Cookie Policy

Last updated: 27 May 2026

1. About This Policy

This Cookie Policy explains how Garisea uses cookies and similar tracking technologies on the partner dashboard at partner.garisea.com, what each one does, how long they last, and how you can control them.

It pairs with the Partner Privacy Notice, which describes how the data we collect via cookies is processed.

2. What Cookies Are

A cookie is a small text file a website stores in your browser to remember something between pages or visits — your login session, your preferred theme, the cookie-consent flag itself.

The dashboard also uses related browser storage technologies — localStorage, sessionStorage, and IndexedDB — for the same purposes. Everything in this policy applies to those equally.

We group cookies into four categories: essential, preference, analytics, and error monitoring. You can manage every category except essential through the cookie consent banner on first visit and from your browser settings any time.

3. Essential Cookies

Strictly necessary for the dashboard to work. Without them you can't sign in, submit a form, or stay authenticated across pages. They cannot be disabled in-app — your only option is to block cookies entirely at the browser level, which breaks the dashboard.

CookiePurposeLifetime
access_tokenAuthenticates your dashboard session. HttpOnly + Secure + SameSite=Lax.30 minutes
refresh_tokenAllows your session to be refreshed without re-entering your password. Rotated on every use.30 days
garisea_csrfCSRF protection token for state-changing requests.Session
cf_*Bot mitigation + DDoS protection tokens set by our security provider.30 minutes
garisea_partner_cookie_consentRemembers your cookie preferences so the banner doesn't reappear.1 year

4. Preference Cookies and Local Storage

These remember choices you've made so we can present the dashboard the way you like it. You can clear them anytime from your browser; Garisea will reset to its defaults next visit.

Key / CookiePurposeLifetime
themeLight / dark / system theme preference.1 year
sidebar_expandedWhether the dashboard sidebar is expanded or collapsed.1 year
recent_searchesYour last few command-palette searches for quick reuse.90 days
timezoneDetected timezone used to render dates and times in your local zone.Session

5. Analytics Cookies

Analytics cookies help us understand how partners use the dashboard — which features get reached, where partners drop off, which screens convert. The aggregate insights help us prioritise improvements. We only set analytics cookies after you accept via the cookie consent banner. They can be revoked anytime by re-opening the banner or clearing the consent cookie.

Our analytics provider sets a small number of cookies on your browser to:

  • Distinguish unique visitors (a 2-year identifier).
  • Maintain per-property session state across page loads (also up to 2 years).

We additionally set a pseudonymous device_id cookie (1 year) that ties your dashboard sessions together for our own product analytics. It does not contain your name, email, or other personal data.

The analytics provider is configured with IP anonymization on and data-sharing with its advertising ecosystem off. We do not use it for advertising remarketing or cross-app tracking.

6. Error Monitoring

A third-party crash-monitoring provider captures errors and crashes that occur in the dashboard so we can fix them. It collects the stack trace, request context (URL, query params with sensitive fields scrubbed), your user ID for correlation, and a hashed IP. Emails and names are scrubbed. We rely on legitimate interestas our lawful basis for error monitoring (it's necessary for platform security and stability) and so this category is not gated by the cookie consent banner. You can't opt out of error monitoring without losing the ability for us to diagnose dashboard errors affecting your account.

7. Third-Party Cookies and Embedded Content

Some features depend on third-party services that set their own cookies in your browser. We don't control these cookies — they fall under each provider's privacy policy.

  • Bot mitigation / DDoS protection — security cookies set automatically when you load any partner.garisea.com page; required for the dashboard to function safely.
  • Google Sign-In and web push — when you authenticate with Google or grant web-push permission, the underlying provider may set its own cookies. Subject to its privacy practices.
  • Image and video CDN — when partner logos, KRA PIN images, and verification documents load, the media CDN may set minimal cookies for cache validation.
  • Payment processing— when you're redirected to our payment provider's checkout page to top up the wallet, buy a lead pack, or renew a subscription, the provider sets its own session cookies. These are scoped to the provider's domain and never reach partner.garisea.com.

8. Managing Your Preferences

You can change your cookie preferences in three ways:

  • The consent banner. Shown on first visit and re-shown after you clear the consent cookie. Toggle analytics on or off there.
  • Browser DevTools. Application → Cookies → delete garisea_partner_cookie_consent; the banner reappears on next page load with your previous selections cleared.
  • Browser-level controls.Chrome, Safari, Firefox, and Edge all let you view, block, and delete cookies per site. Search your browser's help for “manage cookies” — the exact path varies. Blocking essential cookies will break authentication.

Disabling analytics cookies has no functional impact — you'll just be less visible to us in aggregate metrics. Disabling essential cookies breaks sign-in and the dashboard cannot operate.

9. Do Not Track and Global Privacy Control

We respect the Global Privacy Control (GPC) signal sent by browsers that support it. When your browser sends a GPC header, we treat it as an explicit opt-out of analytics cookies for that session. We don't respond to the older “Do Not Track” header because it's been deprecated by every major browser; we rely on the consent banner instead.

10. Equivalent Storage in the Mobile App

Garisea's partner surface is web-only — there is no Garisea mobile app on the partner side. (Customers have a mobile app on iOS and Android; its storage practices are described in the customer-facing Cookie Policy.) When you operate the dashboard from a mobile browser on your phone or tablet, the cookies described in §3–§7 apply normally.

11. Changes to This Cookie Policy

We may update this Cookie Policy as we add or remove third-party services, change retention periods, or align with new regulations. Material changes are notified via the dashboard. The “Last updated” date at the top of this page reflects the most recent revision.

12. Contact

Cookie-related questions: [email protected] or [email protected].