Legal
Cookie policy
Last updated: [PLACEHOLDER: date set at launch]
What cookies are
A cookie is a small piece of data a website stores in your browser to remember something between visits — that you're signed in, which language you prefer, or that you've already answered the cookie banner. Suward also uses browser storage that serves the same purpose (your cookie-consent choice itself is kept in local storage, not a cookie); this policy covers both under the word “cookie” for simplicity.
Categories
Cookies on Suward fall into three categories, and the cookie banner lets you choose per category: Strictly necessary, always on; Analytics, off until you allow it; Marketing, off until you allow it. Necessary cookies alone are enough to use the site — the other two are optional and can be changed at any time.
Strictly necessary
These keep the site working and cannot be switched off: your signed-in session (accessToken and refreshToken, or the equivalent suward_* cookies depending on which part of the platform you're using), your language preference (i18next), and your theme choice. The short-lived access token expires in about 15 minutes and the refresh token in about 30 days; both are reissued automatically while you stay signed in.
Analytics
Analytics cookies are off by default and load only after you allow them in the banner or the cookie settings. They run Google Analytics (via Google's gtag.js) so we can see which pages are used and where visitors drop off, and Sentry, which reports front-end errors so we can fix them. Turning this category on also sets Google Consent Mode v2's analytics_storage signal to granted.
Marketing
Marketing cookies are off by default. Allowing them loads Google Tag Manager, which we use for advertising and conversion tracking through Google Ads, and sets Google Consent Mode v2's ad_storage, ad_user_data, and ad_personalization signals to granted, so ad platforms can measure whether an ad led to a visit.
How consent works
Your choice is recorded with a timestamp and applies to future visits until you change it or the cookie categories themselves change — if we add a category or materially change what an existing one covers, your saved choice is discarded and the banner reappears. Every visit starts with analytics and marketing denied by default (Google Consent Mode v2); nothing in either category loads until you say yes.
Managing preferences
Change your choice any time from the Cookie settings link in the footer, which reopens the same panel you saw on your first visit. You can also block or delete cookies directly in your browser, but strictly necessary cookies are required for sign-in and core functionality — blocking them will break parts of the site.
Third parties
Analytics and marketing cookies are set by Google (Analytics, Tag Manager, Ads) and, for error reporting, Sentry. Each operates under its own privacy terms in addition to this policy; enabling a category here only decides whether that provider's script runs on Suward, not what the provider does with data once it has it.
Retention
Strictly necessary session cookies expire per the times described above, or when you sign out, whichever comes first. Your language and consent-choice settings persist until you change them or clear your browser storage. [TO CONFIRM: exact retention period Google Analytics, Google Ads, and Sentry apply to their own cookies — set by those providers, not published here]
Do Not Track
Most browsers let you block third-party cookies or send a Do Not Track / Global Privacy Control signal. Suward's cookie-category choice already governs this: if you have not opted into analytics or marketing, those scripts do not load regardless of your browser's Do Not Track setting — there is no separate behavior beyond what the consent banner controls.
Changes
Adding a cookie, changing what a category covers, or adding a new third party updates this policy and, where the change materially affects what a category means, resets your saved consent so the banner asks you again.
Questions about this policy: payments@suward.com