Cookie Policy

Last updated: 20 August 2026

This Cookie Policy explains how EchoStream SRL (“Transferify”, “we”, “us”) uses cookies and similar technologies when you visit or use our website and services. It describes what these technologies are, the categories we use, and how you can manage or withdraw your consent at any time. It should be read together with our Privacy Policy, which explains in more detail how we handle personal data.

What are cookies and similar technologies?

Cookies are small text files that a website places on your device to store information. Similar technologies include local storage (the browser’s localStorage), which lets a site keep small amounts of data in your browser between visits. Throughout this policy, references to “cookies” also cover these similar technologies unless we say otherwise.

We use both first-party technologies (set by Transferify) and third-party technologies (set by Google, our analytics and advertising-measurement provider). Third-party cookies are only used for analytics and advertising measurement, and only after you consent - see below.

Your choices: an opt-in consent model

We use an opt-in approach for non-essential cookies, and we ask about two separate purposes: analytics and advertising measurement. On your first visit, a cookie banner appears. No analytics or advertising tag is loaded from Google - not even an anonymous request - until you grant one of those purposes. The strictly necessary sign-in service described below is also operated by Google and runs regardless, because you cannot sign in without it. “Accept all” grants both; “Customize” lets you turn one on without the other; declining or ignoring the banner leaves only the strictly necessary technologies described below.

You can change your decision at any time by opening “Cookie Settings” from the “Resources” menu on our site, which re-opens the cookie preferences so you can grant or withdraw either purpose. Withdrawing takes effect immediately: we stop the Google tag from collecting anything further in that same visit and delete the Google cookies already set (_ga*, _gcl*, _gac*) - you do not have to reload or wait for your next visit. Your choice is remembered in your browser’s local storage (under the key cookie-consent-v2), not in a cookie itself. Because the record lives in your browser, clearing your browser storage will reset your choice and the banner will appear again on your next visit.

Counting your answer, and how a visit reached us

Your answer to the banner is itself counted, and that count needs no cookie and no consent. When you accept, reject, or save your own selection, we send ourselves one anonymous message saying, for each of the two purposes we ask about, whether it was granted or denied, and which control recorded it - nothing else. It sets no cookie, writes nothing to your browser storage, carries no identifier, no session and no account, and it never reaches Google or any other third party. Only the totals are kept, and nothing on our side records your individual answer.

We count it because the visitors who decline are invisible to every analytics and advertising tag by design - no tag runs to report a refusal - so a first-party count is the only way to know how many people decline. A second count works differently, and needs no cookie either. From the moment you open the site, a coarse acquisition category - one word from a closed list: paid-search, organic, social, referral or direct - travels with the requests your browser makes to our servers, alongside the sign-in token those requests already carry. We read it at exactly one moment, when an account is first established, and all we do with it is add one tick to a total for that category; on every other request it is ignored. Where the link carried one of Google’s advertising click parameters we use only the fact that one was present - its value is never read, stored or sent anywhere unless you granted the advertising purpose - and the address of the site you came from never leaves your browser. What each count contains, what is never collected for it, and the legal basis we rely on are set out in Section 11 of our Privacy Policy.

Categories of cookies we use

1. Strictly necessary (essential)

These technologies are required for the service to function and are always on. They do not require your consent because Transferify cannot operate without them. They are used to keep you signed in via Firebase Authentication (managing your login session) and to remember your own cookie-consent choice and basic application state. If you block these technologies in your browser, sign-in and core features will not work.

2. Analytics

These cookies help us understand aggregate product usage so we can improve Transferify. We use Firebase Analytics (Google Analytics 4), provided by Google. They are off by default and are only set after you click “Accept” on the cookie banner. If you decline or ignore the banner, no analytics cookies are set. Typical cookies in this category are _ga and _ga_<container>, which store a randomly generated client identifier used to measure usage in aggregate.

3. Advertising measurement

These cookies let us measure which advertising campaigns brought people to Transferify, so we do not keep paying for advertising that does not work. They are off by default and are only set after you grant the advertising purpose. What we measure is limited on purpose:

  • We record whether a visit came from a paid advertisement, from an unpaid search result, or directly, together with the page you first landed on. That record is kept against your account and is only made once you grant this purpose; the anonymous channel total described above is a separate count that carries no link to you and no landing page.
  • If you arrived from a Google advertisement, the link carries a click identifier (gclid, gbraid or wbraid). We only read its value once you have granted this purpose - if you decline, we never read the value, and use only the bare fact that such a parameter was present - and it is stored against your account for at most 90 days, then deleted.
  • We report two events to Google: that an account was created, and that an account sent its first transfer. Neither carries your email address, your account identifier or any file information.
  • We use Google’s Consent Mode with advertising personalisation permanently switched off, and we do not use remarketing, audience lists, Customer Match or Google Signals. This purpose buys measurement, not profiling.

Cookie inventory

Name / technologyProviderCategoryPurposeRough duration
Firebase Authentication session (local storage)Transferify (first-party)Strictly necessaryKeeps you signed in and manages your authenticated session.Persistent until sign-out or browser storage is cleared
cookie-consent-v2 (local storage)Transferify (first-party)Strictly necessaryRemembers your cookie-consent choice and basic app state.Persistent until you change your choice or clear browser storage
transferify.ads.firstTouch (local storage)Transferify (first-party)Advertising measurementHolds the campaign details described above until you sign in, so they can be attached to your account once. Written only if you granted a non-essential purpose.Up to 90 days
_gaGoogle (third-party)AnalyticsStores a client identifier used to measure aggregate product usage.~2 years
_ga_<container>Google (third-party)AnalyticsMaintains analytics session state for Google Analytics 4.~2 years
_gcl_auGoogle (third-party)Advertising measurementLinks an advertisement click to an action taken on the site, for conversion measurement.~90 days
_gac_<property>Google (third-party)Advertising measurementCarries campaign information for conversion measurement in Google Analytics 4.~90 days

Exact cookie names, containers and durations set by Google may vary; the values above reflect the typical behaviour of Google Analytics 4.

How to manage or withdraw consent

You can manage analytics and advertising cookies in two ways:

  • Cookie Settings on our site: open “Cookie Settings” under the “Resources” menu to re-open the preferences and grant or withdraw each purpose at any time. Withdrawing stops collection in the current visit and deletes the Google cookies already set.
  • Your browser controls: most browsers let you block or delete cookies and clear local storage. Please note that blocking essential cookies and storage will break sign-in and other core Transferify features.

Relationship to our Privacy Policy

This Cookie Policy is part of, and should be read alongside, our Privacy Policy, which explains what personal data we collect, the legal bases we rely on, how long we keep it, and the rights you have over it. Where analytics data collected via cookies constitutes personal data, its processing is described in the Privacy Policy. To erase the data held about you, see our Data Deletion Instructions.

Changes to this policy

We may update this Cookie Policy from time to time to reflect changes in the technologies we use or for legal, regulatory or operational reasons. When we make material changes, we will update the “Last updated” date above and, where appropriate, ask for your consent again through the cookie banner.

Contact

If you have questions about this Cookie Policy or how we use cookies, contact us at support@transferify.ro.