Naar de inhoud

Cookie Notice

Last updated: 2026-09-29 · Version 1.9

This Cookie Notice explains how the SGTM.space website operated by BEO TECHNOLOGY SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ uses cookies, similar technologies and consent-aware server-to-server measurement. It covers sgtm.space itself; cookies placed through the SGTM.space product on your own websites are addressed separately in section 6.

1. What cookies are

Cookies are small text files stored on your device. First-party cookies are written for the website you visit; third-party cookies are written by another provider. Session cookies expire after a session, while persistent cookies remain for a stated period. Local storage and cookieless measurement signals are similar technologies for the purposes of this notice.

2. How measurement works

We use CookieTip as our consent-management platform. In the European Economic Area, the United Kingdom and Switzerland, and whenever we cannot tell where you are, optional analytics and advertising storage starts denied until you choose in the banner. Everywhere else it starts enabled and no banner is shown; you can switch any category off in Cookie settings at any time, and if your browser sends a Global Privacy Control signal on your first visit, when we set that default, the advertisement category starts off (section 8). We tell where you are only from the country Cloudflare assigns to your IP address. CookieTip, our own consent platform, records your category choices and Google tags receive the corresponding Advanced Consent Mode update. When analytics consent is granted, browser events travel through our first-party web loader and server-side Google Tag Manager container to Google Analytics 4, and Cloudflare Web Analytics measures visits and page load performance without setting cookies. When advertising consent is also granted, the Google tag sends page views to Google Ads with its cookies, so that Google Ads can measure our ads and use the visit for remarketing, and eligible conversion data may be made available to Google Ads; our own Google Ads conversion tags are currently paused. Before you choose and after you refuse, Google receives only the cookieless pings described in section 4. With advertising consent, page views and conversions are also sent to OpenAI Ads, from the OpenAI pixel in your browser and from our server-side container, so that OpenAI can measure our ads in ChatGPT.

Purchase, account registration, container creation, DNS verification and the first start of a container's tagging server are recorded by our application and sent directly to our server-side Google Tag Manager container instead of the browser data layer. The application independently checks the CookieTip state saved for your account both when the event happens and immediately before a queued send. Withdrawal before delivery blocks that category permanently; skipped events are not replayed later.

3. Strictly necessary storage

Cookie / storageProviderPurposeDuration
Session cookie sgtmspace-sessionSGTM.spaceMaintains the authenticated session; HttpOnly, SameSite=Lax7 days, renewed with each request
XSRF-TOKENSGTM.spaceProtects forms and consent synchronization against CSRF7 days, renewed with each request
remember_web_*SGTM.spaceKeeps you signed in after the session expires; set when you tick "Remember me" at sign-in, and always when you sign in with Google or GitHub; HttpOnly. Deleted when you sign out400 days
sgtm-theme (localStorage entry)SGTM.spaceRemembers the light or dark app theme you chose; written only when you choose one, and choosing the system theme removes itNo expiry date, kept until you change the theme or clear the site's data
cookietip-consent (cookie and localStorage entry)CookieTip / SGTM.space first partyStores consent ID and the necessary, functional, analytics, performance and advertisement choices, in a cookie and in a localStorage entry of the same name; outside the EEA, the UK and Switzerland, where we can tell your location, we set the cookie on your first visit with every category enabled (advertisement off under Global Privacy Control)Cookie: 365 days; localStorage entry: no expiry date, kept until it is overwritten or you clear the site's data
Cloudflare Turnstile storage (for example cf_*)CloudflareBot and abuse protection during registration and in the public scannerAccording to Cloudflare settings

4. Optional analytics and advertising storage

In the EEA, the UK and Switzerland, and whenever we cannot tell where you are, storage in these categories is placed only on the basis of your consent: until you give it, none of it is set on your device. Elsewhere it is set from your first visit unless you switch it off in Cookie settings. When you withdraw consent or switch a category off, it stops being set.

Before you make a choice, and after you refuse, the Google tag still sends cookieless measurement and consent pings (Google Advanced Consent Mode): to Google Analytics through our tagging domain ssl.sgtm.space, and to Google Ads directly to Google (for example www.google.com) and through our Google tag gateway path on sgtm.space. They store no cookie or identifier on your device and carry the page address (which may include campaign parameters such as gclid or utm_*), the page title, your consent state, basic browser and device information (screen size, language, user agent) and your IP address as Google sees it. Google uses them for aggregated and modelled measurement. Without advertising consent, Google may also pass ad-click identifiers (such as gclid) from page to page in the page address instead of storing them in cookies. No Google cookie is set until you consent.

The list below is generated by scanning this website, so it reflects what is genuinely in use rather than a description we maintain by hand. It is the authoritative inventory for this notice.

Direct server events do not set a new browser cookie. With analytics consent they may carry the GA client/session ID or a stable pseudonymous client ID, account ID, event name, time and limited product context (for example container UUID, plan, region or DNS record). Only with advertisement consent may they also carry one Google click ID, the OpenAI click and browser identifiers (__oppref, __obref), the IP address and user agent of the request, SHA-256 hashes of the account e-mail normalized for Google and for OpenAI, and a pseudonymous advertising ID derived from the account ID. Otherwise ad_user_data and ad_personalization are sent as DENIED.

5. Providers and transfers

CookieTip, our own consent platform, receives consent choices, consent ID, timestamps, IP address, user agent and anti-bot interaction signals, including mouse movement samples, to operate the consent interface, and a list of the scripts and cookies the website uses, from which the list in section 4 is built. Google receives the measurement and consent data described above through our server-side Google Tag Manager endpoint and, for Google Ads, directly and through our Google tag gateway. The Google tag we use is shared with other websites and services of BEO Technology sp. z o.o., so the same Google measurement and advertising data, under the same consent rules and including the cookieless pings, is also made available to the other Google Analytics and Google Ads accounts of BEO Technology sp. z o.o., which we use to measure our wider marketing. With analytics consent only, your browser loads the Cloudflare Web Analytics script from static.cloudflareinsights.com; it sets no cookie, and Cloudflare receives the page address, the referring page, your IP address and user agent, and page load timings. Once loaded, it keeps reporting the pages you open within the site until the next full page load, even if you withdraw consent in the meantime; browser ad blockers often stop it altogether. With advertisement consent only, the Affonso affiliate pixel stores the referring partner in the affonso_referral and affonso_data cookies for 30 days; Affonso receives the visit, and your e-mail address and account ID when you register. The referral identifier is then stored with your account, and every later payment Dodo Payments reports for your account, or for an organization your account created, carries it so the partner's commission can be calculated, also after you withdraw consent (see the Privacy Policy). An account we assign to a partner at the partner's request is reported to Affonso as that partner's lead whatever this consent; this stores no cookie. For partners who have joined the programme, the Affiliate page in the app shows a dashboard embedded from affonso.io, and the partner portal at partner.sgtm.space is run by Affonso; in the dashboard and the portal Affonso may use its own cookies and browser storage needed for them to work, as described in Affonso's privacy policy. With advertisement consent only, the OpenAI Ads pixel, loaded from OpenAI's servers, stores an ad-click identifier in the __oppref cookie for 30 days and a random browser identifier in the __obref cookie for 365 days, both on the sgtm.space domain. OpenAI receives the pages you view and, when you register, create a container, verify DNS or buy a plan, that event, sent from your browser and from our server with a shared event ID so each counts once (a purchase from our server only). Each event carries these identifiers and your IP address and user agent and, once you are signed in, a SHA-256 hash of your account e-mail and a pseudonymous advertising ID derived from your account ID; a purchase also carries the plan and amount. The pixel also uses OpenAI's automatic advanced matching: it detects customer information you enter in forms and other recognizable places on our website, such as your e-mail address, phone number, name and address (for example in the registration, login and billing details forms), normalizes it and hashes it with SHA-256 in your browser, and sends only these hashes with the events; the raw values are not sent. OpenAI uses this data as an independent controller to measure and improve its ads, under its own privacy policy. Withdrawing advertisement consent stops new OpenAI events; the two cookies are not deleted and expire at the end of their periods. The entities, their roles, locations and the safeguards for transfers outside the EEA are listed in section 6 of the Privacy Policy. Providers' policies: CookieTip, Google (and how Google uses information from partner sites), Cloudflare, Affonso and OpenAI.

6. Product cookies on customer domains

Separately, the Service may place cookies on your websites when you enable product add-ons. Cookie Extender re-issues the analytics and advertising cookies your own tags already set on your domain, with a lifetime capped at each vendor's own lifetime. It sets no identifier of its own. You are the controller for those cookies and must provide your own notice, lawful basis and consent mechanism. We act as processor under the DPA.

Strictly necessary storage is used to provide a secure website and requested account functions (GDPR Art. 6(1)(b) and (f)) and does not require consent under applicable ePrivacy rules. Analytics and advertising cookies and identifiers, and the measurement that uses them, including the corresponding direct server event routes, rely on your consent (GDPR Art. 6(1)(a)). The cookieless Google pings described in section 4, including ad-click identifiers passed in the page address, are the exception: the pings store no cookie or identifier on your device, and we send both on the basis of our legitimate interest in aggregated measurement of our website and ads (GDPR Art. 6(1)(f)). Outside the EEA, the United Kingdom and Switzerland, when we can tell your location, these categories are enabled by default and you can object to them at any time in Cookie settings. Accepting our legal documents at registration confirms receipt of those documents and is not consent to optional measurement.

8. Managing and withdrawing consent

You can open Cookie settings from every public, authentication and customer-app layout, or right here, and change or withdraw any optional category at any time. Withdrawing is as easy as giving consent and stops new measurement in the withdrawn category straight away, with two exceptions: an already-loaded Cloudflare Web Analytics script keeps reporting the pages you open within the site until the next full page load (section 5), and the Google tag goes back to the cookieless pings described in section 4. The update is also copied to the authenticated account, so queued server events in that category are not sent. Cookies already stored may remain in your browser until they expire at the end of the duration shown for them, unless you delete them yourself. A partner referral already stored with your account, or with the account that created your organization, keeps crediting that partner on later purchases (section 5). Withdrawal does not affect processing already lawfully performed. Blocking strictly necessary cookies in your browser may prevent login or use of the dashboard.

If you are in the United States, the Do Not Sell or Share My Personal Information link in the footer opens the same settings; refusing the advertisement category is how you opt out of any sharing for advertising purposes. Outside the EEA, the UK and Switzerland, where we can tell your location, we also honour the Global Privacy Control signal: if your browser sends it when we set your default choice, the advertisement category starts off. In the EEA, the UK and Switzerland, and whenever we cannot tell where you are, every optional category already starts off until you choose in the banner, so the signal does not change anything there.

You can also contact us at [email protected].

9. Retention

Consent history is kept for the life of the account and removed with it. Encrypted queued direct-event details are cleared after a terminal delivery or skip, and delivery metadata is deleted after 90 days. Google, Cloudflare, OpenAI and CookieTip apply their own retention periods to data they receive, and so does Affonso; the cookie durations above describe storage in the browser.

10. Changes and contact

We may update this notice; its version and effective date appear at the top of the page. Questions can be sent to BEO Technology sp. z o.o. at [email protected]. See also our Privacy Policy.