Excellent PRO
Excellent PRO

Cookies & privacy

Cookie Policy

Version 1.2 · effective from 23 September 2026 · excellentpro.app

The excellentpro.app Platform uses strictly necessary cookies and browser storage for the operation of the service (login, shopping cart, language, currency, record of your choice) and - only with your consent - analytics cookies. We additionally measure traffic with a tool that stores nothing on your device. We do not profile Users. This Cookie Policy supplements the Privacy Policy.

§ I

What cookies are

  1. Cookies are small text files saved by the browser on the User's device. They allow the site to remember preferences (e.g. login status, shopping cart contents) between visits and subpages.
  2. Cookies do not contain personal data that would allow direct identification - they store a session identifier referring to the Controller's database or a simple preference (selected language, currency).
  3. In addition to classic cookies (HTTP cookies), the Platform uses the browser's localStorage and sessionStorage - analogous mechanisms kept locally and not sent to the server in HTTP headers. sessionStorage is cleared automatically when the browser tab is closed.
§ II

Cookies used on the Platform

All of the entries below are strictly necessary for the operation of the service. Without them you will not be able to log in, place an order or retain your preferences. None of them is shared with third parties.

sb-*-auth-token
Purpose: The login session (Supabase Auth) - keeps you logged in across pages and subpages; for a longer session it may be split into several parts (suffix .0, .1).
Duration: Refreshed on every activity, up to 12 months; removed when you log out.
Type: HTTP cookie, Secure, SameSite=Lax (set by the server as httpOnly).
cart:excellent, cart:oem
Purpose: The shopping cart contents for Users who are not logged in (separately for the Excellent PRO and OEM catalogues), stored locally in the browser. After you log in the cart is merged with the Account cart in the Controller's database and the local entry is removed.
Duration: Until merged with the Account or until the User manually clears the browser data - no automatic expiry.
Type: localStorage (not an HTTP cookie).
epro_lang, epro_currency
Purpose: Remembering the selected language (PL/EN) and price display currency (PLN/EUR), so that the Platform opens in your version.
Duration: 12 months from the last change of the setting.
Type: HTTP cookie set in the browser, SameSite=Lax; contains only the language or currency code.
ep-popup-*
Purpose: Remembering that an announcement (information window) has already been shown, so that it is not displayed again in this session or more than once a day.
Duration: Until the tab is closed (sessionStorage) or a timestamp in localStorage checked for 24 hours; the entry is not sent to the server.
Type: sessionStorage or localStorage.
epro_panels_*
Purpose: For the Controller's staff only: the list of available panels, so that the server is not queried on every navigation.
Duration: Until the browser tab is closed.
Type: sessionStorage.
excpro_consent_v1
Purpose: Remembering your choice in the consent banner (which categories you enabled), so that we do not ask on every visit.
Duration: 12 months, after which we ask again.
Type: localStorage.

Analytics cookies - only with your consent

These are activated only after you enable the “Analytics” category in the banner. Until you do, no Google script is downloaded or executed, and Google receives no data about you. The Google script is loaded through a Google Tag Manager container which, in our configuration, runs Google Analytics 4 only.

_ga, _ga_*
Purpose: Google Analytics 4 - visit statistics: how many people use the Platform, which sources they arrive from and which product pages they view.
Duration: Up to 24 months (Google setting).
Type: Third-party cookies (Google Ireland Ltd.).
Legal basis: Your consent - you may withdraw it at any time (see § V).

Cookieless traffic measurement

Independently of the above, we use Cloudflare Web Analytics, a tool that measures page views and loading speed. We list it here for full transparency, even though it stores no files on your device (no cookies, no localStorage), assigns you no identifier, does not track you across sites and builds no profile. For that reason it does not require consent and operates independently of your banner settings. Provider: Cloudflare, Inc.

§ III

What we do NOT use

Beyond the analytics described in § II, the Controller deliberately does not use the following tracking technologies:

  • Facebook Pixel, TikTok Pixel, LinkedIn Insight Tag
  • remarketing tools (Google Ads, Meta Ads, programmatic)
  • third-party cookies that collect data for profiling or resale
  • web beacons, pixel tags, fingerprinting (canvas/font/audio)
  • session recording (Hotjar, Microsoft Clarity, FullStory, etc.)
  • A/B testing tools based on profiling

Visit statistics serve one purpose: developing the Platform - judging which features are used and what loads slowly. We build no user profiles on that basis, make no automated decisions about anyone, and share none of it for advertising purposes. The Platform is a B2B tool for fulfilling orders, not a marketing channel.

§ IV

Legal basis

  1. Cookies strictly necessary for the functioning of the service do not require the User's consent - legal basis: Article 399(3)(2) of the Electronic Communications Law of 12 July 2024 (Journal of Laws 2024, item 1221) - the exemption for cookies strictly necessary to provide a service requested by the user.
  2. To the extent that cookies process data which may constitute personal data (e.g. a session identifier linked to the Customer's account), the legal basis is Article 6(1)(b) of the GDPR - performance of a contract.
  3. Analytics cookies require your consent - legal basis: Article 399(1) of the Electronic Communications Law and Article 6(1)(a) of the GDPR. Consent is voluntary, given by a deliberate action in the banner (no toggle is pre-ticked), and you may withdraw it at any time without affecting the lawfulness of processing carried out beforehand.
  4. Traffic measurement that stores nothing on your device (Cloudflare Web Analytics, see § II) requires no consent, as there is no storing of, or access to, information on terminal equipment within the meaning of Article 399(1) of the Electronic Communications Law. The legal basis is Article 6(1)(f) of the GDPR - the Controller's legitimate interest in maintaining and developing the Platform.
§ V

Managing cookies

  1. You can disable cookies at any time in your browser settings. Disabling session cookies will make it impossible to log in and place an order - the Platform will not function correctly.
  2. To delete cookies already saved on your device, use the "Clear browsing data" function in your browser.
  3. Instructions for popular browsers:
  4. To change or withdraw your consent, use the "Cookie settings" link in the footer of every page - the banner reopens with your saved settings. There is no need to open developer tools or clear browser data.
§ VI

Consent banner

  1. On the first visit to the Platform, a consent banner is displayed. The banner contains:
    • information about the categories of cookies in use
    • three categories to choose from: Essential (always active, the service does not work without them), Analytics and Marketing - the latter two switched off by default. The "Marketing" category is currently unused: the Platform has no advertising tools, so enabling it runs no script and only passes a consent signal in Consent Mode; we will put it to use only after updating this Policy
    • a link to this Cookie Policy and the Privacy Policy
    • three buttons on the same screen: "Reject all", "Customise" and "Accept all"
  2. Refusing consent is as easy as giving it - the "Reject all" button sits on the same screen, is the same size as "Accept all" and works with a single click, without extra steps. No switch is pre-ticked (in line with the CJEU judgment in Case C-673/17 Planet49). Inaction does not amount to consent: until you click, no analytics script is executed.
  3. Consent is handled with Google Consent Mode v2. Until you decide, every category other than the essential ones has the status denied, meaning Google tools store no cookies and transmit no data.
  4. Once you make your choice, the excpro_consent_v1 key is saved in localStorage with your decision for each category and the date it was given, valid for 12 months. The banner does not appear again until this key is cleared, its validity expires, or the substance of the consent changes.
  5. You can change or withdraw your choice at any time via the "Cookie settings" link in the footer of every page. The banner reopens with your saved settings.
  6. The banner is accessible to people using assistive technologies (screen readers) - it has a role="dialog" attribute and an ARIA label describing the content.
§ VII

Contact

For matters relating to cookies, their configuration or this Policy - please contact the Controller:

For the full rules on the processing of personal data - see the Privacy Policy. For the full terms of use of the Platform - see the Terms and Conditions.

This Cookie Policy version 1.2 comes into force on 23 September 2026 (version 1.1 applied from 3 September 2026, version 1.0 from 1 May 2026).

Related documents: Terms and Conditions · Privacy Policy