Cookie notice
This page explains which cookies and similar technologies we use, for what purpose, and how you can withdraw your consent at any time.
Last updated: August 2026
1. What are cookies?
Cookies are small text files stored by your browser. LocalStorage, SessionStorage and tracking pixels work in a comparable way. Any storage access that is not strictly necessary for the service you requested requires your consent under § 25 (1) TTDSG — we obtain it through our consent banner (Usercentrics/Cookiebot). Necessary storage is permitted under § 25 (2) TTDSG when required for operation.
2. Strictly necessary storage
| Service | Provider | Purpose | Duration |
|---|---|---|---|
| Sign-in session | E-Signing.io | Keeps you signed in and protects against session hijacking. | until sign-out, max. 30 days |
| Language choice (lang) | E-Signing.io | Remembers whether you use the German or English version so your next visit opens in the right language. | 12 months |
| Consent (CookieConsent) | Cybot A/S (Cookiebot) | Stores your cookie decision and, together with the Cookiebot consent log, serves as the record of consent (Art. 7 (1) GDPR). Provider: Cybot A/S (Usercentrics/Cookiebot), Denmark. | 12 months |
| Consent (CookieConsentBulkSetting / LocalStorage) | Cybot A/S (Cookiebot) | LocalStorage entry set by Cookiebot so a decision given across domains is preserved. | 12 months |
| Paddle (payment processing, incl. Retain) | Paddle.com Market Ltd. | Paddle.js is loaded so payments can be processed securely, interrupted payments recovered (Paddle Retain, formerly ProfitWell) and fraud detected. Inside the signed-in area the Paddle customer ID is passed along. No analytics or advertising. Transfers to third countries (incl. the USA) are based on standard contractual clauses. | Session up to 12 months |
| Language choice (es:lang / LocalStorage mirror) | E-Signing.io | Mirrors the language choice in LocalStorage so the selected language is preserved even when cookie use is restricted. | 12 months |
3. Functional storage
LocalStorage and SessionStorage are used inside the app to remember your working environment (e.g. last active workspace, open panels, onboarding status, integration status). These entries are not strictly required for operation, but improve usability. They are only set inside the app and are not shared with third parties.
| Service | Provider | Purpose | Duration |
|---|---|---|---|
| Sidebar state (sidebar_state) | E-Signing.io | Remembers whether the side navigation is expanded or collapsed. | 7 days |
| Active workspace (active_workspace) | E-Signing.io | Remembers the last active workspace so you can continue directly after reopening. | until deleted |
| Editor panel (editor:aside) | E-Signing.io | Remembers whether the right info panel in the editor is open or closed. | until deleted |
| Onboarding tour (tour-state) | E-Signing.io | Remembers which onboarding steps you have already seen so the tour is not repeated. | until deleted |
| Feature badges (gamification:seen) | E-Signing.io | Remembers which hints or badges you have already seen. | until deleted |
| Pending referral code (pending_referral) | E-Signing.io | Remembers a referral code before you sign up so bonus sends can be assigned after registration. | until redemption or deletion |
| Granola status (integration_status:granola:*) | E-Signing.io | Remembers whether your workspace is connected to Granola. | until deleted |
| MPU Manager status (integration_status:mpu:*) | E-Signing.io | Remembers whether your workspace is connected to the MPU Manager. | until deleted |
| Zapier status (integration_status:zapier:*) | E-Signing.io | Remembers whether your workspace is connected to Zapier. | until deleted |
| Cached documents (warm-documents) | E-Signing.io | Keeps a list of recently opened documents in memory so they load faster. | Session |
| OAuth return (oauth-return) | E-Signing.io | Remembers the page to return you to after an OAuth flow. | Session |
| OAuth signup (oauth-signup) | E-Signing.io | Holds OAuth signup data while the account is being created. | Session |
| Pending invite (pending-invite) | E-Signing.io | Remembers a team invitation token before you register. | Session |
| AI draft (ai-brief:*) | E-Signing.io | Holds an AI-generated document draft while you edit it. | Session |
| Last Granola meeting (granola:last-meeting) | E-Signing.io | Remembers the last selected meeting for faster access. | Session |
| Document type hint | E-Signing.io | Remembers that a document type hint dialog should not be shown again. | until deleted |
| Inquiry hint | E-Signing.io | Remembers that the incoming inquiries hint has already been shown. | until deleted |
| Granola dock height | E-Signing.io | Remembers the height you adjusted the Granola dock to. | until deleted |
| Granola dock minimized | E-Signing.io | Remembers whether the Granola dock is minimized. | until deleted |
4. Services requiring consent
| Service | Provider | Purpose | Duration |
|---|---|---|---|
| Zapier Workflow-Element | Zapier Inc., USA | Functional · Transfer to a third country (USA) based on EU standard contractual clauses | Sitzung |
5. Google Consent Mode v2
Where Google services are active, they run in Consent Mode v2: before your decision all signals are set to “denied” and no advertising or analytics cookies are set. Only after your consent do we grant the corresponding signals.
6. Withdrawing consent
You can change your decision at any time with effect for the future — without any disadvantage.
7. Browser settings
Independently of our banner you can block or delete cookies in your browser. Blocking necessary cookies may break sign-in and the signing flow.
8. Consent management (Usercentrics/Cookiebot)
To obtain, manage and document your consent we use the consent management platform Cookiebot provided by Cybot A/S, Havnegade 39, 1058 Copenhagen, Denmark (part of the Usercentrics group). Cookiebot automatically blocks scripts requiring consent until you agree and stores your decision in the "CookieConsent" cookie (12-month lifetime). As proof of consent it logs an anonymised IP address, date and time, user agent, the domain visited and the scope of your decision. The legal basis is § 25 (2) no. 2 TTDSG (technically required for the service you requested) and Art. 6 (1) (c) GDPR in conjunction with our accountability obligation under Art. 7 (1) GDPR. Processing takes place on servers in the EU; a data processing agreement under Art. 28 GDPR is in place.
9. Full cookie list
The overview below is maintained automatically by Cookiebot and updated after every scan of our domains.