Cookie Policy

Last Updated: 28.01.2026

This Cookie Policy explains how Sonar Seed ("we," "us," or "our") uses cookies and similar tracking technologies in the Sonar Seed application (the "App"), including both the merchant dashboard and the influencer portal.

1. What Are Cookies?

Cookies are small text files that are placed on your device (computer, smartphone, tablet) when you visit a website or use a web application. Cookies allow the website to recognize your device and remember certain information about your visit.

Types of cookies we use:

  • Session Cookies: Temporary cookies that expire when you close your browser
  • Persistent Cookies: Cookies that remain on your device for a set period or until you delete them

2. How We Use Cookies

We use cookies for the following purposes:

2.1 Essential Cookies (Strictly Necessary)

These cookies are essential for the App to function properly and cannot be disabled without severely impairing your experience.

Cookie NamePurposeDurationType
sb-access-tokenSupabase authentication token for merchant/influencer loginSessionFirst-party
sb-refresh-tokenAllows automatic re-authentication without re-login30 daysFirst-party
__Secure-next-auth.session-tokenVercel/Next.js session managementSessionFirst-party
__Host-next-auth.csrf-tokenCSRF protection for form submissionsSessionFirst-party

Legal Basis: These cookies are necessary for contract performance (GDPR Art. 6(1)(b)) and do not require consent.

2.2 Analytics Cookies (Optional)

We use analytics cookies to understand how users interact with the App and identify areas for improvement. You can opt out of analytics cookies using the cookie preferences tool (see Section 5 below).

Cookie NameProviderPurposeDurationType
_gaGoogle Analytics 4Distinguishes unique users2 yearsThird-party
_ga_<container-id>Google Analytics 4Stores session state and campaign data2 yearsThird-party
_gidGoogle Analytics 4Distinguishes unique users (short-term)24 hoursThird-party

What we track:

  • Page views and navigation paths
  • Feature usage (e.g., which buttons are clicked)
  • Time spent on pages
  • Device type, browser, and screen resolution
  • Aggregated performance metrics

What we do NOT track:

  • Personal identifiers (email, name, address)
  • Keystrokes or form inputs
  • Mouse movements or scrolling behavior (no session replay)

Data Sharing: Analytics data is processed by Google LLC in the United States. We have a Data Processing Agreement with Google and have enabled IP anonymization.

Google Analytics Opt-Out: You can install the Google Analytics Opt-Out Browser Add-on.

Legal Basis: Legitimate interest (GDPR Art. 6(1)(f)) for improving the App, provided you do not object. You may opt out at any time.

2.3 Cookies We Do NOT Use

We want to be transparent about what we do not use:

  • Advertising Cookies: We do not serve ads or use cookies for targeted advertising.
  • Third-Party Marketing Cookies: We do not allow third-party marketing platforms to set cookies.
  • Social Media Cookies: We do not embed social media widgets that set cookies (e.g., Facebook Pixel, LinkedIn Insight Tag).
  • Cross-Site Tracking: We do not participate in cross-site tracking or data broker networks.

3. Other Tracking Technologies

3.1 Local Storage

We use browser local storage to temporarily store non-sensitive data such as:

  • User interface preferences (e.g., sidebar collapsed/expanded)
  • Draft content before submission (to prevent data loss)
  • Cached data to improve performance

Important: Local storage data remains on your device and is not transmitted to our servers unless you explicitly perform an action (e.g., save a setting).

3.2 Server Logs

Our hosting provider (Vercel) automatically collects server logs containing:

  • IP address (anonymized after 30 days)
  • Request timestamp
  • URL accessed
  • HTTP status code
  • User agent (browser and device information)

Purpose: Security monitoring, error debugging, and performance optimization.

Retention: Raw logs retained for 30 days; aggregated anonymized logs retained for 1 year.

3.3 Email Tracking (Transactional Emails Only)

Emails sent via Resend (e.g., magic login links, shipping notifications) may include:

  • Open tracking: A 1x1 pixel to detect when the email is opened
  • Link click tracking: Links redirected through Resend's domain to track clicks

Purpose: To monitor email deliverability and detect issues (e.g., emails not being received).

Opt-Out: You can disable image loading in your email client to prevent open tracking. Click tracking cannot be disabled as it's necessary for magic login links to function.

4. Third-Party Cookies and Services

The App integrates with the following third-party services that may set their own cookies when you interact with them:

4.1 Shopify

When you authenticate via Shopify OAuth, Shopify may set cookies on their domain (myshopify.com) to manage your session. These cookies are governed by Shopify's Cookie Policy: https://www.shopify.com/legal/cookies

4.2 Google Analytics

As described in Section 2.2, Google Analytics sets cookies to track usage patterns. Google's use of data is governed by their Privacy Policy: https://policies.google.com/privacy

5. Your Cookie Choices

5.1 Cookie Preferences Tool

You can manage your cookie preferences at any time by clicking the Cookie Settings link in the App footer.

Available Options:

  • Essential Cookies: Always active (cannot be disabled)
  • 🔘 Analytics Cookies: Optional (you can enable or disable)

5.2 Browser Settings

Most browsers allow you to control cookies through their settings. You can:

  • Block all cookies
  • Delete existing cookies
  • Set preferences for specific websites

Browser Help Pages:

Note: Disabling essential cookies will prevent the App from functioning properly. You will not be able to log in or use key features.

5.3 Do Not Track (DNT)

Some browsers include a "Do Not Track" (DNT) signal. Currently, there is no industry consensus on how to interpret DNT signals, so the App does not respond to DNT requests.

If a standard emerges, we will update this policy and implement support for DNT signals.

6. Mobile App Considerations

Currently Not Applicable: The Sonar Seed App is a web application accessible via browser. We do not have a native mobile app at this time.

If we launch a mobile app in the future, we will update this Cookie Policy to address mobile-specific tracking technologies (e.g., mobile advertising IDs, push notification tokens).

7. Changes to This Cookie Policy

We may update this Cookie Policy from time to time to reflect changes in our practices or legal requirements.

Notification of Changes:

  • Updated "Last Updated" date at the top of this page
  • Email notification for material changes
  • In-app banner notification

Your Continued Use: By continuing to use the App after changes take effect, you accept the updated Cookie Policy.

8. Contact Us

If you have questions about our use of cookies or this Cookie Policy, please contact:

Sonar Seed
Data Protection Officer

Email: privacy@sonarseed.com
Support: support@sonarseed.com
Legal: legal@sonarseed.com

Address: Sonar Stack, c/o GAM, Pappelallee 64, 10437 Berlin, Deutschland


Appendix: Detailed Cookie Table

For transparency, here is a complete list of cookies set by the Sonar Seed App:

Cookie NameCategoryProviderPurposeDurationDomain
sb-access-tokenEssentialSupabaseAuthentication token for logged-in usersSession.sonarseed.com
sb-refresh-tokenEssentialSupabaseRefresh token to maintain login30 days.sonarseed.com
__Secure-next-auth.session-tokenEssentialNext.jsServer-side session managementSession.sonarseed.com
__Host-next-auth.csrf-tokenEssentialNext.jsCSRF protectionSession.sonarseed.com
_gaAnalyticsGoogleGoogle Analytics user identifier2 years.sonarseed.com
_ga_<ID>AnalyticsGoogleGoogle Analytics session and campaign data2 years.sonarseed.com
_gidAnalyticsGoogleGoogle Analytics short-term user identifier24 hours.sonarseed.com

Cookie Attributes:

  • Secure: All cookies transmitted only over HTTPS
  • HttpOnly: Where applicable, cookies are not accessible via JavaScript (prevents XSS attacks)
  • SameSite: Set to Lax or Strict to prevent CSRF attacks

Questions or Concerns?

If you believe a cookie has been set incorrectly or have privacy concerns, please contact privacy@sonarseed.com immediately.


Effective Date: This Cookie Policy is effective as of 28.01.2026.

Version: 1.0