Legal
Cookie Policy
Last updated: September 24, 2026
1. About this policy
Cookies are small text files stored on your device by a website. LocalStorage and similar APIs persist small amounts of data directly in your browser. Together, these mechanisms help a site remember your preferences, keep you signed in, and, where allowed, measure usage or run campaigns.
TERTIQ uses these mechanisms conservatively. No third-party analytics provider, advertising pixel, or marketing tracker is currently active on our public website or in the application. The categories below describe the storage in use today and the optional categories supported by the consent architecture.
2. Categories
TERTIQ recognizes three categories of storage:
- Necessary. Always on. Required for authentication, session integrity, security, and remembering choices like your consent itself. Cannot be disabled without breaking core site functions.
- Analytics. Off by default. Intended for privacy-friendly, first-party or aggregated usage statistics. No analytics scripts, SDKs, or beacons are currently enabled in production.
- Marketing. Off by default. Intended for promotional attribution on marketing pages. No advertising pixels or conversion trackers are currently used.
You can change or withdraw your consent at any time using the Manage cookie preferences control below, or the consent banner when it appears.
3. Items currently in use
| Name | Purpose | Category | Expiry |
|---|---|---|---|
next-auth.session-token Cookie | Signed JWT session cookie issued by the authentication layer to keep authenticated users signed in to the TERTIQ application. | Necessary | Session, or 30 days from sign-in as configured. |
next-auth.csrf-token Cookie | Double-submit CSRF protection token used during sign-in flows and form submissions to prevent cross-site request forgery. | Necessary | Session / short-lived. |
next-auth.callback-url Cookie | Remembers the post-sign-in destination during an authentication redirect so you land on the page you requested. | Necessary | Session / short-lived. |
VERIFICATION_REQUEST Cookie | Server-side record (not a browser cookie) issued when a magic link is sent, bound to the identifier. Listed here for completeness because a matching token is consumed by sign-in. | Necessary | Up to 24h after issuance. |
tertiq.cookieConsent.v1 localStorage | localStorage record storing your cookie preferences, the timestamp they were saved at, and the schema version. Read client-side to decide whether to re-show the consent banner and which optional categories to enable. | Necessary (localStorage) | Persistent on device until cleared or reset via Cookie Preferences. |
Cookie names are illustrative; the authentication layer may prefix names based on deployment configuration and whether the site uses secure cookies under HTTPS.
4. Optional categories
The Analytics and Marketing categories are exposed in the consent manager today so that enabling them later does not require a second immediate consent prompt. As of the last update above, enabling either category does not activate any network request, tracker, SDK, or third-party script in the browser.
- Analytics category. Aggregated, privacy-friendly product-usage statistics. If and when enabled, any new scripts or destinations will be identified by updated entries in this policy and, where applicable, a corresponding subprocessor update.
- Marketing category. Attribution for promotional channels on the marketing website. If and when enabled, any new trackers, destinations, and retention windows will be listed by updated entries in this policy.
A material change to the set of non-necessary items will re-trigger the consent banner on your next visit, and this policy will be updated with the new last-updated date.
5. Managing preferences
You can review or change your preferences at any time using the Manage cookie preferences control below. You can also reset them by clearing storage for the www.tertiq.com origin in your browser controls.
Disabling or deleting necessary cookies is likely to break authentication, the consent manager itself, or other essential features.
6. Questions
If you have a question about this policy, a suspected discrepancy, or a request to exercise your rights with respect to personal data, please contact the principal contact documented in the Privacy Policy, or your workspace account team. We handle cookie and privacy enquiries as part of standard account correspondence.
Preference manager
Review or change your cookie categories at any time. The preference manager lets you enable or disable optional analytics and marketing categories individually.
