Cookie Policy
Last updated: 21 August 2026
Effective date: 21 August 2026
This Policy lists everything OneTap.Work stores on your device or reads from it, and what you can do about each item. It complements our Privacy Policy, which explains what we do with personal data more generally.
"Cookies" in this Policy means cookies and the technologies that work like them — browser local storage, scripts, tags and identifiers.
1. The short version
- Everything strictly necessary to sign you in and remember your choices is always active.
- Google Analytics and any marketing tags stay switched off until you allow them.
- One analytics tool, Umami, runs without a consent gate. It sets no cookies and cannot identify you by name, but it does recognise a returning browser. Section 4 explains why, and how to object.
- We use no advertising cookies of our own and we do not sell data to advertisers.
2. What we store on your device
Strictly necessary — always active
| Name | Type | Purpose | Expires |
|---|---|---|---|
| sessionId | Cookie (HTTP-only, secure) | Keeps you signed in. Cannot be read by scripts | 30 days |
| __locale__ | Cookie | Remembers your interface language | On clearing |
| cookieConsent | Local storage | Remembers the choice you made in the banner, so we do not ask again | Until cleared |
Without these the Service cannot work, so they do not require consent. If you block them, you will not be able to sign in.
Functional — your interface preferences
Local storage entries that remember how you like the app: your list or grid view, whether you hide jobs you have already seen, and which one-off prompts you have dismissed. They stay in your browser, are never sent to anyone, and clearing them only resets the interface. Because they exist solely to deliver the interface you asked for, they are written whether or not you allow the "Functional" category.
What the Functional toggle in the banner actually controls is the functionality_storage signal we pass to Google's tags — see section 3. Turning it off does not remove your interface preferences from your own browser; you can clear those yourself as described in section 6.
Analytics and measurement
| What | Set by | Purpose | Consent |
|---|---|---|---|
| Google Analytics cookies (_ga, _ga_*) | Google | Measures visits, pages and traffic sources | Required — blocked until you allow "Analytics" |
| Google Tag Manager | Google | Loads the tags above according to your choice. Sets no cookies itself | Container loads; the tags inside it respect your choice |
| Umami events | Us, self-hosted | Measures which features are used | Not gated — see section 4 |
| signupAttribution | Us, local storage | If you arrive from a campaign link, stores the campaign parameters (utm_*, gclid, fbclid), the referring site and the landing page for up to 90 days, so a later registration can be attributed to that campaign | Required — written only once you allow “Marketing”, and deleted if you withdraw it |
Error monitoring
We use Sentry to be told when something breaks. It is configured for errors only — no session recording and no behaviour tracking — and it sets no cookies. Reports sent from our servers include the IP address of the failing request. This runs without a consent gate because we cannot operate a service we cannot see failing.
3. Google Consent Mode
Google's tags on our site run under Consent Mode v2. Before you answer the banner, every consent signal is set to denied and no analytics or advertising cookies are written. When you choose, your answer is passed to the tags, which adjust accordingly. If you withdraw consent later, the signals flip back to denied.
4. Umami, and why it is not behind the banner
Umami is an analytics tool we run on our own infrastructure. We use it to answer questions like which features people use and where they get stuck.
- It sets no cookies and stores no name, e-mail address or account details.
- It recognises a returning browser using a hash of your IP address and browser details that is regenerated every day. It cannot follow you across days, and it cannot be reversed into an IP address.
- Your account identifier is attached to these events only if you have consented to analytics. Without that consent the data is pseudonymous.
We rely on legitimate interests rather than consent because analytics gated behind a banner only measures the people who accept banners, which is not a representative picture of how the Service is used. We consider the impact on you to be minimal given the safeguards above.
If you disagree, you can object — write to support@onetap.work — or block the script in your browser, as described in section 6.
5. Changing your mind
When you first visit, a banner lets you accept everything, refuse everything, or open Customize and decide per category. Four categories are shown:
- Essential — always on, cannot be switched off.
- Functional — the
functionality_storagesignal sent to Google's tags. - Analytics — Google Analytics.
- Marketing — advertising and remarketing tags.
You can change or withdraw your choice at any time:
- "Cookie settings" in the site footer, or
- Settings → Cookies when you are signed in.
Withdrawing consent stops the relevant tags from loading. Cookies already written by a third party may remain in your browser until they expire or you delete them — section 6 explains how.
Your choice is stored in your own browser and nowhere else, so it applies to that browser only, and clearing your browser data means we will ask you again.
6. Controlling storage in your browser
Every mainstream browser lets you view, block and delete cookies and local storage, usually under Privacy or Site settings. You can also block third-party cookies generally, browse in a private window, or use a content blocker — which will stop analytics scripts, including Umami, from loading at all.
Blocking strictly necessary items will prevent you from signing in. Blocking anything else only reduces what we can measure.
7. Changes to this Policy
If we add a provider or a purpose, we will update this Policy and the tables above. Where a change is material we will ask you to review your choices again.
8. Contact
JDG Sviatoslav Mysiv
al. Jana Pawła II 3b/137, 80-462 Gdańsk, Poland
NIP: 5842863282
support@onetap.work
This Policy is published in Polish and English. For users in Poland the Polish version prevails.