Cookie Policy
1. What this covers
This Policy explains what we store on your device when you use the sugibana.flow public website and the signed-in application, and how to control it. It supplements our Privacy Policy, which governs personal data more generally.
“Cookies” here means more than cookies. The law that applies — Article 5(3) of the ePrivacy Directive (2002/58/EC), as implemented in Lithuanian law — regulates any storing of information on, or reading of information from, your device. That includes browser localStorage and sessionStorage, which we use more than we use cookies. We have therefore listed both together rather than listing only the things technically called cookies.
Acceptance of cookies is separate from acceptance of our Terms of Service and is never bundled into it.
2. Who is responsible
The controller is Sugibana MB, a Lithuanian mažoji bendrija, company code 308103418, registered office Gelininkų g. 17, Laumėnai, LT-53135 Kauno r..
Questions about anything on this page: [email protected].
3. What we do not do
- No third-party cookies. Every item in section 4 is set by this site.
- No analytics or measurement tools. No Google Analytics, no Google Tag Manager, no product-analytics SDK, no session recording, no heatmaps.
- No advertising or retargeting tags, and no profiling or cross-site tracking of any kind.
- Nothing is stored on your first visit. Arriving on our public pages sets no cookie at all. Storage begins only when you do something that needs it.
4. The complete list
Signing in and staying signed in
- firebase-id-token — a cookie holding your sign-in token, so the server knows the request is yours. Set when you sign in; cleared when you sign out.
- Firebase authentication storage — our sign-in provider (Google Firebase Authentication) keeps your session in browser storage so you are not signed out on every reload.
- sgb:legal-accepted-… — records which version of the Terms and Privacy Policy you accepted, so you are not asked again for a version you have already agreed to. This is also our evidence of what you agreed to.
These are strictly necessary: without them you cannot sign in or stay signed in, which is the service you explicitly requested.
Remembering choices you made
- sg-ui-lang — the interface language you selected.
- sgb-public-theme and sugibana:theme — whether you chose the light or dark appearance on the public site.
- sgb-theme and sgb-brand-color — the colour theme and brand colour of your workspace, so the application renders in your colours immediately rather than flashing the default first. Signed-in users only.
- sugibana:shipping:labelSize, setup-banner-dismissed-…, sku-import-suggested:… — small in-app preferences: your label size, a banner you dismissed, a suggestion you already answered. Signed-in users only.
Each of these is written only in direct response to an action you took, and each holds a preference rather than an identifier.
Getting you through signup
- sf:onboarding-segment — which option you selected before signing up, so the signup wizard opens where you left off.
- waitlist_wt — your waitlist invitation token, carried from the invite link into the signup form.
- marketing_cmp — if you arrived through a campaign link, the campaign name, so we can tell which campaigns bring people who sign up. It is written at the moment you begin signing up, not when you arrive; it lasts only for the browser tab; it is deleted as soon as your account is created; and it contains a short campaign label and nothing about you. If you never start signup, it is never stored.
We do not claim this one is strictly necessary. It exists to measure our own marketing, not to deliver anything you asked for, and we are not going to describe it as something it is not. Whether an item like this requires your prior agreement is a question we have put to legal counsel, and we will update this page with the answer. In the meantime it is disclosed here, it is first-party, it is not shared with anyone, and section 5 explains how to prevent it.
Access control on our test site
- x-staging-key — set only on our internal staging site to remember that you entered the access key. It is never set on the public site.
5. How to control what is stored
Because we set no analytics or advertising items, we do not show a cookie banner. There is nothing behind it that we would switch off for you, and a banner implying otherwise would be misleading. Control therefore sits with your browser, where it applies to every site rather than only ours:
- Block or delete site datafor sugibana-flow.com in your browser’s privacy settings. This removes everything listed above.
- Use a private window. Everything is discarded when you close it.
- Clearing while signed in signs you out, and the application will not work until you sign in again — the items in the first group of section 4 are what keep you signed in.
If we later add anything that measures your behaviour or that a third party can read, we will ask for your agreement before it is set, and this page will say so first.
6. Changes to this Policy
The version at the top changes whenever this Policy does. Because the list in section 4 is a description of software, it is reviewed when that software changes — in particular, no third-party script, analytics tool or advertising tag may be added without this page and the consent position being updated in the same change.
7. Contact
[email protected]. If you are in the EEA or the UK you may also complain to your national data-protection authority; ours is the State Data Protection Inspectorate of Lithuania.
