Cookie Policy
How GoSavis uses cookies and similar technologies, and how you can control them
Strictly necessary storage
We use the following first-party cookies where they are necessary to provide a feature you requested, protect the service or remember your privacy choice:
auth: Signed-in session. It is HttpOnly, Secure in deployed HTTPS environments and normally lasts for the browser session, 7 days or 90 days when you choose to be remembered
refresh: Renews a signed-in session. It is HttpOnly and lasts for the browser session, 30 days or 90 days when you choose to be remembered
gs_csrf: Protects signed-in form submissions against cross-site request forgery. It lasts for 7 days
did: An opaque device identifier used for device recognition, security alerts and multi-factor authentication trust. It lasts for up to 1 year
mainstayReturn: Remembers the GoSavis Business page to return to after a cross-surface journey. It lasts for 1 day
gosavis_gate: Records access to a restricted pre-launch or preview environment when that gate is enabled. It lasts for 30 days and is not used on an ungated public environment
gs_consent: Stores your external-media and analytics choices across GoSavis subdomains. It lasts for 180 days, after which we ask again
Preferences, drafts and offline storage
When you choose a theme, language, region, layout or similar setting, we use first-party browser storage to remember that choice. Session storage also protects work in progress, such as form, search and checkout state, from being lost during a journey. These records use descriptive GoSavis keys, generally remain until you change the setting or clear browser data, and are not used for advertising or cross-site profiling.
The application may also use IndexedDB for pending media uploads and Cache Storage for installed-app assets. These stores support the upload or offline feature you requested. You can remove them by clearing GoSavis site data in your browser. Signing out clears authentication state but does not automatically reset preferences you asked the device to remember.
Optional categories
External media
Videos from YouTube, Vimeo and TikTok remain behind a GoSavis placeholder until you allow External media. Loading one lets that provider receive your IP address, browser information, the page containing the media and any cookies or identifiers it controls. YouTube embeds use its privacy-enhanced domain, but the provider may still process technical information when the video loads.
Analytics
If Google Analytics is configured for the environment, it loads only after you allow Analytics. Advertising storage and personalisation remain disabled. Google Analytics may set _ga and a property-specific _ga cookie for up to 2 years to distinguish visits. We do not describe this data as anonymous, and we do not use your analytics choice as consent for advertising.
Services loaded when you request a feature
Some providers are contacted only when you request the corresponding feature. Google or Apple is contacted when you choose its sign-in button. Stripe is contacted when you open an online card-payment or payout-onboarding component. Cloudflare Turnstile is contacted when a protected form requires a security challenge. These services may use their own cookies or local storage to complete the requested authentication, payment or security operation.
Map pages and location search can contact Mapbox, OpenStreetMap tile services or Nominatim when you open a map, search for a place or ask the browser to use your location. Those providers receive the technical information necessary to return the requested map or result. The Privacy Policy explains the related personal-data processing.
Managing and withdrawing your choice
You can change your choice at any time using Cookie preferences. The controls use the same category names as this policy: Strictly necessary, External media and Analytics. The available actions are Accept all, Reject non-essential and Choose preferences.
Withdrawing consent prevents new optional provider loads. For analytics, GoSavis also sends a denied consent update and removes analytics cookies it can identify. Content already loaded from an external provider may require a page refresh to disappear. Browser controls can block or clear all site data, but blocking strictly necessary storage will prevent sign-in, bookings and other secured features from working.
For more detail about personal information processed through these technologies, read our Privacy Policy.
Changes to this policy
We update this policy and the consent schema when the product or provider list changes. If we add a new optional purpose, provider or technology that is not covered by your existing choice, we will ask you again rather than treating an earlier choice as advance consent.