Legal

Cookie & Tracking Policy

Last updated: 18 September 2026

1. Purpose

This Cookie & Tracking Policy explains how Vesonus AS uses cookies, local storage, pixels, tags, similar browser technologies and related identifiers on vesonus.com and, where applicable, vesonus.app.

It should be read together with the Vesonus Privacy Policy and Terms of Service.

2. Who we are

Vesonus AS

Kjellergata 17A

2003 Lillestrøm

Norway

Org. no. 935 677 335

Privacy and legal contact: support@vesonus.com

Platform-specific support: support@vesonus.app

3. What these technologies are

Cookies are small text files stored on a device. Similar technologies include local storage, pixels, SDKs, tags, browser identifiers and server-side event identifiers.

These technologies can be used for essential functionality, security, preferences, analytics, attribution, advertising measurement and service improvement.

4. Consent principle

Vesonus intends to obtain consent before using non-essential analytics or advertising tracking where required by applicable law.

Essential technologies may operate without optional consent where they are necessary to provide a service explicitly requested by the user, protect security, maintain authentication, remember privacy choices or perform another legally permitted essential function.

Users should be able to reject optional analytics and advertising tracking without losing access to the core service.

5. Consent categories

Vesonus currently uses the following consent model:

5.1 Essential

Always active where necessary. Examples may include authentication, security, fraud prevention, session continuity, consent-state storage and other core service functions.

5.2 Analytics

Used to understand how people use Vesonus, measure performance, identify product issues and improve the website or platform. Analytics should activate only after the required consent is obtained.

5.3 Advertising / measurement

Used to attribute campaigns, measure ad performance and support advertising-platform conversion reporting. Advertising measurement should activate only after the required consent is obtained.

6. Current launch measurement providers

Subject to the final production configuration and consent choices, Vesonus may use:

• Google Analytics 4 (GA4) for website/app analytics;

• Meta Pixel and related Meta measurement tools;

• TikTok Pixel and related TikTok measurement tools; and

• OpenAI/ChatGPT Ads browser measurement and related conversion tools where advertiser access is available.

The exact technologies, identifiers and provider roles must be verified against the live production configuration before this Policy is published.

7. Cross-domain attribution

Vesonus uses vesonus.com as the marketing website and vesonus.app as the authenticated platform.

Where consent permits, limited attribution information may be carried from vesonus.com to vesonus.app so that Vesonus can understand whether a registration, trial or paid conversion came from a marketing campaign.

This may include UTM parameters and supported advertising click identifiers.

When advertising consent is absent, advertising identifiers such as gclid, fbclid, ttclid, oppref or similar identifiers should not be retained or transferred unless a separate lawful basis clearly applies.

8. First-touch attribution

Vesonus may store limited first-touch campaign information so that a later signup can be attributed to the original campaign source.

Working retention target: up to 13 months, subject to final technical verification and applicable law.

9. Analytics retention

Working retention target for analytics event/user data is up to 14 months where the relevant provider supports that setting.

Provider-level retention and deletion behavior can differ. Public wording must match actual configured settings at launch.

10. Provider-specific notes

10.1 Google Analytics

GA4 may process device, browser, session, event and attribution information. Vesonus should configure GA4 consistently with the approved consent model and avoid sending data that should not be collected without consent.

10.2 Meta

Meta measurement may use browser identifiers, click identifiers, event data and, where separately approved, supported server-side conversion data. Browser and server copies of the same event should use a shared event identifier where deduplication is supported.

10.3 TikTok

TikTok measurement may use browser identifiers, click identifiers and conversion-event information. Browser and server event copies should follow provider-supported deduplication rules.

10.4 OpenAI / ChatGPT Ads

Where available, OpenAI/ChatGPT advertising measurement may use browser and conversion-event information. Any cross-domain attribution or server-side measurement must follow the shared Vesonus measurement contract and consent rules.

11. Server-side measurement

Some conversion events may be sent from Vesonus servers to advertising providers where this improves measurement reliability and is lawful.

Server-side transmission does not bypass consent requirements. If an event depends on advertising consent, Vesonus should not send it merely because it is transmitted from the server rather than the browser.

For providers that support event deduplication, overlapping browser/server copies should share the same event ID.

GA4 should not receive duplicate generic browser and server copies where no reliable general event-ID deduplication mechanism exists.

12. Consent controls

Users should be able to:

• accept optional categories;

• reject optional categories;

• manage analytics and advertising preferences separately where the consent interface supports this; and

• withdraw consent later as easily as reasonably possible.

Withdrawing consent should prevent future optional tracking. It does not make prior lawful processing unlawful.

13. Consent records

Vesonus may retain limited records showing that a user made a privacy choice, including the choice, date/time, policy or consent version and relevant technical context.

These records may be retained for a reasonable compliance period so Vesonus can demonstrate that consent choices were respected.

14. Browser controls

Users can also manage or delete cookies through browser settings. Blocking all cookies may affect functionality that relies on strictly necessary storage.

15. Do Not Track and similar signals

Browser privacy signals are evolving. Vesonus should honor legally required signals where applicable and should not claim support for a specific signal until that behavior is implemented and verified.

16. No dark patterns

Vesonus should not make rejection materially harder than acceptance, use misleading consent wording, preselect optional categories where prohibited, or make access to the core service conditional on optional advertising consent.

17. Third-party websites and services

Links, embeds or third-party services may place their own technologies when a user interacts with them. Their privacy practices are governed by their own policies unless Vesonus controls the processing.

18. Changes to providers

Vesonus may add, remove or replace analytics, advertising, infrastructure or communications providers as the product evolves.

Before enabling a new non-essential tracking provider, Vesonus should assess consent, disclosure, legal-basis, data-transfer and retention requirements and update this Policy where necessary.

19. Relationship to creator websites

Creator websites hosted through Vesonus may have separate public-site analytics rules. Launch V1 should not assume creator-specific marketing trackers are enabled. Any creator-site tracking that requires consent must use an appropriate consent mechanism before activation.

20. Contact

Questions about cookies, tracking or consent can be sent to support@vesonus.com.