Cookie Policy
Effective date: September 9, 2026 Version: 1.2 (English)
This English version is provided for convenience. Users located in the Russian Federation are additionally governed by the Russian-language Cookie Policy at /cookies. In case of discrepancy, the Russian version prevails for users in the Russian Federation.
1. What are cookies
Cookies are small text files placed on your device by a website. They allow the site to remember your actions and preferences (such as language, authentication, and analytics signals) over time.
We also use similar technologies — local storage, session storage, and pixels — which we refer to collectively as "cookies" in this Policy.
2. How we use cookies
We use cookies to:
- Keep you signed in to your Account;
- Remember your language, theme, and workspace preferences;
- Protect the Service against fraud and abuse;
- Measure how the Service is used, in aggregate, so we can improve it;
- Deliver marketing content only where you have consented.
3. Categories of cookies
3.1 Strictly necessary (always on)
Required to operate the Service: authentication, session, Supabase SSR, CSRF protection, load balancing, consent preferences. Without these cookies, the Service cannot function. These do not require consent under GDPR.
The complete list:
sb-*— Supabase authentication session (httpOnly)NEXT_LOCALE— interface language, 365 days. URLs carry no locale prefix, so the cookie is the only carriercurrent_brand_id— the brand selected in the dashboard, 365 days (httpOnly)ym_oauth_state— CSRF state while connecting Yandex Metrica, 10 minutes (httpOnly)geo_ref— the partner code you arrived with, so their commission can be credited on payment, 90 days (httpOnly, no cross-site tracking)geo-scout-cookie-consent— your banner choice, stored in localStorage (not a cookie) together with the document version and date
We set no functional cookies. Interface preferences — theme, table state, dismissed hints — live in the browser's localStorage, are never sent to us or to third parties, and identify no one.
3.2 Analytics
Help us understand how visitors use the Service in aggregate.
- Umami Analytics — self-hosted on the Operator's infrastructure in Russia, privacy-friendly and sets no cookies. Runs without consent as aggregate first-party statistics.
- Yandex Metrica — measures our own traffic, including referrals from AI systems. Sets its own cookies (
_ym_uid,_ym_d, 1 year;_ym_isad, 2 days;yabs-sid, session) and is operated by Yandex LLC (Russia). Loaded only after you consent to analytics in the cookie banner — before that the script is not added to the page.
3.3 Marketing
We do not use third-party advertising cookies on GEO Scout. If this ever changes, you will be asked for consent through our cookie banner.
3.4 Session recording
We do not record your sessions for behavioural analytics.
The only exception is an application crash: an error report may carry a replay of the actions that led to it (Sentry Session Replay). All on-screen text is masked and media is blocked in such a recording — it shows the shape of the interface, never the content of your data.
Session recording on public pages (outside the dashboard) may be enabled for statistics, and only with your consent to analytics technologies and with text masking. It is never enabled inside the dashboard.
4. Third-party cookies
Some pages may embed third-party services (for example, YouTube videos in the knowledge base, or the YooKassa checkout). When you interact with these, the third party may set its own cookies governed by its own policy.
Services we load ourselves:
- Yandex Metrica (Yandex LLC, Russia) — analytics, consent-gated. Privacy policy↗
- Sentry (EU region, Germany) — crash diagnostics. Events are scrubbed before they leave us: e-mail, IP address, cookies and authorisation headers are stripped, and the user is identified only by an opaque id. Requests go through our own server (
/api/sentry), so your IP address never reaches Sentry.
5. Your choices
- Cookie banner. On your first visit, you may accept, reject, or customise non-essential cookies. All three actions carry equal weight; nothing optional loads before you choose.
- Change your mind. The "Change cookie settings" button at the bottom of this page reopens the banner. Withdrawing consent is as easy as giving it.
- Account settings. Dashboard → Settings → Privacy → Analytics toggle. It controls the same consent; for signed-in users the choice is also stored with its date, IP address and document version.
- Browser settings. You can delete or block cookies at any time through your browser. Blocking strictly-necessary cookies will break sign-in and other critical features.
- Do Not Track. We respect explicit "Do Not Track" signals where technically feasible; we already minimise tracking by default.
6. Retention
| Cookie type | Retention |
|---|---|
| Authentication session | Until sign-out or 30 days of inactivity |
| Language / theme / preferences | 365 days |
Consent preference (geo-scout-cookie-consent, localStorage) | Until you clear site data |
| Analytics (first-party, Umami) | No cookies set |
Yandex Metrica (_ym_uid, _ym_d) | 1 year |
7. Changes
We may update this Policy to reflect changes in technology or law. Material changes will be announced in-app or by email.
8. Contact
Questions about cookies: support@geoscout.pro.