Cookie Policy

This policy explains which browser technologies Floov uses, why they are used, and how visitors can control optional categories.

Last updated:

1. Scope and Terminology

This policy applies to Floov pages and published forms operated by FLOOV S.R.L.. A cookie is a small value stored by a website in a browser. Local storage and session storage are similar browser technologies but are not automatically sent with each request. We refer to them together as “browser storage”.

Floov distinguishes essential technology from optional analytics and marketing technology. Essential technology is active because it provides a requested feature or keeps the service secure. Floov’s own site and app offer separate Analytics and Marketing choices. Marketing covers lead attribution and CRM tracking as well as advertising and campaign measurement, personalized advertising, and remarketing. On published forms, the separate choice described below applies only to customer-configured GA4, GTM, and Meta Pixel.

2. Technologies We Use

  • HTTP cookies for authenticated sessions, security, and CSRF protection.
  • Local storage for consent choices and for published-form progress or device choices when the corresponding form feature is enabled.
  • Session storage for preserving pending account-setting changes during Google reauthentication and deduplicating first-party form events within the current tab.
  • Pixels, tags, or SDKs only for optional Floov analytics, HighLevel CRM and attribution tracking, or customer-configured GA4, GTM, and Meta Pixel, under the rules below.

3. Essential Cookies and Storage

Essential cookies and browser storage used by Floov
Name or pattern Purpose Typical duration
*_session Maintains login state, security context, and server session Normally two hours of inactivity; browser behaviour may retain the cookie until its expiry
XSRF-TOKEN Protects state-changing requests from cross-site request forgery Session
cookie_consent (local storage) Records category choices and their timestamp so the banner need not ask on every page Up to 180 days, or until changed or browser storage is cleared
floov:profile-email-change-draft (session storage) Preserves pending profile changes while a customer reauthenticates with Google Removed after return from reauthentication, or when the browser tab session ends
floov_form_attempt:* (session storage) Stores completion and sent-event flags to avoid duplicate first-party form events after a refresh; contains no random visitor or attempt identifier Current browser tab session
Password or access session state Remembers an authorised form/report unlock and protects sensitive account actions Session or the short validity stated in the feature
Turnstile verification Cloudflare bot and abuse protection on protected requests Short-lived, as determined by Cloudflare

Essential technology does not require an opt-in because it is used to deliver a feature the visitor requests or keep the service secure. It is not used for advertising.

4. Published-Form Browser Storage

Floov treats the following first-party storage as part of the corresponding form feature rather than as Analytics or Marketing:

  • a partial response identifier and opaque resume token;
  • the current page and locally cached answers for save-and-resume;
  • a device marker used when a form owner enables one-response-per-device protection; and
  • other form preferences expressly described in the interface.

When a form owner enables save-and-resume or device-based duplicate prevention, the corresponding browser values are read and written as part of that form feature. They are not controlled by the separate GA4, GTM, and Meta Pixel tracking choice. Clearing browser storage removes existing values. Files selected in a form are never persisted in browser storage and must be selected again after a reload.

5. Analytics and Marketing Technologies

Floov Analytics and Marketing Tags

On Floov’s marketing and authenticated application pages, PostHog receives a limited pageview only after Analytics is enabled. Floov also uses Google Tag Manager as a container for Floov-configured analytics and marketing tags. The container loads only after Analytics or Marketing is enabled, and each tag must require the category matching its purpose. DOM autocapture, session recording, surveys, and feature flags are disabled in PostHog. Authenticated PostHog events use an internal account ID, not name or email. Floov’s own PostHog and Google Tag Manager integrations are never loaded on published forms or public reports.

PostHog and Google Analytics 4 are Floov’s active browser analytics providers. The published Floov GTM container includes a Google Analytics 4 tag for page and related website and application usage measurement after Analytics consent. Floov does not currently run Google advertising or retargeting tags on its marketing or application pages. Before Floov activates another tag, this policy will be updated where necessary, and the tag will remain off unless the visitor has enabled its category.

Floov also uses HighLevel external tracking for lead attribution and customer-relationship management. After Marketing consent, HighLevel can receive page URLs, referring and campaign information, session and device information, IP address and approximate location, and fields submitted through supported forms in the page DOM. This can create or update a contact and associate the page activity or submission with that contact. Floov does not load this tracker on published forms.

Optional analytics and marketing technologies
Technology Category When it can load
PostHog browser SDK Analytics After Analytics consent on Floov pages
Google Analytics 4 Analytics On Floov pages after Analytics consent; on a configured form, after Analytics consent when the owner enables the form banner, otherwise immediately at the owner’s direction
Google Tag Manager Analytics and Marketing On Floov pages after at least one optional category is enabled, with each Floov tag requiring its matching category; on a configured form, after both Analytics and Marketing consent when the owner enables the form banner, otherwise immediately at the owner’s direction
Google advertising tags Marketing On Floov pages only if Floov configures advertising measurement, personalized advertising, or remarketing, and then after Marketing consent
HighLevel external tracking Marketing After Marketing consent on Floov pages other than published forms
Meta Pixel Marketing On a configured form, after Marketing consent when the owner enables the form banner, otherwise immediately at the owner’s direction

The provider can set or read its own identifiers after loading. Its exact names and durations can change and are governed by its documentation. See HighLevel’s Privacy Policy. Floov does not currently run advertising or retargeting tags on Floov marketing or application pages.

First-Party Form Measurement

Published forms send limited first-party view, start, and page-reach events to Floov so owners can understand form performance. The viewer stores completion and sent-event flags in session storage to avoid duplicating events after a refresh in the same tab. Those flags contain no random visitor or response-attempt identifier and are not sent to Floov. Signals update aggregate counters without retaining individual visitor-event records. This measurement is not used across websites or for advertising, and Floov does not store raw IP addresses in form-analytics records. It is separate from PostHog and customer-installed trackers.

Stripe Checkout

Selecting Subscribe sends the customer to Stripe’s hosted checkout and billing tools. Stripe may use cookies for checkout, security, fraud prevention, payment processing, and its own legal obligations under Stripe’s cookie policy. Those technologies are controlled by Stripe on its domain.

6. Published Forms and the Form Owner

When the form owner enables Floov’s form consent banner, owner-configured GA4, GTM, and Meta Pixel follow the visitor’s selected categories. Choices expire after 180 days, and a changed notice version asks again.

If the owner disables the form banner, configured GA4, GTM, and Meta Pixel technologies may load immediately at that owner’s direction. The owner must then provide the privacy and cookie notice and obtain any consent required for its audience, jurisdiction, trackers, and purposes. Save-and-resume, device-based duplicate prevention, and Floov’s first-party form measurement remain separate. Questions about owner-configured trackers should be directed to that form owner.

7. Managing Your Choices

  • Select Accept all, Reject non-essential, or open Preferences in the banner. Optional categories are not preselected.
  • Use Cookie Preferences in the site footer at any time. A change applies to future use and does not make prior consent-based processing unlawful.
  • When a published form displays Floov’s banner, use the persistent Privacy choices button to withdraw or change that choice. Google Consent Mode is updated and Meta receives its revoke signal where those providers were loaded.
  • Clear cookies, local storage, and site data in your browser to remove stored identifiers and consent choices. The banner will ask again afterward.
  • Browser blocking can prevent even essential cookies and may stop login, checkout initiation, protected forms, or other requested features from working.

Because Floov does not sell or share personal information for cross-context behavioural advertising, Global Privacy Control and Do Not Track do not change a sale/sharing practice. The consent controls remain the reliable way to manage the optional technologies described here.

8. Changes and Contact

We may update this policy when browser technology, providers, or law changes. We will update the date above and provide additional notice where required.

FLOOV S.R.L.

CUI 54655476 · Trade Register J2026030772003 · Romania

[email protected]