Cookie Policy
How Ottili ONE uses cookies and similar technologies.
Ottili ONE uses cookies and similar technologies to operate the platform, remember your preferences and improve your experience. This page lists the actual technologies we use, grouped by purpose, and explains what each one does.
Essential
Always activeRequired for core functionality. Cannot be disabled.
- Ottili session & authOttili ONE (first-party)
Keeps you signed in to Ottili ONE, preserves the active company/workspace context, and secures OAuth state and CSRF protection.
- Storage:
- cookie
- Hosts:
- ottili.one
- dashboard.ottili.one
- Data collected:
- A secure authentication token and the active company/workspace identifier. No analytics or marketing data.
- Retention:
- Session, or until you sign out.
- Consent decision storageOttili ONE (first-party)
Stores your cookie consent decision (per category), the schema version, and the timestamp so your choice is honored across pages.
- Storage:
- localStorage
- Data collected:
- Your consent choice per category (essential/analytics/marketing/functional), schema version and timestamp.
- Retention:
- Until you change or withdraw consent, or clear site data.
- Consent audit logOttili ONE (first-party)
Keeps a local history of your consent changes (category, action, timestamp) for accountability and to prove lawful consent.
- Storage:
- localStorage
- Data collected:
- A local record of each consent change: category, action (given/withdrawn/modified) and timestamp.
- Retention:
- Until you clear site data.
Analytics
OptionalHelp us improve our service by analyzing usage patterns.
- Google Analytics 4Third-party
Measures how visitors use the public website so we can improve content and performance. Loaded via Google Tag Manager.
- Storage:
- cookie
- script
- Hosts:
- www.googletagmanager.com
- www.google-analytics.com
- Data collected:
- Page views, session duration, approximate geographic region (country), device and browser type, referral source and interaction events. Uses first-party GA cookies (_ga, _ga_*) for identification.
- Retention:
- GA cookies persist up to 24 months (project-configurable).
- Plausible AnalyticsThird-party
Privacy-friendly, cookie-free website analytics used as an alternative to Google Analytics.
- Storage:
- script
- Hosts:
- plausible.io
- Data collected:
- Aggregated, anonymized page views and custom events. No cookies are set and no personal data or persistent identifiers are stored.
- Retention:
- No persistent cookie; aggregated data retained per the Plausible project retention setting (default 24 months).
- Custom analytics endpointThird-party
Optional self-hosted or custom analytics endpoint, used only when NEXT_PUBLIC_ANALYTICS_PROVIDER=custom is configured.
- Storage:
- script
- Data collected:
- Depends on the configured endpoint. Only sent after analytics consent; the payload contains page path, page title and anonymized interaction events.
- Retention:
- Depends on the endpoint configuration.
Marketing
OptionalUsed for advertising, remarketing, and social media integration.
No third-party marketing technologies are deployed.
Functional
OptionalEnhance user experience with preferences and non-essential features.
- Language preferenceOttili ONE (first-party)
Remembers your selected website language (English / German) so it is applied on return visits.
- Storage:
- cookie
- Data collected:
- Your selected locale (en or de).
- Retention:
- Until you change language or clear site data.
This inventory reflects the technologies deployed on the Ottili ONE public website (policy version 1.0.0, schema 1.0.0).
For questions about cookies or to request preference changes, contact support@ottili.one.Version 2026.07 • Effective: July 1, 2026
This legal document is published but pending final legal verification. Treat it as provisional until verified.
Governed under T-Q1-WEB-0199: added effective date, status and approval governance to the cookie policy.
