Cookie Policy
What we store on your device, why, and how to change your mind. Strictly necessary by default; everything else is opt-in.
Summary
We use a minimal set of strictly necessary cookies for authentication, security and the consent record itself. Everything else - functional preferences, analytics, marketing - is off by default and only set after you opt in via the banner. You can change your choice any time from the footer link, and we ask again after 12 months.
Overview
This Cookie Policy explains how Michal Jatczak T/A ITSailor, a sole trader registered in Malta (Malta VAT MT32760411, DUNS 507601021), uses cookies and similar technologies (local storage, session storage, pixels) on itsailor.io and on the SaaS dashboards we operate (SEAWALL, HOIST, DECKLOG - currently in sales MVP phase).
We operate under Article 5(3) of the ePrivacy Directive (2002/58/EC, as amended by 2009/136/EC) and its Maltese implementation in the Processing of Personal Data (Electronic Communications Sector) Regulations (S.L. 586.01), made under the Data Protection Act (Chapter 586). Non-essential cookies are set only after you give informed, specific, freely given, and unambiguous consent (CJEU Planet49, C-673/17, paragraphs 49-65).
Cookie categories
We classify cookies into four categories, aligned with EDPB guidance and the structure of our consent banner:
- Strictly necessary - required for the site to function: authentication, CSRF protection, the consent record itself, and the anti-bot check that protects our public forms from automated abuse. These are exempt from the consent requirement under the second sentence of Article 5(3) of the ePrivacy Directive (see Recital 66 of Directive 2009/136/EC), because the storage is strictly necessary to provide the service you requested. The personal data they involve is still processed under GDPR Article 6(1)(b) and Article 6(1)(f). Always on.
- Functional - remember preferences you set (e.g. dark mode, language). Not required for the site to work; opt-in.
- Analytics - cookie-free measurement through Plausible Cloud, hosted in the EU. It does not create an advertising profile or a cross-site identifier. The tracker loads only after opt-in.
- Marketing - currently disabled across the entire site. If we ever enable a retargeting pixel or attribution tracker (e.g. for a specific LinkedIn or Google Ads campaign), it goes here. Opt-in.
Per-cookie inventory
The table below is the canonical inventory at the effective date of this Policy. Each row was traced to the file that sets or reads the cookie before it was published, because this is the one claim on the site anyone can check against a live browser in under a minute. We refresh it whenever a category changes, and notify active customers per section 08.
Strictly necessary
| Name | Purpose | Set by | Duration |
|---|---|---|---|
itsailor_consent_v1 | Records the cookie choices you made in the banner: one decision per category, plus the schema version and a random consent ID. Without it we would have to ask you again on every page. | itsailor.io (first-party cookie, and the same value in localStorage) | 12 months from the decision, then the banner asks again |
__Host-directus_session_token | Keeps you signed in to the customer dashboard after you log in with an ITSailor account. | itsailor.io (first-party, httpOnly, Secure). Over plain HTTP in local development the same cookie is set without the __Host- prefix. | The session lifetime our identity service returns, or 30 days if you tick the box to stay signed in |
__Host-directus_refresh_token | Renews the session token in the background so an active session does not drop you back to the login screen. | itsailor.io (first-party, httpOnly, Secure). Unprefixed in local development, as above. | 7 days, or 30 days if you tick the box to stay signed in |
__Secure-next-auth.session-token | Signed-in session for the dashboard when you log in with your Microsoft work account through Entra single sign-on. Read on every dashboard request to decide whether you are signed in. | itsailor.io (first-party, httpOnly, Secure), set by our authentication library. Outside HTTPS it is named next-auth.session-token. | We set no explicit lifetime, so the default of the authentication library applies. Signing out deletes it immediately. |
next-auth.csrf-token | Cross-site request forgery protection for the single sign-on flow. It ties the sign-in request you started to the response that comes back. | itsailor.io (first-party) | Session. It is cleared when you close the browser, and on sign-out. |
portal_claim | Single-use token that links a purchase you just made to the Microsoft account you are about to sign in with, when your work account differs from the email you paid with. Set only when you open a claim link we sent you. | itsailor.io (first-party, httpOnly) | 15 minutes |
panel_company_id | Remembers which of your companies is the active one in the dashboard, so subscriptions, users, orders and invoices all open on the same organisation. Set only after you sign in, and only to a company your account belongs to. | itsailor.io (first-party, httpOnly) | 12 months |
_GRECAPTCHA | Bot and abuse scoring on our two public forms: the contact form and the free FinOps scan request. reCAPTCHA v3 is invisible and shows no challenge. It is not used for advertising or cross-site profiling. | Google LLC, via www.recaptcha.net (third-party) | Set and controlled by Google, approximately 6 months. That is the default Google documents, not a commitment we can make. |
One qualification on that table. Every row was verified against our own source except the ones a third party sets because of a script we load: _GRECAPTCHA. For those, the lifetime is what the provider documents. It is not a figure we can read from our own code, and it is not a commitment we can make on the provider's behalf.
Functional · opt-in
No functional cookies are active at the effective date of this Policy. When we add one (e.g. a dark-mode preference), it will be listed here and the consent schema version will bump - your banner re-appears so you can decide.
Analytics · opt-in
Plausible does not set an analytics cookie. When the production integration is enabled, its EU-hosted cloud endpoint receives cookie-free page views and selected conversion events only after analytics consent. Form contents, dashboard routes, checkout routes, arbitrary query parameters, and dynamic report identifiers are removed before a request can leave the browser. The redacted request is sent to a path on itsailor.io and relayed from there to Plausible. We do that because most filter lists match on the vendor name, so measuring an audience of IT operators without it counts a biased sample. It changes nothing about what is sent, and nothing is sent at all until you opt in. What Plausible keeps is aggregate: counts per page, per referrer, per country and per device class, with no visitor-level record behind them. How far back that aggregate history reaches is a property of the plan we hold and can change when the plan does; the aggregation itself does not. See the Plausible data policy.
Marketing · opt-in
No marketing cookies are active. If we ever run a paid attribution pixel (e.g. for a specific LinkedIn Ads campaign), the vendor, cookie name, and retention are added here before the campaign goes live.
How consent works
The first time you visit itsailor.io, a consent banner appears at the bottom of the page. You have three options. Each one is a single click on that banner, none is hidden behind an extra step, and there is no dark pattern between them (EDPB Guidelines 05/2020 require refusing to be as easy as consenting):
- Accept all - opts you in to all four categories.
- Reject all- leaves only strictly-necessary on. The site continues to work in full. We do not operate a “consent or pay” model: rejecting non-essential cookies is free and gives you the same access (EDPB Opinion 08/2024).
- Customize - opens a panel with one toggle per category. Strictly necessary is locked on; the other three are independent.
Whichever you choose, your decision is recorded in itsailor_consent_v1(localStorage) plus an audit row in our consent_log Directus collection. The audit row contains: the event type (accept-all / reject-all / save-selection / withdraw), the schema version that was active, the categories you chose, your user agent, a SHA-256 hash of your IP when the production-only CONSENT_IP_HASH_SALT is configured (otherwise no IP hash is written), and a server timestamp. We never store the raw IP in this log.
Your choice is remembered for 12 months. After that the banner asks again, with your previous answers pre-loaded, so a decision is renewed rather than inherited indefinitely.
You can change or withdraw your choice at any time:
- Open the Cookie preferences link in the site footer. The settings panel re-opens with your current state pre-loaded.
- Save a new selection. The change writes another
consent_logrow and adjusts which cookies fire from that point forward. - Plausible sets no analytics cookie. Every page view and conversion event re-checks the current consent record before it is sent, so turning analytics off stops them from that moment. The tracker already running on the page you are reading keeps sending its engagement ping for that one page, so the change takes full effect from your next page load.
Third-party cookies
We currently set no third-party advertising or cross-site tracking cookies. The third-party requests we make are:
- Plausible Cloud- the cookie-free analytics tracker is loaded from the browser only after analytics consent and sends redacted page and conversion events to Plausible's EU-hosted service. It is not used for advertising or cross-site profiling.
- Stripe Checkout - when you initiate a purchase, Stripe sets payment-processing cookies on the Stripe-hosted checkout page (you are redirected to
checkout.stripe.comfor the transaction). Stripe's cookie policy applies on that page; ours does not. - Google reCAPTCHA v3 - runs on our two public forms: the contact form and the free FinOps scan request. The script is served from
www.recaptcha.net, withwww.google.comandwww.gstatic.comallowlisted in our content security policy for the assets Google documents as fallbacks. It sets the_GRECAPTCHAcookie and collects device, network and interaction signals, including your IP address, to score whether a submission is automated. It is invisible and shows no challenge, and it is not used for advertising or cross-site profiling. We treat it as strictly necessary (section 03) because those two forms are the abuse surfaces we cannot leave open. Google may process that data in the United States; Google's applicable data-transfer safeguards and terms apply. - Microsoft Entra- if you sign in to the dashboard with your Microsoft work account, Microsoft sets authentication cookies during the redirect. Microsoft's cookie policy applies on those pages.
- Google Workspace connector- the SaaS Auditor Google Workspace connector redirects your administrator to Google's own consent screen, where Google sets its cookies. There is no Google sign-in for the ITSailor dashboard itself.
- YouTube / Vimeo embeds - none currently embedded on itsailor.io. If we add a video embed in the future, we will use the privacy-extended embed mode where the platform supports it, and gate the embed behind a click-to-load placeholder until consent is given.
Do Not Track and Global Privacy Control
We honour the Global Privacy Control (GPC) signal. If your browser signals GPC (the navigator.globalPrivacyControl property that browsers set alongside the Sec-GPC request header), we read it on page load and record a Reject-all decision for you, exactly as if you had made it through the banner. The check runs in your browser: our servers do not read the header. This aligns with EDPB Guidelines 05/2020 on signals that constitute valid expressions of refusal.
The older Do Not Track (DNT) signal is honoured the same way. We read navigator.doNotTrack, its Microsoft-prefixed variant, and window.doNotTrack. Where a browser sends contradictory signals (DNT off + GPC on, or vice versa), the more privacy-preserving signal wins.
Changes to this Policy
We refresh this Policy whenever the cookie inventory changes. Material changes - adding a new vendor, a new category, or a new purpose for an existing cookie - are announced by email to active customers at least 30 days before they take effect, and trigger a schema-version bump that re-prompts the consent banner.
Non-material changes (typographical corrections, vendor reference URL updates, restructuring of this Policy without changing what cookies fire) are made silently with a revised effective date.
Contact and complaints
- Data Subject Rights requests (access, rectification, erasure, objection, withdraw consent in writing): dsr@itsailor.io
- General privacy questions: privacy@itsailor.io
- Legal: legal@itsailor.io
Postal: Michal Jatczak T/A ITSailor, Level 1, Unit 60, Door No 63, Connecticlub Business Center, Triq Il-Ballut (Zona Industrijali, Mosta), MST 4001, Mosta, Malta.