and none are used for advertising.
3. Product analytics (opt-in)
With your consent, we use PostHog and Vexo to measure how the product is used — page views, feature usage, funnel events, and error reports — to decide what to improve. When you decline (or haven't decided), these tools are not initialized and send nothing: no cookies, no local storage, no beacons. When you accept, PostHog stores a first-party identifier in your browser; you can sign in without being individually identified if you prefer to decline.
4. Session replay (separate, specific opt-in)
With your specific consent — a separate switch, off by default even if you accept analytics — PostHog may record sessions on authenticated in-app pages: page content, interactions, and console output, so we can see and fix real problems. Recordings are used for debugging only, are never used for advertising, and are retained for a limited period. We chose to make this a separate switch because it is more sensitive than aggregate analytics; you can accept analytics and still decline replay.
5. What we never use cookies for
No advertising cookies. No cross-site tracking. No data sales. No sharing of your browsing behavior with data brokers. No third-party ad networks receive anything from your browser when you use Votra.
6. Global Privacy Control (GPC)
If your browser sends the Global Privacy Control signal, we honor it as an opt-out: optional analytics and session replay stay off for your visits regardless of any earlier choice, and the banner stays suppressed. You can still use "Cookie settings" to re-enable explicitly.
7. Changing your choice
Use "Cookie settings" in the footer of any page to revisit your decision at any time — turning things off takes effect immediately and stops future collection. Your choice persists across visits; if you declined, we do not re-prompt you on every page (that would be a dark pattern, and we don't do those).
8. Third-party recipients and retention
When consented, analytics data goes to PostHog (US cloud, EU Standard Contractual Clauses) and Vexo; see the "Who we share data with" section of our Privacy Policy for the full vendor list and safeguards. Analytics identifiers are kept only while your consent remains in effect.
9. Contact
Questions about this policy: privacy@votra.dev.
Effective date: September 22, 2026.
