TEMPLATE — REQUIRES REVIEW BY A QUALIFIED U.S. ATTORNEY BEFORE PUBLICATION This document is a template that contains [PLACEHOLDER] tags that must be replaced with accurate company-specific information before use. It is drafted in a U.S.-first posture with GDPR/UK GDPR/Swiss revDSG consent handling for EU/UK/Swiss users. It is not legal advice; the authors are not lawyers. A qualified attorney should review and finalize this document, and the cookie inventory below should be confirmed against the application's actual cookies before publication.
Effective Date: [PLACEHOLDER: MM/DD/YYYY] Last Updated: June 23, 2026
Company: [PLACEHOLDER: Legal Entity Name] ("we", "us", "our") Website / Platform: [PLACEHOLDER: https://nitix.app or applicable domain] Contact: [PLACEHOLDER: privacy@nitix.app]
1. Introduction
This Cookie Policy explains how [PLACEHOLDER: Legal Entity Name] uses cookies and similar technologies when you visit and use Nitix ("Platform"). This policy should be read alongside our Privacy Policy.
2. What Are Cookies?
Cookies are small text files placed on your device (computer, tablet, or mobile phone) when you visit a website. They are widely used to make websites work more efficiently, provide a better user experience, and supply information to website owners.
Similar technologies we may use include:
- Local Storage — Data stored in your browser that persists across sessions
- Session Storage — Data stored in your browser for the duration of a single session
- Web Beacons / Pixels — Small transparent images used to track page views or email opens
- Fingerprinting — Techniques that identify your device based on browser configuration [PLACEHOLDER: confirm if used]
3. Types of Cookies We Use
3.1 Essential / Necessary Cookies (Strictly Required)
These cookies are required for the Platform to function properly. They cannot be disabled without breaking core functionality.
nitix_auth_token— Stores your JWT (JSON Web Token) authentication credential after login. Required to identify your session and authorize API requests. Duration: 7 days (refreshed on each visit). Category: Necessary.nitix_session— Maintains your authenticated session state across page navigation. Duration: Session (cleared when browser is closed). Category: Necessary.nitix_csrf— Cross-site request forgery protection token. Duration: Session. Category: Necessary.nitix_consent— Records your cookie consent preferences (accepted, rejected, or customized). Duration: 12 months. Category: Necessary.nitix_locale— Stores your language, timezone, and regional display preferences. Duration: 12 months. Category: Necessary.
Legal basis: Necessary for performance of the contract (providing the Services) and/or legitimate interests (security).
3.2 Functional Cookies
These cookies enable enhanced functionality and personalization. They are optional but improve your experience.
nitix_prefs— Stores your Platform preferences such as theme (light/dark), default strategy parameters, chart settings, and display layout. Duration: 12 months. Category: Functional.nitix_recent— Stores recently viewed strategies, backtests, and instruments for quick access. Duration: 30 days. Category: Functional.
Legal basis: Your consent (opt-in).
3.3 Analytics / Performance Cookies
These cookies help us understand how users interact with the Platform so we can improve it. These are only set if you consent.
ph_[PLACEHOLDER: project key]_posthog— PostHog product analytics — stores an anonymous analytics identifier and session/feature-flag state to measure usage. Duration: [PLACEHOLDER: ~1 year]. Category: Analytics.ph_optout— PostHog — records that you have opted out of analytics tracking, so we do not track you. Duration: [PLACEHOLDER: ~1 year]. Category: Analytics.sentry_session— Sentry error monitoring — tracks session for error correlation. Duration: Session. Category: Analytics / Performance.sentry_replay— Sentry error monitoring — session replay for debugging user-reported issues. Duration: Session. Category: Analytics / Performance.
Legal basis: Your consent (opt-in) under GDPR / UK GDPR / Swiss revDSG. These cookies are not set until you accept analytics tracking via the consent banner. [PLACEHOLDER: Confirm the exact PostHog cookie names and durations against your deployment.]
3.4 Third-Party Cookies
These cookies are set by third-party services integrated with the Platform. We do not control these cookies directly.
Stripe (Payment Processing)
__stripe_mid— Stripe fraud prevention and payment processing. Duration: 1 year. Category: Third-Party (Necessary for checkout).__stripe_sid— Stripe fraud prevention and payment processing. Duration: 30 minutes. Category: Third-Party (Necessary for checkout).
These cookies are set when you interact with the Stripe payment form and are required for secure payment processing.
4. Cookie Categories at a Glance
- Necessary: Required for authentication (JWT), session management, CSRF protection, and consent tracking. Cannot be disabled. ~5 cookies.
- Functional: Enable personalization, theme preferences, and recently viewed items. Can be disabled. ~2 cookies.
- Analytics / Performance: Track usage patterns via PostHog product analytics and Sentry error monitoring. Set only with your consent. ~4 cookies.
- Third-Party: Set by Stripe for secure payment processing. Active only during checkout. ~2 cookies.
5. Consent Management
5.1 How We Obtain Consent
When you first visit the Platform, we display a cookie consent banner at the bottom of the screen that:
- Identifies the categories of cookies we use (Necessary, Functional, Analytics, Third-Party)
- Allows you to Accept All cookies with a single click
- Allows you to Manage Preferences to accept or reject Functional and Analytics cookies individually
- Essential/Necessary cookies cannot be toggled off as they are required for the Platform to function
- Links to this Cookie Policy and our Privacy Policy for full details
Your preference is stored in the nitix_consent cookie (and mirrored in localStorage under the key nitix:cookie-consent) and respected across subsequent visits.
5.2 Withdrawing Consent
You can change your cookie preferences at any time by:
- Clearing your browser's cookies for our domain, which will re-trigger the consent banner on your next visit
- Opening browser Developer Tools → Application → Local Storage and deleting the
nitix:cookie-consentkey - Contacting us at [PLACEHOLDER: privacy@nitix.app]
Withdrawing consent does not affect the lawfulness of processing carried out prior to withdrawal.
5.3 Do Not Track and Global Privacy Control
[PLACEHOLDER: Some browsers send a "Do Not Track" (DNT) signal. Specify how we respond — e.g., disabling analytics cookies / ignoring DNT / other.]
[PLACEHOLDER: If any cookie or technology ever constitutes a "sale" or "share" under the CCPA/CPRA, we will honor the Global Privacy Control (GPC) browser signal as an opt-out request. Confirm GPC handling with counsel.]
6. How to Disable Cookies
6.1 Browser Settings
You can control or delete cookies through your browser settings. Here are instructions for common browsers:
| Browser | Instructions |
|---|---|
| Chrome | Settings → Privacy and security → Cookies and other site data |
| Firefox | Settings → Privacy & Security → Cookies and Site Data |
| Safari | Preferences → Privacy → Manage Website Data |
| Edge | Settings → Cookies and site permissions → Manage and delete cookies |
| [PLACEHOLDER: Other browsers] | [PLACEHOLDER] |
For more detailed instructions, visit https://www.allaboutcookies.org/manage-cookies/.
6.2 Opt-Out Links for Third Parties
- PostHog (analytics): Opt out via our consent banner / cookie preferences; PostHog also honors an opt-out flag stored in the
ph_optoutcookie. See https://posthog.com/privacy - Stripe: Managed via browser cookie settings
- Sentry: Managed via browser cookie settings
- [PLACEHOLDER: Additional opt-out links for other third parties]
6.3 Effects of Disabling Cookies
Disabling certain cookies may affect the functionality of the Platform:
- Essential cookies cannot be disabled — the Platform will not function correctly without them
- Disabling analytics cookies — we will not track your usage patterns; Platform functionality is unaffected
- Disabling third-party cookies — payment processing may be impacted; some features may not work as expected
- Disabling all cookies — you will not be able to log in, maintain a session, or use the Platform
6.4 Mobile Devices
If you use our Platform on a mobile device, you can manage cookies through your mobile browser settings. [PLACEHOLDER: If a mobile app exists, describe in-app tracking controls here.]
7. Updates to This Policy
We may update this Cookie Policy periodically. Changes will be reflected by:
- Updating the "Last Updated" date above
- [PLACEHOLDER: Displaying a new consent banner if cookie categories change materially]
- [PLACEHOLDER: Sending email notification for significant changes]
8. Contact
For questions about our use of cookies:
- Email: [PLACEHOLDER: privacy@nitix.app]
- Address: [PLACEHOLDER: Principal place of business / registered agent address]
- Company: [PLACEHOLDER: Legal Entity Name]
REMINDER: This is a template document. All [PLACEHOLDER] tags must be replaced and the document must be reviewed by a qualified U.S. attorney before publication.