This Cookie Policy is provided by Lars Eppendahl, sole proprietor, trading as saasvisionary.com (“we”, “us”; full details in our Imprint). It supplements our Privacy Policy.
1. What cookies and similar technologies are
Cookies are small text files that a website stores on your device through your browser. Similar technologies include local storage, session storage, pixels and device fingerprinting. Under § 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG), storing information on your device or accessing information already stored there generally requires your consent, unless it is strictly necessary to provide a service you have explicitly requested.
2. Our website (saasvisionary.com)
When you first visit our website, a banner asks whether you allow analytics. Accepting and rejecting are equally easy. Without your consent, nothing except your choice is stored on your device and no analytics take place. You can change your decision at any time via the “Cookie settings” link in the footer. We do not use advertising or retargeting tools, tracking pixels, social media plugins, or externally loaded fonts or videos.
With your consent, the analytics of our own platform (app.saasvisionary.com, see section 3.3 of our Privacy Policy) stores the following in your browser. <key> stands for the ID of our website.
| Name | Type | Purpose | Lifetime | Category |
|---|---|---|---|---|
app.k.<key> |
Local storage | Remembers your consent decision so the banner is not shown on every page | Until you withdraw or clear your browser storage; we ask again after 6 months | Strictly necessary |
app.v.<key> |
Local storage | Pseudonymous visitor ID that recognises returning visits | Until you clear your browser storage or withdraw consent | Analytics (consent) |
app.s.<key>, app.ss.<key> |
Local / session storage | Groups page views into one visit; a new visit starts after 30 minutes of inactivity | Session, or until cleared | Analytics (consent) |
app.a.<key> |
Local storage | Remembers the campaign or referring page you came from | Until you clear your browser storage or withdraw consent | Analytics (consent) |
| Referral cookie | Cookie | Only if you arrive through a partner link: attributes an order to the partner | As set for the partner program | Analytics (consent) |
If your browser sends a “Do Not Track” signal, the analytics do not run at all.
Our hosting provider uses a bot-protection service to protect the website against attacks. If this service shows you a verification step (captcha), it sets the following cookie:
| Name | Provider | Purpose | Lifetime | Type |
|---|---|---|---|---|
__Host-stackprotect_state |
Our hosting provider (bot protection) | Holds a random ID for the verification you have just passed, so that you are not asked again straight away | 10 minutes | Strictly necessary |
This cookie is used solely to distinguish legitimate visitors from automated attacks. Such strictly necessary security measures do not require consent (§ 25(2) no. 2 TDDDG).
3. Our app (app.saasvisionary.com)
When you sign in to the SaaSVisionary app, we use cookies and similar technologies that are strictly necessary to provide the service you requested. Without them, the app cannot work.
The names of the platform’s own cookies start with a technical prefix of the platform; they are listed here by function.
| Cookie | Purpose | Lifetime | Type |
|---|---|---|---|
| Sign-in cookie (may be split into several parts) | Keeps you signed in | Cookie up to 400 days; the sign-in itself ends after 24 hours of inactivity or after 7 days at the latest | Strictly necessary |
| Sign-in verifier | One-time check when you use a sign-in link or reset your password | Removed after use | Strictly necessary |
| Active account | Remembers which account you are working in | 1 year | Strictly necessary |
| Trusted device | Remembers that you trusted this device after two-factor sign-in (only if you choose this) | 30 days | Strictly necessary |
| Passkey challenge | Security check during passkey sign-in | 5 minutes | Strictly necessary |
| View-as / support access | Read-only “view as member” for account staff, and explicitly granted support access | 2 hours / 8 hours | Strictly necessary |
Integration check (e.g. stripe_oauth_nonce) |
Security check while you connect an integration | 10 minutes | Strictly necessary |
| Side menu | Remembers a collapsed side menu (only set when you collapse it) | 1 year | Functional, set at your request |
__stripe_mid, __stripe_sid (Stripe) |
Payment fraud prevention, only on screens that take a payment | 1 year / 30 minutes | Strictly necessary |
__cf_bm (Cloudflare) |
Bot protection, only if it is triggered | 30 minutes | Strictly necessary |
The sign-in cookies are marked “Secure” and are only sent over encrypted HTTPS connections. Local storage in your browser holds only interface preferences (for example theme, panel positions, unsent report drafts, dismissed notices and recently used emoji) until you clear it; none of it is used for tracking. No analytics, advertising pixels, session recording or third-party chat widgets are loaded in the app; fonts are served from our own domain, and Stripe’s script loads only on screens that take a payment.
- Legal basis for storage and access: § 25(2) no. 2 TDDDG (strictly necessary for a service explicitly requested by you).
- Legal basis for any related processing of personal data: Art. 6(1)(b) GDPR (performance of the contract) and Art. 6(1)(f) GDPR (security of the service).
- These cookies are set by our platform provider (USA), which operates the app on our behalf as our processor. See our Privacy Policy for details on this provider and the related transfer safeguards.
Stripe
When you enter payment details, Stripe’s payment form may set its own cookies, which Stripe uses to process the payment securely and to prevent fraud. These are necessary to carry out the payment you requested. Stripe’s own privacy and cookie information applies.
Features configured by customers
Customers can use SaaSVisionary to build their own websites, forms, chat widgets or booking pages. Any cookies used on those customer pages are the responsibility of the respective customer, who must inform visitors and obtain consent where required.
4. Our commitment
For any cookie or similar technology on our website or in the app that is not strictly necessary (such as the website analytics described in section 2), we:
- ask for your consent in advance through a consent banner, with equally prominent options to accept or reject;
- do not activate these tools until you have consented;
- let you withdraw your consent at any time as easily as you gave it (“Cookie settings” in the footer); and
- keep this Cookie Policy and our Privacy Policy up to date.
5. How to manage cookies in your browser
You can view, block and delete cookies in your browser settings at any time. The relevant options are usually found under:
- Chrome: Settings → Privacy and security → Third-party cookies / Delete browsing data
- Firefox: Settings → Privacy & Security → Cookies and Site Data
- Safari: Settings (or Preferences) → Privacy → Manage Website Data
- Edge: Settings → Cookies and site permissions → Manage and delete cookies and site data
Please note that if you block strictly necessary cookies for app.saasvisionary.com, you will not be able to sign in or use the app.
6. Contact
If you have questions about cookies or this policy, please contact us at privacy@saasvisionary.com.