IEInvoiceEU

Cookie Policy

What this site stores in your browser, and why. The short version: only what is needed to keep you signed in and to remember your own interface preferences. There is no advertising and no cross-site tracking.

Last updated 2026-09-09

Draft — company details pending

The structure and substance of this document are in place, but the operating company’s identity, address and contact details have not been filled in yet. Every outstanding item is marked below. This document is not yet binding and has not been reviewed by a lawyer.

Fill in LEGAL_ENTITY in src/data/legal.ts and this notice disappears.

1. Why there is no cookie banner

Article 5(3) of the ePrivacy Directive requires consent for storage that is not strictly necessary to deliver a service the user has asked for. Everything listed below is either strictly necessary or is stored only in your own browser and never read by us, so no consent is required and no banner is shown.

If we ever add analytics or any non-essential storage, this page will change and a genuine consent mechanism will appear first — one that works if you decline.

2. Cookies we set

CookiePurposeLifetime
Session tokenKeeps you signed in. HTTP-only, Secure and SameSite-restricted, so it cannot be read by scripts or sent from another site.Session
CSRF tokenEnsures a sign-in or sign-out request came from this site and not another one.Session
Callback URLReturns you to the page you were on after signing in.Session

These are set by the authentication library the application uses. Blocking them makes signing in impossible.

3. Local storage

The application remembers small interface preferences in your browser’s local storage — for example whether the sidebar is collapsed. This never leaves your device, is not sent to our servers, and clearing your browser data removes it.

4. Third parties

Payment pages are hosted by Stripe, which sets its own cookies for fraud prevention when you are on them. That happens on Stripe’s domain, under Stripe’s own policy, and only when you go through checkout or the billing portal.

If you sign in with Google, Google sets cookies on its own domain during that exchange. Some images on the public site are served from a third-party image host, which receives your IP address as any image host would; it sets no cookies of its own.

There are no analytics, advertising, social or fingerprinting scripts on this site.

5. Controlling storage

Every browser can block or delete cookies and site data. Blocking the cookies in section 2 will prevent you from signing in; blocking local storage only means the interface forgets your preferences.

Questions about this page go to privacy@ address.