OwlMeans

Cookie Policy

Recorded Effective Date: 24 September 2026

Recorded Last Updated: 25 September 2026

Draft prepared: 6 October 2026. Pending activation. Recorded dates concern the preceding version.

Draft revised: 7 October 2026. Activation remains pending.

Non-binding summary. Essential storage supports login, language and requested work. Optional analytics needs a separate choice. Google Ads is not used, and the company site and Platform manager serve their fonts locally. Browser choices are separate from email marketing or training permission. This summary is outside the operative notice.

1. Operator and scope

1.1. Igor Tkachenko OwlMeans Software (trading as “OwlMeans Software, JDG”), NIP 6772507251, EU VAT identifier PL6772507251, REGON 527979906, ul. Ariańska 9/5, 31-505 Kraków, Poland; support@owlmeans.com; telephone +48 780 256 571, operates the website and Platform described in the Privacy Policy. Cookies, localStorage, sessionStorage and IndexedDB can store identifiers or content. Customer-operated applications and external login/payment pages have their own notices.

2. Verified storage and conditional services

ItemPurpose/categoryPersistence
site_cookie_consent cookie and localStorageNecessary record of analytics/marketing choices; contains category values and schema versionCookie: 365 days from writing. localStorage has no automatic expiry and persists until cleared or replaced.
owlmeans-lng, locale_chosen, preferred_locale; themeNecessary requested language/theme preferencelocalStorage until cleared or replaced; no timed expiry verified.
IndexedDB database keyval-store, object store keyval: auth:user, auth:_listLogin and access control. The user record contains the app’s bearer credential; the list is its record index.No automatic browser expiry. Sign-out removes auth:user and the corresponding list entry; the list can remain empty. Current manager server-session validity is separately limited to 7 days; invalidity does not delete the browser record.
Same IndexedDB store: state:flow:state:flow, state:flow:auth-control-state, state:flow:resume-flow, state:flow:_listRequested workflow, redirect and authentication state, including route/input and temporary authentication challenges.No generic browser expiry. Authentication callbacks/controller cleanup remove the control record. The standard login/resume continuation has a 30-minute logical deadline and is removed when consumed or discarded; physical deletion is not scheduled for that deadline.
Same IndexedDB store: vib-intent-draft:current, vib-intent-draft:_listThe Platform manager’s retrieved visitor prompt and record index; a prompt can contain personal data.Draft logical validity 24 hours; expired record removed on later read, or on create/dismiss. No logout purge is configured for this draft. Server handoff reference is separate, single-use and expires in 120 seconds.
localStorage _owlmeans-login-terms, _owlmeans-login-landed, _owlmeans-marketing-consent-skippedAccepted-version UI marker, post-login deduplication and current-sign-in optional-choice skip marker. The landed marker stores a bearer credential; the skip marker normally stores a session identifier and can fall back to the bearer. Neither skip nor the browser version marker substitutes for recorded consent/contractual evidence.No automatic browser expiry or removal on ordinary logout in the current implementation. Values can remain until replaced or site data is cleared.
sessionStorage _owlmeans-oidc-popup, owlmeans:chunk-reloadRequested sign-in popup state and recovery from a failed application-code load.Browser tab/page session, subject to browser restore behavior. Popup state is removed by its clear action. The reload timestamp provides a 60-second retry cooldown rather than a timed storage-deletion rule.
Integrated sign-in cookies _session, _interaction, _interaction_resume; conditional _session.sig, _interaction.sig, _interaction_resume.sigOpaque OIDC session/interaction identifiers and, where configured, their signature companions. Essential sign-in and authorisation state; the session cookie is not the raw access/refresh-token set.Current provider defaults: session 14 days, renewed on provider activity; transient sessions can use a browser-session cookie. Interaction/resume cookies have a 1-hour limit; resume clears its resume cookie and consumes the server interaction. Sign-in cookie names/options and effective overrides depend on deployment. Local application logout does not itself end the provider session.
owlcc link parameter and language parameterCarries selected category choices/language between configured first-party domainsChoice-link timestamp valid for five minutes with clock-skew allowance; parameter removed on adoption. It is not a shared-domain cookie or an account marketing grant.
Google Tag Manager and Google AnalyticsActive measurement services; optional analytics requires its category grant. Google Ads and personalised advertising are not active Platform purposes.Published measurement-tag configuration, cookie names, event fields and actual durations remain to be verified before this revision activates; no unverified duration is asserted.
Google reCAPTCHA; _GRECAPTCHA and any other storage set by the actual integrationActive bot, fraud and abuse prevention in selected protected workflows. A strictly necessary security exception applies only where its legal conditions are met; non-essential device access requires the applicable prior choice. Security processing is separate from analytics, advertising and account marketing permissions.Google documents _GRECAPTCHA for risk analysis when the service executes. Verify actual domains, other storage, data fields and lifetimes before activation; no unverified expiry or blanket consent exemption is asserted.
Sentry diagnostic identifiers or browser storage, if configuredConfirmed diagnostic service; essential error reporting must be proportionate. Optional replay, profiling or device access requires the applicable separate choice.Exact SDK settings, transmitted context, storage and retention require verification. Diagnostic use does not authorise recording prompts, secrets or unrestricted session replay.
Cloudflare, Stripe, Google sign-in and GitHub storageActive network, payment, identity and repository services; storage depends on the service and requested operationActual cookie names and lifetimes follow the verified configuration and relevant provider notice. Requested login/payment/security functions must be distinguished from optional tracking; active service use does not establish a cookie on every page.
Fonts on the company site and Platform managerFont files served locally for page presentationNo visitor request to a Google font CDN is required by these two interfaces. Customer-operated/generated applications have their own configuration and notices.

2.1. Essential functions do not permit unnecessary fingerprinting or marketing. The applicable session identifiers, optional tags, recipients and storage durations shall be disclosed before this revision activates or a new optional service begins.

2.2. The first-party names and lifecycles above describe the current default source configuration. An origin’s IndexedDB resources share the named store; a resource prefix is not a separate database. Browser clearing, eviction, overwrite and server invalidation are distinct from scheduled deletion. OIDC cookies default to HttpOnly and SameSite=Lax; secure transport and any signing or configuration override must follow the actual deployment. Server-issued access and ID tokens default to 1 hour, authorisation codes to 60 seconds, and provider grants/refresh tokens to 14 days subject to their scope and configuration; these are credential-validity rules, rather than a claim that every browser item or supplier copy is deleted at those times.

2.3. Customer-operated applications require their own inventory and notice. Where an application uses the current OwlMeans-generated template, the following additional keys may be present; their presence depends on that application’s version and enabled functions. This table does not make its operator’s independent analytics an OwlMeans marketing purpose.

Conditional application itemPurpose/categoryPersistence
sessionStorage owlmeans:visit-keyPseudonymous guest ownership key, which can associate guest-created records with the later signed-in userTab/page session, including browser restore behavior; retained through sign-in, with no fixed wall-clock deadline or logout removal.
sessionStorage owlmeans:landing-handoff, owlmeans:landing-continued, owlmeans:landing-anchorRequested landing-input continuation, duplicate-continuation marker and return-scroll position; input can contain personal dataHandoff logical validity 30 minutes, expired entry removed when read. Explicit handoff clearing removes the handoff and continued marker; other tab state follows its own consume/clear action or the page session.
sessionStorage owlmeans:auth-seenSign-in/out event deduplication marker intended for optional analytics; stores in or out, not an authentication credentialTab/page session. The current template writes the marker when authentication state is read, independently of whether analytics events are delivered. Any non-essential storage or event use requires the applicable prior choice; category gating must be verified before use. Its presence does not grant tracking consent.
Conditional component cookie sidebar_state and localStorage owlmeans:color-schemeSidebar or colour preference only where that component is used; neither is established as a current Platform-manager writerSidebar default 7 days; colour preference until changed/cleared, removed on selecting the system default.

2.4. The inquiry widget holds unsent text, contact choices and selected files in page memory; it does not itself save an inquiry draft in cookies, localStorage, sessionStorage or IndexedDB. An unsent draft survives closing the dialog and changing its topic while the widget remains mounted. A successful draft clears when its confirmation closes; page unload or widget removal ends that in-memory state. CRM API calls omit browser credentials and use a fresh single-use anti-bot guest token for submission, rather than the Platform’s stored account bearer or a new login session. This does not prevent Google’s reCAPTCHA script from performing its separately disclosed device/security processing or a browser from retaining its own autofill information.

3. Choices and cross-domain handling

3.1. Optional categories start denied. Accept, reject or adjust them through cookie preferences; necessary storage is disclosed rather than presented as optional consent. Change or withdraw choices through the same preferences facility; browser settings also delete or block storage and may disable requested functionality. Withdrawal stops future optional tracking; it does not erase data already lawfully collected, for which privacy rights remain available.

3.2. The shared choice covers owlmeans.com, owlmeans.pl and the configured OwlMeans Platform host disclosed in the dialog. Decorated first-party links can carry a fresh choice and language. Existing destination choices are not automatically overwritten, so a change on one origin may require changing preferences on another. This is not real-time global synchronisation. Language storage is necessary when explicitly chosen and does not depend on optional tracking permission.

3.3. Legal pages omit the optional tag loader in the reviewed site implementation; essential preference adoption may still run. Google consent mode defaults optional signals to denied, with the container withheld until the relevant grant. Each individual tag must also enforce its category; consent mode is not by itself proof that no recipient received data.

3.4. On the company site’s inquiry triggers, the widget runtime is requested from the configured OwlMeans Platform host after a click; the manager may load its same-origin runtime for its contact button or on pointer/focus preloading. The dialog’s first opening requests its security configuration and loads Google reCAPTCHA before submission or the inquiry checkbox is selected. A click or checkbox alone is not consent to otherwise non-essential terminal access: the strictly necessary conditions or appropriate prior choice must cover that processing. Refusing analytics does not prevent sending an inquiry. The inquiry_dialog_open event, with inquiry_widget, inquiry_tab and inquiry_source, reaches the analytics data layer only while analytics consent is granted; refused events are dropped, not held for later consent. The event does not contain the form’s email, message or files. Legal pages have no inquiry widget in the reviewed site implementation. Support email, postal and telephone channels remain available if browser verification is blocked.

4. Regional safeguards

4.1. EU/EEA terminal-access rules, Polish electronic-communications law, German TDDDG §25 and French rules require prior consent for non-essential storage/access, with the appropriate strictly necessary exceptions. Consent must be freely given and withdrawal accessible. Applicable US opt-out/GPC requirements and UK rules remain preserved. Further purposes, recipients, rights and retention are stated in the Privacy Policy; materially new tracking requires renewed information and any necessary fresh choice.