QReportly

QReportly

Sign in

Technical transparency

Cookie Policy

This document explains how the QReportly Platform uses cookies and similar technologies, in accordance with Directive 2002/58/EC (ePrivacy) and Regulation (EU) 2016/679 (GDPR).

Last updated: 31 August 2026

01

Introduction

QReportly (the "Platform" or the "Provider") uses cookies and local storage technologies only to the extent necessary for secure operation of services, in line with data minimization and user transparency principles.

This Cookie Policy supplements the Privacy Policy and Terms of Service. Optional analytics or advertising cookies on the public marketing website are loaded only after an affirmative choice in the cookie banner. Authenticating in the administration panel uses strictly necessary cookies.

02

What Cookies Are

Cookies are small text files stored on the user's device when visiting a website. They enable browser recognition, session maintenance, preference storage, and implementation of security controls.

Similar technologies include local storage (localStorage, sessionStorage) and session identifiers, used for the same technical purposes and subject to the same minimization safeguards.

03

Technical and Structural Cookies

The reporting channel and the authenticated administration panel use strictly necessary cookies (session, CSRF, locale, workspace). Those cookies are required to provide the service the user requested. The public marketing website may additionally load Google Analytics or Meta Pixel when those tools are configured, and only after the visitor accepts analytics cookies. Mere continued browsing is not treated as consent for those optional cookies.

sessionStorage is used for short-lived UI state (for example a reporting-channel language override and dismissing an MFA reminder). The application does not write Channel Data to localStorage. Mere continued browsing is not treated as consent for optional analytics cookies.

  • Dashboard authentication: maintaining secure administrator sessions and validating access tokens;
  • Language preference (qreportly_locale): storing the selected language for the public interface and authenticated area;
  • CSRF anti-fraud tokens: protecting forms and sensitive actions against cross-site request forgery attacks;
  • Workspace Switcher: storing active workspace context when an administrator manages multiple organizations;
  • Technical session cookies: ensuring operational continuity and integrity of reporting flows for authenticated users.
NamePurposeTypeTypical duration
qreportly_cookie_consentStores essential-only vs analytics choice. Not set by continued browsing.Preference12 months
qreportly_localeUI languageStrictly necessary12 months
next-auth.session-token (or __Secure- prefix)Dashboard authenticationStrictly necessarySession / up to 90 days
qreportly_mfa_okRecords a completed MFA step-up for privileged actionsStrictly necessaryAligned to session
qreportly_officer_session / qreportly_active_identityDesignated-person sessionStrictly necessarySession
qreportly_partner_session and related OAuth state cookiesPartner portal authenticationStrictly necessary (partner surfaces)Session
qreportly_auth_intent / qreportly_auth_locale / qreportly_auth_flowSign-in / registration flow continuityStrictly necessaryShort-lived
qreportly_affiliate_refPartner referral attribution when a referral parameter is present. Not used on the reporting channel for advertising.Functional / attribution30 days
Stripe checkout cookiesPayment fraud prevention and checkout (Stripe policies apply)Strictly necessary for paid checkoutSet by Stripe
Google Analytics / Meta Pixel cookiesLoaded only if NEXT_PUBLIC_GA_ID or NEXT_PUBLIC_META_PIXEL_ID is configured and the visitor accepts analytics. Not loaded on /report/ routes.Optional — consentVendor-defined

Retention Period

Session cookies expire upon browser closure or sign-out. The language preference cookie may persist for up to 12 months to avoid repeated resets of user choice. Durations are limited to what is strictly necessary.

04

Secure Third-Party Services — Stripe

For recurring subscription payment processing, the Platform integrates the Stripe payment processor. During checkout and payment method management flows, Stripe may place security cookies on the user's device.

These cookies are used strictly for transaction fraud prevention, payment session validation, compliance with PSD2/SCA obligations, and card data security — card details are not stored on QReportly servers.

Use of Stripe cookies is governed by Stripe's privacy and cookie policies. The Provider recommends reviewing official Stripe documentation for additional details on exact categories and durations.

05

Behavioral Tracking Exclusion

The secure application and the reporting channel intended for whistleblowers do not load Google Analytics, Meta Pixel, or other advertising/analytics modules. Optional analytics or advertising cookies, if configured, apply only to public marketing pages after consent.

The Provider does not collect IP addresses, geolocation data, or digital fingerprints (browser fingerprinting) from reporters in the public reporting channel, in accordance with the anonymity architecture described in the Privacy Policy.

If aggregated analytics tools are used on the public presentation website (for example, anonymized traffic statistics), they are technically separated from the secure reporting area and do not create individual reporter profiles.

06

Cookie Management

Users can configure their browser to refuse cookies or delete existing cookies. Refusal of strictly necessary cookies may prevent dashboard authentication, language preference storage, or payment completion.

Cookie management instructions are available in the documentation of the browser used (Chrome, Firefox, Safari, Edge, etc.).

For Stripe cookies, restrictions may affect the ability to complete online transactions under acceptable security conditions.

07

Cookie Policy Updates

The Provider may update this Policy to reflect technical changes, integration of new essential providers, or legal requirements. The latest update date is indicated in the document header.

The version published on the Platform prevails over any prior versions.

For questions regarding cookie use on the QReportly Platform: