- Scope
- Poland / European Union
- Document status
- production ready
- Questions
- support@airreclaim.com
1. Scope
This Cookies Policy explains how Nova Group Sp. z o.o., operating AirReclaim, uses cookies, local storage, pixels, tags, consent signals, and similar technologies on airreclaim.com.
It should be read with the Privacy Policy. The live Cookiebot consent banner or cookie settings widget provides the most specific current list detected on the website.
2. What these technologies do
A cookie is a small text file stored by a browser. Local storage is browser storage that can hold identifiers or preferences. Pixels and tags can send information when a page, advertisement, or email is viewed or used. Consent Mode signals communicate your consent choices to Google services; the signals are settings rather than cookies themselves.
These technologies can be:
- essential, to operate security, authentication, forms, sessions, payments, consent records, and requested services;
- preference, to remember optional interface choices;
- analytics, to measure use and improve the website;
- marketing, to measure advertising, attribute conversions, create audiences, or personalize advertising;
- authentication, to keep a user securely signed in; or
- payment and security, to process a transaction and prevent fraud.
3. Consent
Essential technologies are used where necessary to provide a service you request, secure the website, remember your privacy choice, authenticate an account, or process a payment. They do not depend on optional cookie consent.
Analytics, marketing, and other non-essential technologies are activated only after the required consent has been obtained. In the European Economic Area, Switzerland, and the United Kingdom, our intended configuration is to set non-essential Google consent states to denied until the visitor makes a choice.
You may accept or reject categories independently where the consent interface offers those categories. Refusing optional technologies does not prevent use of the core compensation-checking and claim-management functions, although some measurement, personalization, or convenience features may be unavailable.
4. Cookie and storage table
Names and duration can vary by browser, provider, domain, product configuration, and provider updates. A wildcard such as _ga_* means any cookie beginning with that pattern.
| Provider | Cookie, local-storage name, or pattern | Category | Purpose | Typical retention | Consent required | Notes |
|---|---|---|---|---|---|---|
| AirReclaim | airreclaim_session, session_*, or equivalent session identifier | Essential / authentication | Maintain a secure website or account session and requested workflow state | Session | No | Exact name depends on the deployed authentication and application configuration |
| AirReclaim | csrf_*, nonce, or equivalent security token | Essential / security | Prevent cross-site request forgery, replay, and unauthorized form submission | Session | No | Contains a security value rather than claim content |
| AirReclaim | airreclaim_locale or equivalent preference | Preference | Remember language or regional display choice | Up to 12 months | Yes where local law requires | May instead be stored as an essential account preference after sign-in |
| Cookiebot CMP by Usercentrics | CookieConsent | Essential / consent | Store the visitor's consent categories and evidence of the choice | 12 months | No | Needed to remember and demonstrate the privacy choice |
| Cookiebot CMP by Usercentrics | CookieConsentBulkTicket | Essential / consent | Share a consent choice across configured related domains where that function is enabled | 12 months | No | Present only when cross-domain bulk consent is configured |
| Google Consent Mode v2 | analytics_storage, ad_storage, ad_user_data, ad_personalization | Consent signals | Communicate granted or denied states to Google tags | Tied to the CMP choice, typically up to 12 months | No separate consent | These are consent states, not browser cookies; they control tag behavior |
| Google Analytics 4 | _ga | Analytics | Distinguish browsers for aggregate website measurement | Up to 24 months | Yes | Used only after analytics consent where required |
| Google Analytics 4 | _ga_* | Analytics | Maintain and count a Google Analytics session or property state | Up to 24 months | Yes | The suffix identifies the relevant measurement property |
| Google Analytics 4 | _gid where configured | Analytics | Distinguish visitors for short-term measurement | 24 hours | Yes | May not be present in all GA4 configurations |
| Google Analytics 4 | _gat* where configured | Analytics | Throttle request rate | About 1 minute | Yes | May not be present in all GA4 configurations |
| Google Ads | _gcl_au | Marketing / measurement | Store and measure advertising conversions | 90 days | Yes | Used for conversion attribution |
| Google Ads | _gcl_aw | Marketing / measurement | Store Google Ads click and conversion information | 90 days | Yes | Present where the relevant conversion-linking function is used |
| Google Ads | _gcl_dc | Marketing / measurement | Store campaign and conversion information for supported advertising products | 90 days | Yes | Present where the relevant advertising product is used |
| Google Ads and Google services | gclid, wbraid, gbraid, or related click identifiers in cookies, storage, or URLs | Marketing / measurement | Attribute a visit or conversion to an advertisement | Up to 90 days | Yes for storage or advertising use | A click identifier can also appear temporarily in a landing-page URL |
| Google advertising services | IDE, DSID, NID, ANID, test_cookie, or related Google-domain cookies | Marketing / remarketing | Advertising delivery, frequency control, audience functions, conversion measurement, and testing cookie support | Session to 13 months | Yes | Third-party names and availability vary by browser, region, Google product, and personalization setting |
| Plausible Analytics | No cookie in the standard cookieless configuration | Analytics | Count aggregate page views, sources, and short-lived daily unique visits without persistent visitor storage | No persistent browser retention | Usually no in strict cookieless mode | If optional custom or personal-data features change the configuration, the consent and disclosure position will be reassessed |
| PostHog | ph_*, posthog_*, and related local-storage identifiers | Analytics / product measurement | Measure product use, link events within a browser, and support product analytics | Up to 12 months | Yes in persistent mode | Not set before consent in the consent-based configuration; strict cookieless mode does not store cookies or local-storage identifiers |
| PostHog | Session-recording and feature identifiers where enabled | Analytics | Support consented session analysis, diagnostics, feature measurement, and playback controls | Session to 12 months | Yes | Session recording should be configured to mask sensitive fields and remain disabled without the required consent |
| Clerk | __session | Essential / authentication | Carry a short-lived session token for signed-in access | About 60 seconds, refreshed while the session remains active | No | Required for account authentication |
| Clerk | __client, clerk_*, or related authentication storage | Essential / authentication | Maintain the authenticated client, refresh state, fraud protection, and sign-in continuity | Session to 12 months depending on configuration | No | Exact names and life depend on the Clerk deployment and user session |
| Stripe | __stripe_mid | Essential / payment security | Distinguish a browser for payment fraud prevention | About 12 months | No | Set where Stripe.js or a Stripe payment interface is used |
| Stripe | __stripe_sid | Essential / payment security | Support payment-session fraud prevention | About 30 minutes | No | Set where Stripe.js or a Stripe payment interface is used |
| Stripe | m, pay_sid, __Host-LinkSession, or related Stripe security and authentication cookies | Essential / payment security | Secure payment, authentication, Link, and fraud-prevention functions | Session to 12 months | No | Names depend on the Stripe payment function selected |
| Worldline | Worldline payment session cookies | Essential / payment | Maintain a secure checkout, authentication, transaction, and return flow | Session | No | Exact names vary by Worldline product and acquiring configuration |
| Worldline | Worldline fraud-prevention and device identifiers | Essential / payment security | Detect fraud, protect transactions, comply with payment-network and regulatory requirements | Session to 13 months | No where strictly necessary | Any Worldline analytics or advertising technology not strictly necessary requires the applicable consent |
| Website security provider | __cf_bm, _cfuvid, or equivalent security cookies where used | Essential / security | Bot management, traffic integrity, rate control, and abuse prevention | 30 minutes to session | No | Present only where the configured security provider sets them |
| Email delivery provider | Secure link or message identifiers | Essential / service communication | Deliver claim communications, prevent abuse, and document delivery or interaction where necessary for the service | Up to 12 months | No for necessary service evidence | Marketing-email measurement is treated separately and used only with the required legal basis |
5. Google Analytics 4 and Google Ads
Where enabled after consent, Google Analytics 4 helps us understand website and funnel use. Google Ads conversion tracking helps measure whether an advertisement led to an eligible action. Remarketing or advertising-personalization functions are used only where enabled and consented.
Google Consent Mode v2 receives choices from the Cookiebot interface and communicates the states for:
analytics_storage;ad_storage;ad_user_data; andad_personalization.
Consent Mode is not a substitute for the consent interface. The website must first collect the visitor's choice. Tags then adjust their behavior based on that choice. We do not intentionally send names, email addresses, claim documents, passport data, or other directly identifying Claim content to Google Analytics.
6. Plausible Analytics
Plausible Analytics is ordinarily configured as cookieless, aggregate analytics. In its standard privacy-focused configuration it does not place cookies or create a persistent visitor profile. A short-lived daily method may be used to avoid double counting without following a visitor across days or devices.
If the deployment is changed to use custom properties or another function involving personal data or browser storage, the relevant disclosure, legal basis, and consent configuration will be updated.
7. PostHog
PostHog may be used to understand product flows, diagnose errors, and improve the checker, account, or claim dashboard. In persistent mode, it can use cookies or local storage and therefore remains blocked until the required analytics consent is granted.
Where session recording is enabled, sensitive form fields and claim information should be excluded or masked. A cookieless mode may be used for limited aggregate measurement without persistent browser storage.
8. Authentication technologies
Clerk or another authentication provider may use essential cookies and tokens to sign users in, refresh a session, detect abuse, and protect accounts. Blocking these technologies can prevent account access because they are required to provide the requested authenticated service.
9. Payment and fraud-prevention technologies
Stripe, Worldline, or another payment provider may set essential cookies or device identifiers when a secure payment interface is loaded. These technologies help process the transaction, apply authentication, prevent fraud, and meet payment-network or regulatory requirements.
AirReclaim does not store full card details. Payment providers may process information under their own privacy information and may act independently for fraud, financial-crime, or regulatory purposes.
10. Third-party cookies
Some technologies are set from a third-party domain. The third party controls the technical cookie and may process data under its own terms. Browser restrictions can shorten retention or block a cookie entirely.
We select providers based on operational need and configure them to respect consent and data-minimization requirements. The current website scan and consent interface should be treated as the most specific record of technologies active at a given time.
11. Changing or withdrawing consent
You can change or withdraw your cookie consent at any time by reopening the cookie settings widget available on the website.
Withdrawing consent does not affect processing that occurred lawfully before withdrawal. After withdrawal, relevant optional tags are disabled for future use, although browser-stored cookies may remain until they expire or are deleted. You may delete them through browser settings.
12. Browser controls
Most browsers let you view, delete, or block cookies and clear local storage. Blocking all cookies can disrupt sign-in, payment, security, form, and consent functions. Browser “do not track” signals are handled where supported by the relevant provider and legal framework.
13. Updates
We update this Policy when providers, cookie names, retention, consent requirements, or the website configuration change. Cookiebot may perform recurring scans and update the website's cookie declaration. The effective date above identifies this version.
14. Contact
Privacy and cookie questions: privacy@airreclaim.com
Nova Group Sp. z o.o.
Żurawia 6/12 Lok. 745
00-503 Warszawa, Poland
