COOKIE POLICY

Version 1.0 – 2025-07-14


1 Scope and controller

This Cookie Policy explains how JadenX GmbH (trading as 'cntrctrs', 'we', 'our'), Kegelbahnstr. 10, 67753 Reipoltskirchen, Germany (Amtsgericht Kaiserslautern HRB 205783B, VAT DE323821525, e‑mail info@entaingine.com), uses cookies and comparable technologies on cntrctrs.com (the "Service").

Unless stated otherwise, JadenX GmbH is the controller within the meaning of Art 4 No 7 GDPR.


2 Cookies and similar technologies

"Cookies" are small text files that a website stores on a visitor’s device and that the browser returns on subsequent visits. Technologies such as localStorage, sessionStorage, tracking pixels, web beacons and tags serve comparable purposes. In this notice, "cookie" is shorthand for all such technologies.

Legal framework. Reading or writing information on end‑user devices is governed by Art 5 (3) ePrivacy Directive, transposed in Germany via § 25 TTDSG. Where a cookie involves processing of personal data, the GDPR applies in parallel.


3 Why we use cookies

CategoryPurposeLegal basis (GDPR)Default state
Strictly necessaryProvide the Service and keep it secure (authentication, CSRF‑protection, load balancing)Art 6 (1)(b) contract or Art 6 (1)(f) legitimate interestAlways active – § 25 (2) TTDSG
AnalyticsUnderstand and improve how visitors interact with the Service (Google Analytics, Vercel Analytics, Posthog)Art 6 (1)(a) consentDisabled until opt‑in
Marketing / AdvertisingMeasure campaign performance, build audiences and serve relevant ads (LinkedIn Insight Tag, X Pixel, Google Ads Tag)Art 6 (1)(a) consentDisabled until opt‑in

Non‑essential cookies are never set before you give consent. 'Accept all' and 'Reject all' are equally prominent. The banner is implemented with react-cookie-consent.


4 Detailed cookie list

Audit date: 2025‑07‑14 – we re‑scan quarterly and update this table as required.

4.1 Strictly necessary

NameProvider / DomainPurposeExpiryHttpOnlySecureSameSite
cntrctrs-cookie-consentcntrctrs – cntrctrs.comStores your cookie consent preferences12 mo✔︎Lax
sb-*-auth-tokenSupabase – *.supabase.coAuthentication session tokenSession✔︎✔︎Lax

4.2 Analytics – loaded only after consent

NameProviderPurposeDefault expiry
ph_<project_api_key>_posthogPostHogDistinct ID, session ID, feature‑flag state12 mo
_gaGoogle Analytics 4Distinguishes users24 mo
_ga_<container-id>Google Analytics 4Persists session state24 mo
_gidGoogle Analytics 4Distinguishes users per day24 h

PostHog also writes to localStorage for feature‑flags. LocalStorage is cleared when you withdraw consent.

4.3 Marketing / Advertising – loaded only after consent

NameProviderPurposeDefault expiry
personalization_idX (Twitter)Ad personalisation & analytics24 mo
guest_id_adsX (Twitter)Identifies devices for ads when logged‑out24 mo
bcookieLinkedIn Insight TagBrowser ID for fraud detection & ads12 mo
lidcLinkedIn Insight TagDatacentre selection & load balancing24 h
li_gcLinkedIn Insight TagStores guest consent for non‑essential cookies6 mo
li_fat_idLinkedIn Insight TagMember indirect identifier for conversions30 d
IDEGoogle Ads (doubleclick.net)Stores ad preferences & user ID13 mo
__gadsGoogle AdsMeasures interactions with ads & prevents duplicate displays13 mo
_gcl_auGoogle Ads / Tag ManagerStores Google Click ID (GCLID) for conversion tracking90 d
test_cookieGoogle Ads (doubleclick.net)Tests if the browser supports cookies15 min

5 Consent mechanism & withdrawal

Our banner:

  • Loads only strictly necessary cookies by default.
  • Shows “Accept all” and “Reject all” with equal prominence, plus category toggles and a “Save preferences” button.
  • Stays visible until you make a choice.
  • Stores decisions in the cookie_consent cookie for 12 months.
  • Can be reopened at any time via Cookie Settings in the footer.

Withdrawing consent deletes analytics/marketing cookies and blocks the associated scripts.


6 International data transfers

  • PostHog EU Cluster is hosted in Frankfurt/Stockholm – no data leaves the EEA.
  • Google LLC, X Corp. and LinkedIn Corp. may process data in the United States. Transfers rely on:
    • certification under the EU–US Data Privacy Framework (DPF),
    • Standard Contractual Clauses (SCCs), and
    • documented Transfer Impact Assessments.

Copies of the SCCs are available on request.


7 Storage duration & deletion

We keep personal data derived from cookies no longer than necessary. Analytics events are truncated or aggregated after 25 months at the latest. Marketing identifiers are deleted once a campaign ends or after 30 days of inactivity, whichever comes first.


8 Your rights

You may exercise the rights in Art 15–22 GDPR (access, rectification, erasure, restriction, portability, objection, automated decision‑making) at any time. See our Privacy Policy for details.


9 Changes to this policy

We review this notice at least quarterly. Material changes (e.g. adding a new marketing pixel) trigger a renewed consent request.

Last update: 2025‑07‑14


10 Contact

Data Protection Officer
JadenX GmbH
Kegelbahnstr. 10
67753 Reipoltskirchen, Germany
info@entaingine.com

You may also lodge a complaint with the State Commissioner for Data Protection and Freedom of Information Rhineland-Palatinate (Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz).