Last updated: 24 July 2026
Cookie policy
This cookie policy explains which cookies and similar technologies Kadova uses on the marketing website, the signed-in platform and customer hosted webshops. We process optional analytics and marketing only after your explicit consent.
1. Who is responsible?
Responsibility depends on context:
- Kadova (marketing site, signup, signed-in platform): Kadova is controller for analytics and marketing consent of platform users and anonymous visitors
- Customer hosted webshop: the customer organisation is controller for consumers; Kadova acts as processor. Optional tenant analytics runs only after consent in that shop
- Shop widgets (iframe): no Kadova cookie banner; marketing email opt-in only via the customer checkout checkbox
2. Strictly necessary
These technologies are required for the service and do not require consent:
- Session and authentication cookies (httpOnly) for login and tenant selection
- Language and interface preferences
- Security, CSRF protection and rate limiting
- Checkout and payment cookies from Stripe/Mollie (contractual)
3. Analytics (opt-in)
Google Analytics 4 on marketing pages measures only after consent via the cookie banner (Consent Mode v2: denied by default). We do not load GA4 in the dashboard. Hosted shops may optionally configure their own GA4; that runs only after shop visitor consent and under tenant responsibility.
- Purpose: insight into website visits and conversion on marketing/signup
- Legal basis: consent (GDPR art. 6(1)(a))
- Proof: ConsentPreference/ConsentEvent on the server; local preference in scoped storage
- Expiry: 13 months without reconfirmation
4. Marketing email (opt-in)
Marketing email to platform users requires explicit consent in My data or notification preferences — never via the cookie banner. Consumer marketing in shops uses a separate checkout checkbox (off by default).
- No implicit opt-in for existing customers
- Withdraw via My data, notification settings or one-click unsubscribe
- Marketing opt-out proof: retained for 10 years
5. Hosted webshops
On /shop/* and customer custom domains we do not show the Kadova marketing banner. With CONSENT_V2_SHOP_UI a tenant-branded banner may appear when the tenant has enabled optional analytics. Consumer marketing email always follows checkout opt-in under shop responsibility.
- Consent scope per tenant: isolated browser storage shop:{clientId}
- Platform GA4 is not loaded on shop routes
- Widgets: no Kadova tracking; checkout marketing checkbox only if offered
6. Browser storage
Besides cookies we use localStorage for consent preferences:
- cookie_consent:kadova-site — marketing website analytics choice
- cookie_consent:shop:{tenantId} — per-shop analytics choice
- kadova_visitor_id — opaque UUID for anonymous consent sync (no fingerprinting)
7. Third parties
Optional tags load only after consent. See also /legal/subprocessors.
- Google Analytics 4 — analytics (consent-gated)
- Stripe / Mollie — payment (necessary at checkout)
- Sentry — error monitoring (legitimate interest, minimised; no consent banner)
8. Changing your choices
You can withdraw or adjust consent at any time:
- Marketing website: reopen the cookie banner via /cookies or clear browser data
- Signed in: Settings → My data
- Shop: cookie settings in the shop footer (when tenant analytics is active)
9. Contact
Questions about cookies or consent: privacy@kadova.nl. See also /privacy for the full privacy policy.
Manage cookie preferences
Adjust your analytics choice for the Kadova marketing website. Signed-in users manage marketing and analytics in My data.