VERI-TRUST

Legal information

Cookie Policy

Information about the cookies, local storage, authentication mechanisms, security technologies, and similar tools that may be used by Veri-Trust.

Last updated: July 2026

1. Purpose of this Cookie Policy

This Cookie Policy explains how Veri-Trust may use cookies, browser storage, authentication tokens, security mechanisms, and similar technologies when users access or use the platform.

It should be read together with the Privacy Policy and GDPR Information page, which provide further information about the purposes, legal bases, recipients, retention periods, international transfers, and rights relating to personal data.

Veri-Trust is operated and developed by Collier Consulting Company SARL.

2. What is a cookie?

A cookie is a small file or piece of information that a website may store or access on a user’s device through a web browser.

Cookies may be used to maintain a session, authenticate a user, remember preferences, secure a service, measure audience activity, process a payment journey, or support other website functionality.

Not every technology used by Veri-Trust is technically a cookie. Similar technologies may include local storage, session storage, authentication tokens, device storage, security identifiers, pixels, software development kits, or other mechanisms that store or access information on a device.

For clarity, this Cookie Policy may use the term “cookies and similar technologies” to refer collectively to these mechanisms.

3. Strictly necessary technologies

Strictly necessary technologies are used only where required to provide a service expressly requested by the user, maintain authentication, secure the platform, preserve essential preferences, prevent abuse, or ensure the technical operation of the website.

These technologies may be used without optional consent where applicable law permits an exemption because they are strictly necessary for the requested service or for electronic communications.

Disabling strictly necessary technologies through browser settings may prevent account authentication, secure sessions, language preferences, subscription management, fraud prevention, or other essential functions from operating correctly.

Veri-Trust does not use the classification “strictly necessary” merely because a technology is commercially useful. The technology must be necessary for the relevant service or security purpose.

4. Authentication and account storage

Veri-Trust uses Supabase to provide account authentication, session management, email confirmation, password-reset functionality, and access control.

Depending on the technical configuration, authentication information may be stored through browser local storage, session storage, secure cookies, or another session mechanism used by Supabase.

Authentication storage may contain an access token, refresh token, expiry information, internal session information, or identifiers required to maintain a signed-in session.

This storage is considered strictly necessary when it is required to create, authenticate, or maintain the user’s requested account session.

Users may remove authentication information by signing out, clearing browser storage, or deleting relevant website data. Clearing this information may immediately end the active session.

5. Language and interface preferences

Veri-Trust may use local storage or a similar browser mechanism to remember the language selected by the user.

The current implementation may store the value “en” or “fr” under a browser-storage key associated with the locale preference.

This preference is used only to display the platform in the language selected by the user and is not intended to track the user across unrelated websites.

The preference may remain stored until it is replaced, manually deleted, or removed when the user clears browser data.

6. Security, rate limiting, and abuse prevention

Veri-Trust may process technical information to protect accounts and infrastructure, enforce usage limits, prevent automated abuse, detect suspicious activity, and maintain service availability.

Relevant information may include IP addresses, timestamps, action types, failed attempts, authentication events, request metadata, and security indicators.

Some of this processing occurs on Veri-Trust servers and may not involve placing a cookie on the user’s device.

Where a security provider such as Cloudflare or Cloudflare Turnstile is enabled, that provider may use necessary cookies or similar technologies to distinguish legitimate users from automated or malicious activity.

Security technologies are not used by Veri-Trust for behavioural advertising.

7. Subscription and payment technologies

Paid Veri-Trust subscriptions are processed through Stripe.

When a user chooses a paid plan, Veri-Trust may redirect the user to a Stripe-hosted checkout page or use Stripe functionality required to create and administer the payment session.

Stripe may use cookies or similar technologies on its own pages for payment processing, fraud prevention, authentication, regulatory compliance, security, and checkout functionality.

The cookies and technologies used directly on Stripe-controlled pages are governed by Stripe’s applicable privacy and cookie documentation.

Veri-Trust does not directly store full payment card details.

8. Hosting and infrastructure technologies

Veri-Trust uses Vercel for hosting, deployment, content delivery, and related infrastructure services.

Vercel or its infrastructure partners may process technical request information necessary to deliver the website, protect the service, diagnose errors, prevent abuse, and maintain availability.

Some infrastructure processing may occur through server logs, network identifiers, or technical security mechanisms rather than through cookies stored directly by Veri-Trust.

Infrastructure technologies will be classified according to their actual purpose and configuration rather than solely according to the name of the provider.

9. Analytics and audience measurement

Veri-Trust does not intend to activate non-essential analytics or audience-measurement technologies without first implementing the information and consent measures required by applicable law.

Certain narrowly configured audience-measurement technologies may qualify for a consent exemption only where all applicable legal and technical conditions are satisfied.

If Veri-Trust introduces analytics that require consent, those analytics will remain disabled until the user has made an affirmative choice.

The Cookie Policy and preference interface will be updated to identify the relevant provider, purpose, stored information, duration, recipients, and withdrawal mechanism.

10. Advertising and cross-site tracking

Veri-Trust does not currently intend to use advertising cookies, behavioural profiling cookies, cross-site tracking pixels, or technologies designed to follow users across unrelated websites.

Such technologies will not be introduced without an appropriate legal assessment, an update to this Cookie Policy, and prior consent where required.

Rejecting optional advertising technologies must not prevent access to the core Veri-Trust service unless a specific optional service technically depends on the requested technology.

11. Translation functionality

When a user requests the translation of a published community comment, the relevant text may be transmitted to OpenAI or another configured translation provider.

The translation feature is initiated by a deliberate user action and does not itself require Veri-Trust to place an advertising or analytics cookie.

The resulting translation may be stored in the Veri-Trust database to avoid repeatedly sending the same comment for translation.

Any provider-side technologies used when visiting a provider-controlled website are governed by that provider’s own documentation and are distinct from the server-to-server translation request made by Veri-Trust.

12. Consent for optional technologies

Where consent is legally required, Veri-Trust will request consent before activating or accessing the relevant optional technology.

Consent must be freely given, specific, informed, and unambiguous.

The user must be able to accept or reject optional technologies through choices presented with comparable clarity and accessibility.

Silence, inactivity, continued browsing, or a pre-selected option will not be treated as valid consent where affirmative consent is required.

Optional technologies must remain disabled until valid consent has been obtained.

13. Refusing optional technologies

Users may refuse optional analytics, advertising, personalisation, or other non-essential technologies without losing access to the core Veri-Trust service.

The refusal mechanism must be as accessible as the acceptance mechanism.

A refusal may be stored through a necessary preference mechanism so that the platform does not repeatedly ask the same user to make the same choice during the applicable preference period.

Refusing optional technologies does not prevent Veri-Trust from using strictly necessary technologies required for security, authentication, requested functionality, or legal compliance.

14. Withdrawing or changing consent

Where optional technologies are introduced, users will be able to withdraw or modify their consent at any time through a cookie-preference control made available on the platform.

Withdrawal must be as easy as giving consent.

Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.

After withdrawal, Veri-Trust will stop activating the relevant optional technologies and will take reasonable steps to prevent further optional storage or access.

Information already lawfully collected may remain subject to the retention periods and legal requirements described in the Privacy Policy.

15. Duration of cookie preferences

Veri-Trust may retain the user’s cookie choice for a limited period so that the consent interface is not shown on every visit.

Unless a different period is required by law or justified by a material change, Veri-Trust intends to retain an acceptance or refusal preference for no longer than six months before requesting a new choice.

A new choice may be requested earlier where the purposes, providers, categories of technologies, legal requirements, or consent interface materially change.

Strictly necessary storage may have a different duration where required for the relevant session, security, authentication, or preference purpose.

16. Technology duration and deletion

Session technologies generally expire when the browsing session ends, the user signs out, or the session is otherwise invalidated.

Persistent browser storage may remain until its configured expiry, until it is replaced, until the user signs out, or until the user clears the relevant browser data.

Security and authentication durations may be determined by the session configuration, provider configuration, security requirements, and account status.

Veri-Trust will periodically review enabled technologies and remove those that are no longer necessary or proportionate.

The duration stated in the technology inventory is indicative of the intended configuration and must be verified against the actual production configuration.

17. Browser and device controls

Most browsers allow users to view, block, restrict, or delete cookies and website storage through browser settings.

Users may also clear local storage, session storage, cached website data, or permissions associated with Veri-Trust.

Browser settings vary by browser, device, and software version.

Blocking all storage may prevent Veri-Trust from maintaining authentication, remembering the language selection, protecting sessions, or providing other requested functionality.

Browser-level deletion does not necessarily delete information lawfully stored in Veri-Trust databases or server logs.

18. Third-party providers

The current or potential providers associated with website operation may include Supabase, Vercel, Stripe, Cloudflare, Google Workspace, and OpenAI where the corresponding functionality is enabled.

The inclusion of a provider in this policy does not mean that every provider places cookies on the Veri-Trust website or receives every category of personal data.

Each provider may process information only for the services, integrations, and configurations actually enabled.

Some providers may act as processors, sub-processors, or independent controllers depending on the relevant activity.

19. International transfers

Some technology providers or their sub-processors may process data outside the European Economic Area.

Where an international transfer is subject to the GDPR, Veri-Trust will rely on an applicable transfer mechanism, such as an adequacy decision, the European Commission’s Standard Contractual Clauses, or another legally recognised safeguard.

Further information about international transfers is provided in the Privacy Policy and GDPR Information page.

20. Personal data and legal bases

Information collected through cookies or similar technologies may constitute personal data where it relates to an identified or identifiable individual.

Strictly necessary account and service technologies may support processing based on performance of a contract under Article 6(1)(b) GDPR.

Security, fraud-prevention, rate-limiting, and infrastructure technologies may support processing based on Veri-Trust’s legitimate interests under Article 6(1)(f) GDPR or a legal obligation under Article 6(1)(c), depending on the purpose.

Optional analytics, advertising, or personalisation technologies requiring consent will rely on consent under Article 6(1)(a) GDPR.

The rules governing storage or access on a user’s device apply in addition to the legal basis required for any subsequent processing of personal data.

21. Current implementation status

At the date of this policy, Veri-Trust is intended to operate primarily with technologies necessary for language preferences, account authentication, security, rate limiting, infrastructure, requested subscriptions, and requested platform functionality.

Non-essential advertising or cross-site behavioural tracking technologies are not intended to be active at launch.

Before production launch and after every material technical change, Veri-Trust should perform a technical audit of browser cookies, local storage, session storage, network requests, embedded services, and provider configurations.

The production technology inventory must be updated whenever a new technology, provider, purpose, or retention period is introduced.

22. Changes to this Cookie Policy

Veri-Trust may update this Cookie Policy to reflect technical changes, new providers, new integrations, legal developments, or changes to the technologies used by the platform.

The date displayed at the top of the page indicates the latest published update.

Where a change affects a consented purpose or introduces a new optional technology, Veri-Trust may request a new consent choice before activating that technology.

23. Contact

Questions about cookies and similar technologies: privacy@veri-trust.app.

Legal and compliance requests: legal@veri-trust.app.

General support: support@veri-trust.app.

Website: https://veri-trust.app.

Technology inventory

Technologies currently used or planned

This inventory describes the principal technologies identified in the current Veri-Trust architecture. It must be checked against the final production configuration before launch and after every material technical change.

TechnologyProviderPurposeCategoryStorage typeExpected durationConsent
Locale preferenceVeri-TrustRemember whether the user selected the English or French interface.Essential preferenceBrowser local storageUntil replaced or deletedNot required where strictly necessary for the requested preference
Authentication sessionSupabaseAuthenticate users, maintain sessions, refresh access, and protect account functionality.Strictly necessaryLocal storage, session storage, or secure session mechanism depending on configurationSession duration or until sign-out, expiry, revocation, or deletionNot required for requested account functionality
Security and rate limitingVeri-Trust / infrastructure providersPrevent abuse, enforce usage limits, detect suspicious requests, and protect service availability.Strictly necessary securityPrimarily server-side records; provider technology where enabledAccording to the applicable security and retention scheduleNot required where strictly necessary for security
Hosting and deliveryVercelDeliver the website, operate infrastructure, diagnose failures, and protect availability.Strictly necessary infrastructureTechnical request logs and provider security mechanismsAccording to provider and Veri-Trust retention configurationNot required for essential website delivery
Checkout and subscriptionStripeCreate checkout sessions, process payments, prevent fraud, and administer subscriptions.Strictly necessary paymentStripe-hosted cookies and payment-session technologiesAccording to Stripe configuration and legal requirementsNot required for the payment service requested by the user
Bot and abuse protectionCloudflare / TurnstileDetect automated abuse and protect forms or platform endpoints where enabled.Strictly necessary securitySecurity cookies or comparable technical signals where enabledAccording to the enabled security configurationNot required where strictly necessary for security
Comment translationOpenAI or configured providerTranslate a published community comment after a user requests a translation.Requested functionalityServer-to-server request; translation may be cached in the databaseAccording to the translation and review retention scheduleNo cookie consent expected for the server-side request; privacy information remains applicable
Optional analyticsNot currently selectedPotential future audience measurement and product analytics.Optional analyticsNot enabled unless configuredTo be defined before activationRequired unless a valid exemption applies
Advertising or cross-site trackingNone intended at launchNo advertising or cross-site behavioural tracking purpose is currently intended.Optional advertisingNot enabledNot applicableWould require prior consent if introduced

Important production verification

This policy describes the intended Veri-Trust configuration and the technologies currently identified in the project.

Before official launch, the deployed production website must be inspected to verify the exact cookie names, local-storage keys, providers, purposes, domains, expiry periods, and data flows.

A technology must not be described as inactive if it is actually enabled in production.