Last updated: 24 July 2026

Cookie policy

This cookie policy explains which cookies and similar technologies Kadova uses on the marketing website, the signed-in platform and customer hosted webshops. We process optional analytics and marketing only after your explicit consent.

1. Who is responsible?

Responsibility depends on context:

  • Kadova (marketing site, signup, signed-in platform): Kadova is controller for analytics and marketing consent of platform users and anonymous visitors
  • Customer hosted webshop: the customer organisation is controller for consumers; Kadova acts as processor. Optional tenant analytics runs only after consent in that shop
  • Shop widgets (iframe): no Kadova cookie banner; marketing email opt-in only via the customer checkout checkbox

2. Strictly necessary

These technologies are required for the service and do not require consent:

  • Session and authentication cookies (httpOnly) for login and tenant selection
  • Language and interface preferences
  • Security, CSRF protection and rate limiting
  • Checkout and payment cookies from Stripe/Mollie (contractual)

3. Analytics (opt-in)

Google Analytics 4 on marketing pages measures only after consent via the cookie banner (Consent Mode v2: denied by default). We do not load GA4 in the dashboard. Hosted shops may optionally configure their own GA4; that runs only after shop visitor consent and under tenant responsibility.

  • Purpose: insight into website visits and conversion on marketing/signup
  • Legal basis: consent (GDPR art. 6(1)(a))
  • Proof: ConsentPreference/ConsentEvent on the server; local preference in scoped storage
  • Expiry: 13 months without reconfirmation

4. Marketing email (opt-in)

Marketing email to platform users requires explicit consent in My data or notification preferences — never via the cookie banner. Consumer marketing in shops uses a separate checkout checkbox (off by default).

  • No implicit opt-in for existing customers
  • Withdraw via My data, notification settings or one-click unsubscribe
  • Marketing opt-out proof: retained for 10 years

5. Hosted webshops

On /shop/* and customer custom domains we do not show the Kadova marketing banner. With CONSENT_V2_SHOP_UI a tenant-branded banner may appear when the tenant has enabled optional analytics. Consumer marketing email always follows checkout opt-in under shop responsibility.

  • Consent scope per tenant: isolated browser storage shop:{clientId}
  • Platform GA4 is not loaded on shop routes
  • Widgets: no Kadova tracking; checkout marketing checkbox only if offered

6. Browser storage

Besides cookies we use localStorage for consent preferences:

  • cookie_consent:kadova-site — marketing website analytics choice
  • cookie_consent:shop:{tenantId} — per-shop analytics choice
  • kadova_visitor_id — opaque UUID for anonymous consent sync (no fingerprinting)

7. Third parties

Optional tags load only after consent. See also /legal/subprocessors.

  • Google Analytics 4 — analytics (consent-gated)
  • Stripe / Mollie — payment (necessary at checkout)
  • Sentry — error monitoring (legitimate interest, minimised; no consent banner)

8. Changing your choices

You can withdraw or adjust consent at any time:

  • Marketing website: reopen the cookie banner via /cookies or clear browser data
  • Signed in: Settings → My data
  • Shop: cookie settings in the shop footer (when tenant analytics is active)

9. Contact

Questions about cookies or consent: privacy@kadova.nl. See also /privacy for the full privacy policy.

Manage cookie preferences

Adjust your analytics choice for the Kadova marketing website. Signed-in users manage marketing and analytics in My data.