Legal & trust
Cookie Policy
Last updated: July 31, 2026
1. Current position
Brand My Inbox currently uses essential browser storage for authentication, security, service operation, and the consent record. Optional analytics and marketing technologies are not required to use the public site and must remain blocked until the relevant consent is recorded.
2. Categories
Strictly necessary: authentication, load handling, security, requested workflows, and consent memory. Preferences: optional language or interface settings. Analytics: optional aggregated audience and product measurement. Marketing: optional campaign attribution, advertising, or cross-site technologies.
3. Current inventory
brandmyinbox_consent_v1 is first-party local storage used to remember category choices, consent version, timestamp, and whether GPC was detected. It expires logically after 180 days, when the consent version changes, or when the user clears browser storage.
Base44 authentication and security storage may be set when needed for sign-in and service delivery. Exact production cookie names, provider, purpose, type, duration, and domain must be scanned and added to this inventory before launch and after every vendor change.
4. Consent choices
On a first visit, users can accept optional categories, choose essential only, or configure each optional purpose separately. Optional storage must not load before consent. Refusing optional technologies does not block the core public site or account service.
5. Withdrawal and renewal
Open Cookie settings in the footer to change or withdraw choices as easily as they were given. A new choice replaces the previous one for future processing. Brand My Inbox asks again after 180 days or when the consent model materially changes.
6. Global Privacy Control
When the browser sends a recognized Global Privacy Control signal, Brand My Inbox records it and keeps marketing sharing disabled. A future advertising or sale/sharing system must also consume this signal server-side where required.
7. Third-party technologies
Cloudflare, Base44, Google, Stripe, embedded media, or other providers may use necessary or optional technologies according to the feature used. Optional third-party tags must be added to the inventory and connected to the correct category before deployment.
8. Governance
Run an automated and manual cookie scan on public, authenticated, checkout, OAuth, and embedded-content flows before launch and after releases. Keep consent logs, vendor records, processing purposes, retention, transfer terms, and proof that rejection works. This policy must be updated when the inventory changes.