Cookie Policy
Effective: April 1, 2026 · Version 1.0
This Cookie Policy explains how TumaFlow uses cookies and similar technologies when you visit our website or use our platform. We are committed to being transparent about the technologies we use and giving you control over them.
1. What Are Cookies?
Cookies are small text files that a website places on your device (computer, tablet, or phone) when you visit. They are widely used to make websites work efficiently, to remember your preferences, and to provide information to website owners about how their site is used.
Similar technologies include localStorage, sessionStorage, and pixel tags. Where we refer to "cookies" in this policy, we mean all of these technologies.
2. Categories of Cookies We Use
2.1 Strictly Necessary Cookies
These cookies are essential for the website to function and cannot be switched off. They are typically set in response to actions you take, such as logging in or filling in forms.
| Cookie Name | Purpose | Duration |
|---|---|---|
| auth_token | Stores your encrypted login session (JWT) as an httpOnly cookie. Required for authentication. | 24 hours |
| __Host-next-auth | Next.js session security token. | Session |
2.2 Functional Cookies
These cookies enable enhanced functionality and personalisation. They may be set by us or by third-party providers whose services we have added to our pages.
| Cookie Name | Purpose | Duration |
|---|---|---|
| tumaflow_theme | Remembers your UI theme preference (light/dark). | 1 year |
| tumaflow_sidebar | Remembers dashboard sidebar collapsed/expanded state. | 1 year |
2.3 Analytics Cookies
These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. All information these cookies collect is aggregated and therefore anonymous. If you do not allow these cookies, we will not know when you have visited our site.
| Cookie / Tool | Provider | Purpose | Duration |
|---|---|---|---|
| _ga, _ga_* | Google Analytics | Distinguishes users; measures site traffic and behaviour. | 2 years |
| _gid | Google Analytics | Distinguishes users within a 24-hour window. | 24 hours |
| ph_* | PostHog (self-hosted) | Product analytics — feature usage and funnel tracking. | 1 year |
2.4 Marketing Cookies
We currently do not use marketing or advertising cookies on the TumaFlow platform. We will update this policy and request your consent before doing so.
3. Third-Party Cookies
Some cookies are set by third parties on our pages. These third parties have their own privacy and cookie policies. Third-party cookies currently include:
- Google Analytics — analytics and performance monitoring (Google Privacy Policy)
- Stripe — fraud prevention on checkout pages (Stripe Privacy Policy)
4. How to Control Cookies
4.1 Browser Settings
You can control and/or delete cookies at any time using your browser settings. Most browsers allow you to:
- View and delete cookies already stored on your device
- Block cookies from specific websites
- Block all third-party cookies
- Block all cookies from all websites
- Delete all cookies when you close your browser
Browser-specific instructions: Chrome · Firefox · Safari · Edge
4.2 Opt-Out of Analytics
To opt out of Google Analytics tracking across all websites, install the Google Analytics Opt-out Browser Add-on.
4.3 Impact of Disabling Cookies
Blocking strictly necessary cookies will prevent you from logging in and using the dashboard. Blocking functional cookies means your preferences will not be saved between sessions. Blocking analytics cookies has no impact on platform functionality.
5. Updates to This Policy
We may update this Cookie Policy from time to time to reflect changes in technology or law. The "Effective Date" at the top of this page will be updated accordingly.
6. Contact Us
If you have questions about our use of cookies, please contact us at privacy@tumaflow.io.