Skip to main content

Cookie Policy

Last updated: May 31, 2026

Document owner: Privacy Engineering Lead and Data Protection Officer delegate Review cadence: Quarterly; ad hoc on tracker, vendor, product, or legal requirement changes Effective date: 2026-05-31 Controller / Legal entity: EthicPages, Inc. Registered address: 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ Primary contact: ethicpages+contact@invictosoft.com

1. Purpose and scope

This Cookie Policy explains how EthicPages, Inc. ("EthicPages," "we," "us," or "our") uses cookies and similar technologies when you visit our website, authenticate to your workspace, interact with hosted Trust Center pages, process subscription checkout flows, or engage with support surfaces and product communication interfaces.

This policy should be read together with our Privacy Policy, Terms of Service, and Data Processing Agreement. If you are a customer administrator, you may have additional responsibilities to provide notice to your users regarding technologies deployed in your own configured public pages.

2. What cookies and similar technologies are

Cookies are small text files placed on a device (browser, mobile webview, or similar client) to store identifiers or settings. Similar technologies include:

  • local storage/session storage entries
  • SDK or script-generated identifiers
  • pixel tags and event beacons
  • server logs that correlate session identifiers

For readability, this policy uses "cookies" as an umbrella term unless a distinction is legally required.

2.1 Categories used in this policy

CategoryDescriptionTypical legal basis in EEA/UK
Strictly necessaryRequired for core site and account functions such as authentication and securityLegitimate interest and/or contract necessity; consent typically not required
FunctionalSupports preferences and enhanced usability (language, display state)Consent where legally required
AnalyticsMeasures traffic, behavior trends, and service performanceConsent in EEA/UK; legitimate interests in some other jurisdictions
Performance diagnosticsDetects errors and latency to improve reliabilityConsent in EEA/UK where non-essential identifiers are used
Marketing/advertisingAttribution and campaign optimization cookiesConsent required in EEA/UK

EthicPages does not rely on cross-context behavioral advertising cookies for resale of user data. We do not sell personal data as defined by many privacy laws.

3. How and why we use cookies

We use cookies to keep the Service secure, stable, and usable for procurement and compliance workflows. Specific uses include:

  1. Maintaining authenticated sessions and preventing account misuse.
  2. Preserving security signals required to detect suspicious activity.
  3. Improving product quality through aggregated usage measurements.
  4. Understanding performance bottlenecks and reliability patterns.
  5. Supporting lawful and transparent billing and checkout experiences.

3.1 Essential versus analytics distinction

Use caseEssential?Why
Session authentication and CSRF defenseYesRequired to safely log in and keep sessions protected
Checkout and anti-fraud validationYesRequired for secure payment completion and abuse prevention
Feature usage counting for product planningNoUseful for optimization but not required to provide core service
Campaign attribution for growth analysisNoOptional and consent-gated where required
Error diagnostics with persistent identifiersUsually noHelpful for debugging but not always essential

Where a cookie is not essential, we request consent before storing or reading it in jurisdictions that require prior consent (including EEA and UK contexts).

4. Consent management and user choices

EthicPages uses a consent interface that allows users to review cookie categories and make category-level choices. The interface appears on first relevant visit and can be reopened through footer controls or preference settings.

4.1 Consent states and behavior

Consent stateStrictly necessary cookiesAnalytics cookiesMarketing cookies
No choice yetAllowedBlocked in consent-required regionsBlocked in consent-required regions
Accept allAllowedAllowedAllowed
Reject non-essentialAllowedBlockedBlocked
Custom selectionAllowedBased on user choiceBased on user choice

4.2 Withdrawal of consent

Users can withdraw consent at any time via cookie settings. Withdrawal does not affect lawfulness of processing before withdrawal but stops future processing relying on consent. Existing cookies may remain until expiry unless manually removed from browser settings; however, we stop using blocked categories after preference update.

5. EEA/UK and similar jurisdiction requirements

For visitors located in the European Economic Area (EEA), United Kingdom, and similar jurisdictions, EthicPages applies an opt-in model for non-essential cookies. This means we do not activate analytics or other non-essential categories unless consent is collected.

5.1 Regulatory alignment posture

Requirement areaEthicPages approach
Prior consent for non-essential cookiesEnabled for EEA/UK flows
Granular category controlsProvided via cookie banner/preferences panel
Ability to withdraw consentProvided at all times via settings/footer access
Documentation and recordsConsent states retained according to retention policy
Vendor transparencyListed in this policy and Subprocessors

Where local law differs by country or sector, Customer remains responsible for jurisdiction-specific obligations in its own implementation context.

6. Cookie inventory

The following inventory describes common cookie classes used by EthicPages. Names may vary by deployment, browser, and update cycle. We periodically review and update this table.

6.1 Authentication and session cookies

Cookie or identifier classProviderPurposeCategoryTypical retention
ep_sessionEthicPagesMaintains authenticated user sessionStrictly necessarySession to 30 days depending on remember-me setting
ep_csrfEthicPagesPrevents cross-site request forgeryStrictly necessarySession
ep_auth_stateEthicPagesStores sign-in flow state and anti-replay metadataStrictly necessarySession
ep_org_contextEthicPagesPersists selected workspace contextFunctional/necessaryUp to 30 days

6.2 Security and abuse prevention

Cookie or identifier classProviderPurposeCategoryTypical retention
ep_security_tokenEthicPagesCorrelates suspicious session behaviorStrictly necessaryUp to 12 months
ep_rate_limit_keyEthicPagesSupports anti-automation controlsStrictly necessaryUp to 24 hours
stripe_mid / related anti-fraud keysStripeFraud detection and secure payment processingStrictly necessaryVaries by processor policy

6.3 Analytics and performance

Cookie or identifier classProviderPurposeCategoryTypical retention
ep_analytics_idEthicPages analytics stackDistinguishes repeat visits for aggregate reportingAnalyticsUp to 13 months where consented
ep_perf_sessionEthicPages monitoring toolsCorrelates page performance tracesPerformance diagnosticsSession to 30 days
ep_feature_flagsEthicPagesEnables staged rollout analysis and experiment governanceFunctional/analyticsUp to 90 days

6.4 Communication and campaign measurement

Cookie or identifier classProviderPurposeCategoryTypical retention
ep_campaign_refEthicPagesStores referral source for campaign attributionMarketing/analyticsUp to 90 days
ep_newsletter_prefEthicPagesStores explicit email preference selectionsFunctionalUp to 12 months

This inventory is representative and may change as vendors and service architecture evolve. Material changes affecting legal rights are reflected in policy updates and, where required, renewed consent prompts.

7. Retention and lifecycle management

Cookie retention is based on purpose, legal basis, and operational need. We avoid indefinite storage and remove or rotate identifiers as part of security and privacy controls.

7.1 Retention standards

Data classRetention approach
Strictly necessary session identifiersUsually session-based or short-lived persistent tokens for secure authentication
Security event correlation tokensLonger retention when required to investigate abuse and attacks
Analytics identifiersLimited retention with periodic rotation and consent dependence
Marketing attribution valuesShort-to-medium retention based on campaign measurement need and consent

We may shorten retention windows in response to legal updates, incident learnings, or customer commitments.

8. Browser and device controls

Most browsers allow users to block, restrict, or delete cookies. Device controls may include private browsing modes, cookie lifetime restrictions, site-level settings, and anti-tracking features.

8.1 Practical implications of disabling cookies

Action by userPotential impact
Block all cookiesSign-in, account persistence, and checkout may fail
Delete session cookies frequentlyRepeated sign-ins and interrupted workflows
Block third-party cookies onlySome integrations, payment steps, or diagnostics may degrade
Use strict anti-tracking modeCertain embedded content or analytics features may not function

Blocking strictly necessary cookies can prevent secure use of the Service. If a procurement or legal team requires strict lockdown settings, we recommend validating critical workflows in advance.

9. Do Not Track and global privacy controls

Some browsers transmit "Do Not Track" (DNT) signals or related preference headers. Because industry standards for DNT response have not been uniformly adopted, our handling may vary by context and legal requirement. In jurisdictions where recognized global privacy controls have legal force, we honor them in accordance with applicable law and technical feasibility.

10. Third-party technologies and subprocessors

Certain cookies are set by trusted third-party providers supporting hosting, billing, analytics, communication, and reliability functions. Third-party processing is governed by contractual safeguards and review controls described in our Subprocessors List and Data Processing Agreement.

10.1 Third-party safeguards

SafeguardDescription
Vendor due diligenceSecurity, privacy, and reliability review before onboarding
Contractual controlsData processing agreements and confidentiality clauses
Access limitationRole-based access and least privilege for operational access
Transfer mechanismsSCCs and supplementary safeguards where required

11. Customer responsibilities for hosted pages

If you use EthicPages hosted Trust Center capabilities, you remain responsible for:

  1. Providing legally accurate disclosures to your own visitors.
  2. Configuring consent behavior to align with your jurisdictional obligations.
  3. Ensuring your own embedded scripts or external tags comply with law.
  4. Coordinating privacy notices with your legal, security, and procurement teams.

EthicPages provides configuration support but does not assume legal responsibility for Customer-specific compliance determinations.

12. Children and sensitive categories

EthicPages is a B2B service and is not directed at children. We do not intentionally deploy non-essential tracking to users known to be under legal age thresholds for consent. We also avoid building categories intended to infer sensitive personal characteristics from behavioral data.

13. Security controls for cookie data

Where applicable, we apply security controls such as:

  • secure and HttpOnly cookie flags for authentication tokens
  • same-site policies to reduce CSRF exposure
  • encryption in transit
  • limited internal access to cookie-derived telemetry
  • retention and deletion controls aligned to purpose

Cookie data can still present risk if user devices are compromised. Customers should enforce endpoint hygiene and organizational security controls.

14. Policy updates and change notifications

We may update this Cookie Policy to reflect legal requirements, technology changes, or product development. Material changes are announced through website notices, application prompts, or direct communication where appropriate. The "Effective date" and last-updated value identify the active version.

If required by law, we seek renewed consent before activating materially different non-essential cookie purposes.

15. Contact and rights requests

For cookie-related questions, consent records, or privacy rights requests, contact us at ethicpages+contact@invictosoft.com. You may request additional details about cookie categories, retention logic, and jurisdictional handling.

15.1 Contact matrix

Inquiry typeContact route
Cookie and tracker questionsethicpages+contact@invictosoft.com (subject: Cookies)
Privacy rights requestethicpages+contact@invictosoft.com (subject: Privacy Rights)
Security concernethicpages+contact@invictosoft.com (subject: Security)
Postal noticeEthicPages, Inc., 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ

Related documents: Privacy Policy · Terms of Service · Data Processing Agreement · Subprocessors · Acceptable Use Policy

Template for operational transparency; not legal advice. Consult qualified counsel for your jurisdiction.