AirReclaim

Wybierz język

Dostępne języki

Więcej języków

Back to legal center

Legal and compliance

Cookies Policy

Cookies, local storage, consent categories, measurement providers, retention, and privacy controls.

Effective date
21 Jul 2026
Last updated
21 Jul 2026
Operator
Nova Group Sp. z o.o.
Scope
Poland / European Union
Document status
production ready

1. Scope

This Cookies Policy explains how Nova Group Sp. z o.o., operating AirReclaim, uses cookies, local storage, pixels, tags, consent signals, and similar technologies on airreclaim.com.

It should be read with the Privacy Policy. The live Cookiebot consent banner or cookie settings widget provides the most specific current list detected on the website.

2. What these technologies do

A cookie is a small text file stored by a browser. Local storage is browser storage that can hold identifiers or preferences. Pixels and tags can send information when a page, advertisement, or email is viewed or used. Consent Mode signals communicate your consent choices to Google services; the signals are settings rather than cookies themselves.

These technologies can be:

  • essential, to operate security, authentication, forms, sessions, payments, consent records, and requested services;
  • preference, to remember optional interface choices;
  • analytics, to measure use and improve the website;
  • marketing, to measure advertising, attribute conversions, create audiences, or personalize advertising;
  • authentication, to keep a user securely signed in; or
  • payment and security, to process a transaction and prevent fraud.

Essential technologies are used where necessary to provide a service you request, secure the website, remember your privacy choice, authenticate an account, or process a payment. They do not depend on optional cookie consent.

Analytics, marketing, and other non-essential technologies are activated only after the required consent has been obtained. In the European Economic Area, Switzerland, and the United Kingdom, our intended configuration is to set non-essential Google consent states to denied until the visitor makes a choice.

You may accept or reject categories independently where the consent interface offers those categories. Refusing optional technologies does not prevent use of the core compensation-checking and claim-management functions, although some measurement, personalization, or convenience features may be unavailable.

Names and duration can vary by browser, provider, domain, product configuration, and provider updates. A wildcard such as _ga_* means any cookie beginning with that pattern.

ProviderCookie, local-storage name, or patternCategoryPurposeTypical retentionConsent requiredNotes
AirReclaimairreclaim_session, session_*, or equivalent session identifierEssential / authenticationMaintain a secure website or account session and requested workflow stateSessionNoExact name depends on the deployed authentication and application configuration
AirReclaimcsrf_*, nonce, or equivalent security tokenEssential / securityPrevent cross-site request forgery, replay, and unauthorized form submissionSessionNoContains a security value rather than claim content
AirReclaimairreclaim_locale or equivalent preferencePreferenceRemember language or regional display choiceUp to 12 monthsYes where local law requiresMay instead be stored as an essential account preference after sign-in
Cookiebot CMP by UsercentricsCookieConsentEssential / consentStore the visitor's consent categories and evidence of the choice12 monthsNoNeeded to remember and demonstrate the privacy choice
Cookiebot CMP by UsercentricsCookieConsentBulkTicketEssential / consentShare a consent choice across configured related domains where that function is enabled12 monthsNoPresent only when cross-domain bulk consent is configured
Google Consent Mode v2analytics_storage, ad_storage, ad_user_data, ad_personalizationConsent signalsCommunicate granted or denied states to Google tagsTied to the CMP choice, typically up to 12 monthsNo separate consentThese are consent states, not browser cookies; they control tag behavior
Google Analytics 4_gaAnalyticsDistinguish browsers for aggregate website measurementUp to 24 monthsYesUsed only after analytics consent where required
Google Analytics 4_ga_*AnalyticsMaintain and count a Google Analytics session or property stateUp to 24 monthsYesThe suffix identifies the relevant measurement property
Google Analytics 4_gid where configuredAnalyticsDistinguish visitors for short-term measurement24 hoursYesMay not be present in all GA4 configurations
Google Analytics 4_gat* where configuredAnalyticsThrottle request rateAbout 1 minuteYesMay not be present in all GA4 configurations
Google Ads_gcl_auMarketing / measurementStore and measure advertising conversions90 daysYesUsed for conversion attribution
Google Ads_gcl_awMarketing / measurementStore Google Ads click and conversion information90 daysYesPresent where the relevant conversion-linking function is used
Google Ads_gcl_dcMarketing / measurementStore campaign and conversion information for supported advertising products90 daysYesPresent where the relevant advertising product is used
Google Ads and Google servicesgclid, wbraid, gbraid, or related click identifiers in cookies, storage, or URLsMarketing / measurementAttribute a visit or conversion to an advertisementUp to 90 daysYes for storage or advertising useA click identifier can also appear temporarily in a landing-page URL
Google advertising servicesIDE, DSID, NID, ANID, test_cookie, or related Google-domain cookiesMarketing / remarketingAdvertising delivery, frequency control, audience functions, conversion measurement, and testing cookie supportSession to 13 monthsYesThird-party names and availability vary by browser, region, Google product, and personalization setting
Plausible AnalyticsNo cookie in the standard cookieless configurationAnalyticsCount aggregate page views, sources, and short-lived daily unique visits without persistent visitor storageNo persistent browser retentionUsually no in strict cookieless modeIf optional custom or personal-data features change the configuration, the consent and disclosure position will be reassessed
PostHogph_*, posthog_*, and related local-storage identifiersAnalytics / product measurementMeasure product use, link events within a browser, and support product analyticsUp to 12 monthsYes in persistent modeNot set before consent in the consent-based configuration; strict cookieless mode does not store cookies or local-storage identifiers
PostHogSession-recording and feature identifiers where enabledAnalyticsSupport consented session analysis, diagnostics, feature measurement, and playback controlsSession to 12 monthsYesSession recording should be configured to mask sensitive fields and remain disabled without the required consent
Clerk__sessionEssential / authenticationCarry a short-lived session token for signed-in accessAbout 60 seconds, refreshed while the session remains activeNoRequired for account authentication
Clerk__client, clerk_*, or related authentication storageEssential / authenticationMaintain the authenticated client, refresh state, fraud protection, and sign-in continuitySession to 12 months depending on configurationNoExact names and life depend on the Clerk deployment and user session
Stripe__stripe_midEssential / payment securityDistinguish a browser for payment fraud preventionAbout 12 monthsNoSet where Stripe.js or a Stripe payment interface is used
Stripe__stripe_sidEssential / payment securitySupport payment-session fraud preventionAbout 30 minutesNoSet where Stripe.js or a Stripe payment interface is used
Stripem, pay_sid, __Host-LinkSession, or related Stripe security and authentication cookiesEssential / payment securitySecure payment, authentication, Link, and fraud-prevention functionsSession to 12 monthsNoNames depend on the Stripe payment function selected
WorldlineWorldline payment session cookiesEssential / paymentMaintain a secure checkout, authentication, transaction, and return flowSessionNoExact names vary by Worldline product and acquiring configuration
WorldlineWorldline fraud-prevention and device identifiersEssential / payment securityDetect fraud, protect transactions, comply with payment-network and regulatory requirementsSession to 13 monthsNo where strictly necessaryAny Worldline analytics or advertising technology not strictly necessary requires the applicable consent
Website security provider__cf_bm, _cfuvid, or equivalent security cookies where usedEssential / securityBot management, traffic integrity, rate control, and abuse prevention30 minutes to sessionNoPresent only where the configured security provider sets them
Email delivery providerSecure link or message identifiersEssential / service communicationDeliver claim communications, prevent abuse, and document delivery or interaction where necessary for the serviceUp to 12 monthsNo for necessary service evidenceMarketing-email measurement is treated separately and used only with the required legal basis

5. Google Analytics 4 and Google Ads

Where enabled after consent, Google Analytics 4 helps us understand website and funnel use. Google Ads conversion tracking helps measure whether an advertisement led to an eligible action. Remarketing or advertising-personalization functions are used only where enabled and consented.

Google Consent Mode v2 receives choices from the Cookiebot interface and communicates the states for:

  • analytics_storage;
  • ad_storage;
  • ad_user_data; and
  • ad_personalization.

Consent Mode is not a substitute for the consent interface. The website must first collect the visitor's choice. Tags then adjust their behavior based on that choice. We do not intentionally send names, email addresses, claim documents, passport data, or other directly identifying Claim content to Google Analytics.

6. Plausible Analytics

Plausible Analytics is ordinarily configured as cookieless, aggregate analytics. In its standard privacy-focused configuration it does not place cookies or create a persistent visitor profile. A short-lived daily method may be used to avoid double counting without following a visitor across days or devices.

If the deployment is changed to use custom properties or another function involving personal data or browser storage, the relevant disclosure, legal basis, and consent configuration will be updated.

7. PostHog

PostHog may be used to understand product flows, diagnose errors, and improve the checker, account, or claim dashboard. In persistent mode, it can use cookies or local storage and therefore remains blocked until the required analytics consent is granted.

Where session recording is enabled, sensitive form fields and claim information should be excluded or masked. A cookieless mode may be used for limited aggregate measurement without persistent browser storage.

8. Authentication technologies

Clerk or another authentication provider may use essential cookies and tokens to sign users in, refresh a session, detect abuse, and protect accounts. Blocking these technologies can prevent account access because they are required to provide the requested authenticated service.

9. Payment and fraud-prevention technologies

Stripe, Worldline, or another payment provider may set essential cookies or device identifiers when a secure payment interface is loaded. These technologies help process the transaction, apply authentication, prevent fraud, and meet payment-network or regulatory requirements.

AirReclaim does not store full card details. Payment providers may process information under their own privacy information and may act independently for fraud, financial-crime, or regulatory purposes.

10. Third-party cookies

Some technologies are set from a third-party domain. The third party controls the technical cookie and may process data under its own terms. Browser restrictions can shorten retention or block a cookie entirely.

We select providers based on operational need and configure them to respect consent and data-minimization requirements. The current website scan and consent interface should be treated as the most specific record of technologies active at a given time.

You can change or withdraw your cookie consent at any time by reopening the cookie settings widget available on the website.

Withdrawing consent does not affect processing that occurred lawfully before withdrawal. After withdrawal, relevant optional tags are disabled for future use, although browser-stored cookies may remain until they expire or are deleted. You may delete them through browser settings.

12. Browser controls

Most browsers let you view, delete, or block cookies and clear local storage. Blocking all cookies can disrupt sign-in, payment, security, form, and consent functions. Browser “do not track” signals are handled where supported by the relevant provider and legal framework.

13. Updates

We update this Policy when providers, cookie names, retention, consent requirements, or the website configuration change. Cookiebot may perform recurring scans and update the website's cookie declaration. The effective date above identifies this version.

14. Contact

Privacy and cookie questions: privacy@airreclaim.com

Nova Group Sp. z o.o.
Żurawia 6/12 Lok. 745
00-503 Warszawa, Poland