Legal
Cookie Policy
Last updated: 20 August 2026
01
1. What this covers
This page is an inventory, not a description. It lists every cookie TOVR sets and every key it writes to your browser's local storage, with what each one holds and how long it lasts.
"Cookies" here means cookies and anything equivalent — local storage, session storage — because Art. 5(3) of the ePrivacy Directive treats storing information on your device the same way regardless of the mechanism.
The previous version of this page described "Supabase authentication tokens" and "analytical cookies". Neither existed: Supabase is not part of TOVR, and our analytics runs without cookies. It has been replaced with the real list.
02
2. Your choice, and how to change it
Strictly necessary cookies are set without asking, because the platform cannot run without them and Art. 5(3) ePrivacy exempts them.
Everything else is off until you switch it on. Nothing analytic is loaded before you answer the banner — not merely nothing captured; nothing loaded.
To change your answer at any time, use the "Cookie settings" link in the footer of every page, or Settings → Preferences → Privacy if you are signed in. Withdrawing is exactly as easy as consenting: one click, from the same dialog.
If your browser sends Global Privacy Control or Do Not Track, we record a rejection and never show you the banner.
We do not treat scrolling, continued browsing or closing the banner as consent. If you ignore the banner, nothing non-essential is set and you will be asked again.
Browser settings are NOT the consent mechanism here, and we no longer point you at them. Deleting cookies in your browser deletes the record of your choice along with everything else, which means we have to ask again — it is not a way to say no. The dialog is.
03
3. Cookies we set
All of these are first-party — set by tovr.eu, readable by nobody else.
| Name | Provider | Purpose | Category | Duration |
|---|---|---|---|---|
| __Secure-tovr.session_token | TOVR | Keeps you signed in | Necessary | 30 days |
| __Secure-tovr.session_data | TOVR | Short-lived session cache | Necessary | 5 minutes |
| __Secure-tovr.account_data | TOVR | Short-lived account cache | Necessary | 5 minutes |
| __Secure-tovr.dont_remember | TOVR | Marks a session you asked not to be remembered | Necessary | Session |
| tovr.consent | TOVR | Your cookie choices, so we stop asking | Necessary | 12 months |
| NEXT_LOCALE | TOVR | The language you chose | Functional | Session |
| sidebar_state | TOVR | Whether the sidebar is open or collapsed | Functional | 7 days |
| oauth_org_id | TOVR | Integration connect flow: which organisation is connecting | Necessary | 10 minutes |
| oauth_provider_slug | TOVR | Integration connect flow: which provider | Necessary | 10 minutes |
| oauth_provider_id | TOVR | Integration connect flow: which provider record | Necessary | 10 minutes |
| oauth_account_label | TOVR | Integration connect flow: the label you gave the account | Necessary | 10 minutes |
| oauth_scopes | TOVR | Integration connect flow: the permissions you selected | Necessary | 10 minutes |
| __stripe_mid | Stripe | Fraud prevention on billing pages only | Necessary | 1 year |
| __stripe_sid | Stripe | Fraud prevention on billing pages only | Necessary | 30 minutes |
04
4. What we store in your browser
These are not cookies. They are keys in your browser's local storage: they stay on your device, are never sent with a request, and are readable only by tovr.eu. They are listed because the law is about storing information on your device, not about the word "cookie".
Clearing site data in your browser removes all of them.
| Key | What it holds | Category |
|---|---|---|
| theme | Light or dark mode | Functional |
| app-state-store | One-time carrier for display preferences migrated to your account | Functional |
| onboarding-checklist | Which setup steps you have completed or dismissed | Functional |
| tovr:lastAuthMethod | Which sign-in method you used last, so it is offered first | Functional |
| tovr:view-mode:* | Table or card view, per screen | Functional |
| tovr:integrations-layout | Layout of the integrations page | Functional |
| tovr:canvas:chain-builder | View settings of the chain builder canvas | Functional |
| tovr-shipments-page-browser | Your saved freight filters and the organisation identifiers they are scoped to | Functional |
05
5. What we do not set
• No advertising cookies. No remarketing, no conversion pixels, no ad networks. We do not run advertising.
• No cross-site tracking, and no third-party tracker embedded in our pages.
• No analytics cookies. PostHog runs in memory-only mode — with consent it measures usage within the page you have open, and stores nothing on your device. This is a deliberate choice and we would rather say it plainly than claim a category we do not use.
• No social media widgets or share buttons that phone home.
Stripe's two cookies appear only on billing pages, are set by Stripe for payment fraud prevention, and are described in Stripe's own privacy policy.
06
6. More
The Privacy Policy explains what we do with personal data generally, who receives it, and what your rights are. The Sub-processors page lists every provider involved.
Questions about this page: [email protected].