🇷🇴 Română · 🇬🇧 English

Cookie Policy — Zephren

Version 1.2.0 · In force since 5 August 2026.

1. What are cookies?

Cookies are small text files that your browser stores on your own device (computer, tablet, phone) when you visit a website. They allow the site to “remember” certain preferences (language, theme, login) or to measure, in aggregate, how the site is used, in order to improve it.

We distinguish between first-party cookies (stored directly by zephren.ro) and third-party cookies (stored by one of our sub-processors — e.g. Supabase for authentication, Cloudflare for bot protection).

2. Legal framework

  • Law 506/2004 Art. 4 para. (3) — processing of personal data in the electronic communications sector (RO transposition of ePrivacy)
  • GDPR (EU Regulation 2016/679) Art. 7 — conditions for consent: explicit, specific, informed, granular and withdrawable at any time
  • ePrivacy Directive 2002/58/EC Art. 5(3) — cookies that are not strictly necessary require prior opt-in
  • ANSPDCP Decision no. 174/2018 — guidance on the validity of consent in the digital environment

3. Cookies we use

Transparency note: Zephren follows the “minimum necessary” principle. All essential cookies serve a strictly technical purpose, with no profiling. Analytics cookies are active only if you choose “Accept all” or “Customise → Analytics”. Rejecting them switches them off entirely — but it does not switch off aggregate measurement, which continues without cookies; see section 3.2.

3.1 Essential (always-on, no opt-in required)

Under Art. 5(3) ePrivacy, these cookies are strictly necessary for the operation of the Service — without them you cannot log in, preferences are not saved and the interface does not display correctly.

CookieProviderPurposeDuration
sb-<id>-auth-tokenSupabaseAuthentication session (JWT)7 days
zephren.cookie-consentZephrenYour consent preferences12 months
themeZephrenTheme preference (dark/light)12 months
langZephrenPreferred language (RO/EN)12 months
currency_modeZephrenDisplay currency (EUR/RON/auto)12 months
__cf_bmCloudflare TurnstileBot protection on forms30 minutes

3.2 Analytics (opt-in required)

Active only after your explicit consent. They help us identify usability issues, technical errors and prioritise improvements. All sensitive inputs (passwords, email, tax ID, phone) are masked automatically before being sent to providers.

CookieProviderPurposeDuration
ph_*PostHog (EU Cloud, Frankfurt)Product analytics + session replay with masked inputs (passwords, email, tax ID)12 months
sentry-traceSentry (Irlanda DPA)Error tracking + stack-trace correlation (PII scrubbed)session

If you reject: the cookies in the table above are not placed at all, nothing is written to or read from your browser’s local storage, no profile is created and you are not linked to your account; error monitoring (Sentry) stays fully off. We nevertheless continue to count visits and actions in aggregate, through a temporary identifier computed on PostHog’s servers (from IP address and user agent, with a value that rotates daily), which never reaches your device. Basis: Art. 5(3) ePrivacy — transposed by Art. 4 para. (5) of Law 506/2004 — covers storage on and access to terminal equipment, neither of which the cookieless mode performs, so consent does not apply; processing of the identifier rests on legitimate interest, Art. 6(1)(f) GDPR, with a right to object (Art. 21). If your browser sends the Do Not Track signal, we measure nothing.

3.3 Marketing (opt-in required — currently disabled)

CookieProviderPurposeDuration
No marketing cookies are active at present. We will notify you 30 days in advance if we activate any.

4. Managing consent

You can change your preferences at any time, without penalty. Withdrawing consent does not affect the lawfulness of processing carried out previously (GDPR Art. 7 para. 3).

This will reopen the consent banner.

5. How to disable cookies in your browser

In addition to the banner options, you can block/delete cookies directly from your browser. Note: blocking essential cookies will affect the operation of the Service (you will not be able to log in, preferences will disappear, etc.).

6. Changes to this policy

Any substantial change increments the cookie-policy version above (see COOKIE_POLICY_VERSION) and is published here, dated. The banner reopens by itself only when what we actually asked you to accept changes — a new purpose or a new type of storage on your device. A clarification, a correction or a change of provider does not reset your choice; you can nevertheless change it at any time, using the button in section 4.

7. Contact and related information

Last updated: 5 August 2026. Document provided as is; for legal interpretation we recommend consulting a lawyer specialised in GDPR / ePrivacy. In case of any discrepancy, the Romanian version prevails.

Folosim cookies

Folosim cookie-uri esențiale pentru funcționarea aplicației (sesiune, preferințe). Cu acordul dumneavoastră adăugăm cookie-uri de analiză (PostHog EU, Sentry) și de marketing (GDPR Art. 7).

Dacă refuzați, nu se scrie și nu se citește nimic pe dispozitivul dumneavoastră — nici cookie-uri, nici stocare locală — iar monitorizarea erorilor (Sentry) rămâne complet oprită. Continuăm totuși să numărăm, agregat, vizitele și acțiunile din aplicație, fără să vă identificăm, fără profil de utilizator și fără să vă putem recunoaște la o vizită următoare. Detalii și temeiul juridic în Politica de confidențialitate și în Politica de cookie-uri.