Legal

Cookie Policy

Last updated · Applies to Tagjet and the api.tagjet.app API

Tagjet stores one strictly necessary cookie to keep you signed in and – only if you accept it – Google Analytics on the website and in the dashboard, so we can see which pages people read, which parts of the dashboard they use, and whether visitors go on to create an account. There is no advertising and no cross-site tracking.

Nothing is written to your browser and nothing is sent to Google until you answer the banner shown on your first visit. Before you answer, the analytics tag is not merely set to “denied” – it is not loaded at all. Your answer covers both https://tagjet.app and the dashboard, and you can change it at any time from the Cookie settings control – in the footer of every page of the website and the documentation, and at the bottom of the dashboard sidebar.

1. What this policy covers

This policy describes what Tagjet stores on your device when you visit https://tagjet.app or use the dashboard, and the choices you have. It supplements the Privacy Policy. It does not apply to the API itself – API requests are authenticated with an API key and set no cookies at all.

The same boundary applies to measurement. Analytics runs in your browser, on the website and in the dashboard. It sees how the interface is used, not what you send through it: no Document sent to the API, and nothing extracted from one, is ever passed to an analytics provider.

2. What we store on your device

What is stored depends on the answer you give the consent banner on your first visit. Nothing in the analytics group below exists until you accept it.

ItemTypeWhy it existsHow longCategory
tj_refreshHTTP cookie (httpOnly, Secure, SameSite)Keeps you signed in to the dashboard by allowing a new access token to be issued without re-entering your password.Up to 14 days; cleared when you sign out.Strictly necessary
Access tokenIn-memory only (JavaScript variable)Authenticates dashboard requests during the current page session.Discarded when the tab is closed or reloaded. Never written to disk.Strictly necessary
tj_consent_v1Local storage entryRecords whether you accepted or declined analytics, and when, so we can honour your answer without asking again on every page.No expiry of its own; removed when you clear site data for this domain.Strictly necessary
_gaHTTP cookie (first-party, Secure)Set by Google Analytics. Holds a randomly generated identifier for your browser so that repeat visits are counted as one visitor rather than several.Two years from your most recent visit.Analytics – only if you accept
_ga_<container id>HTTP cookie (first-party, Secure)Set by Google Analytics. Holds session state and a session counter for the Tagjet property.Two years from your most recent visit.Analytics – only if you accept
tj_attr_v1Local storage entryRecords how you first reached us – the page you landed on, the referring site, and any campaign parameters in the address – so we can tell whether an account came from the marketing site.Ninety (90) days from when it is written.Analytics – only if you accept

Before you answer, the marketing site writes nothing at all. Your answer itself is then recorded – if you decline, the tj_consent_v1 record is the only thing left behind, and it exists so that we do not ask you again on every page.

3. Strictly necessary storage and lawful basis

The sign-in cookie, the in-memory access token and the record of your consent choice are strictly necessary – the first two to deliver a service you have explicitly requested, and the third to honour the answer you gave. Under the ePrivacy Directive as implemented in Latvian law, strictly necessary storage does not require prior consent, so these three are set without asking. The associated processing of personal data rests on the performance of our contract with you (Art. 6(1)(b) GDPR), and, for the consent record, on our obligation to be able to demonstrate that consent was given (Art. 7(1) GDPR).

4. Analytics, and the consent that gates it

With your consent, and only then, we use Google Analytics 4 on https://tagjet.app and in the dashboard to understand how they are used – which pages are read, which links are followed, which parts of the dashboard are used, and whether a visitor goes on to create an account. Our provider for this purpose is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acting as our processor under Google’s data processing terms.

Until you accept, the analytics tag is not on the page. This is stronger than it sounds: every Consent Mode v2 signal – analytics, functionality, personalisation, and all three advertising signals – is set to “denied” before anything else runs, and the Google script itself is never fetched, so no request reaches Google and no identifier is created. Accepting loads the script and switches the analytics and functionality signals to granted. The three advertising signals stay denied permanently; no code path in either application grants them.

Storing and reading the analytics cookies rests on your consent under the ePrivacy Directive as implemented in Latvian law, and the processing of the resulting personal data on Art. 6(1)(a) GDPR. You may withdraw that consent at any time – see Your choices below – without affecting anything processed before you did.

What is sent to Google Analytics:

  • the address and title of the page, the page you came from, and the time of the visit. On https://tagjet.app the address is the one in your address bar, including any campaign parameters; in the dashboard it is rebuilt from the path alone, so nothing in the query string is sent – see the guarantee below;
  • an approximate location – country and city – derived from your IP address, which is not retained in the analytics records;
  • your device and browser type, screen size, and the language your browser asks for;
  • the randomly generated identifier held in the _ga cookie, which is not linked to your name or email address;
  • once you sign in, your internal Tagjet account identifier – a random UUID – so that a visit and the account it belongs to are counted once rather than twice, together with whether that account is a normal user or an administrator;
  • which actions you take, as a fixed list of events with a small number of low-cardinality parameters. On https://tagjet.app and in the documentation: the call-to-action, navigation, legal or documentation link you followed, the plan a pricing card refers to, and the address you clicked to email us; which section of the page was on screen when you did it, and which sections came into view as you scrolled; opening or closing the documentation menu, moving between guides, and copying one of the code samples – which sample, in which language, and how long it was;
  • in the dashboard: signing up, signing in and out, a session being restored or expiring, verifying an email, requesting and completing a password reset, and enabling or disabling two-factor authentication; creating or revoking an API key, and that a key was pasted into the interactive console – that it happened, never the key itself; selecting a plan and its price and currency, starting checkout, whether you came back from Stripe having completed or cancelled it, and opening the Stripe billing portal; crossing 80% or 100% of your monthly included scans; opening a scan or its stored image; and which kind of filter you applied to the scan list – a search, a status or a date – never what you typed into it;
  • in both: opening the cookie settings, and the answer you give the banner. When one of the actions above fails we send the error code – a short server-defined value such as UNAUTHORIZED or RATE_LIMITED – never the message;
  • how you first reached us, if the record described as tj_attr_v1 above exists: the page you landed on, the referring site and any campaign parameters in the address, sent with the sign-up and sign-in events so we can tell whether an account came from the marketing site.

Once you sign in, the events above are associated with your account identifier. That means Google can see, against that pseudonymous identifier, which subscription tier an account looked at or chose and what it costs, how far through checkout it got, how much of its monthly quota it has used, when two-factor authentication was turned on or off, and that API keys were created or revoked. It cannot see who you are: no name, no email address, and no content from any Document.

We never send Google your name, your email address, an API key, an access or refresh token, the contents of any Document, anything extracted from one, or anything you type into a search box. That is a property of how the measurement is built rather than a promise applied afterwards, and it takes two mechanisms rather than one. First, the events are a fixed list and none of them carries those fields. Second, the address reported with every event from the dashboard is rebuilt from the page path: the query string is dropped and an identifying path segment is replaced by a placeholder. That matters because a verification or password-reset link carries a single-use token in its address, and an analytics tag reads that address from the browser on every event it sends, not only when the page opens. Following a link from one of those screens back to this site is the same problem in reverse, so the page you came from is put through the same reduction before the arriving page view is sent.

Google Ireland Limited may pass the data to Google LLC in the United States and to Google’s own sub-processors. That transfer is covered by the Standard Contractual Clauses incorporated into Google’s data processing terms and by Google LLC’s certification under the EU–US Data Privacy Framework.

The cookies expire two years after your most recent visit. The event-level records behind our reports are kept for no longer than fourteen (14) months and are then deleted by Google automatically; aggregated reports that identify nobody may be kept longer. Declining, or deleting the cookies, stops new records being created.

5. What we still do not use

Beyond the measurement described above, Tagjet runs no advertising and no cross-site tracking. Specifically, we do not use:

  • advertising, retargeting or conversion pixels from any network;
  • social media tracking widgets or embedded share buttons that phone home;
  • session recording, heat mapping, or device fingerprinting – the section-level reading signal described above is the identifier of a section that came into view, not a recording of your pointer, your keystrokes or your screen;
  • A/B testing or personalisation tools that store an identifier;
  • Google Signals, ads personalisation, or a link between our analytics property and any Google advertising account – the features that would let this data be joined across sites and devices, or used to target advertising, are switched off in the property and denied in the tag.

If this ever changes we will update this policy, give notice, and – where the law requires it – ask for your consent before setting anything non-essential.

6. Third-party and browser-set technologies

Every item in the table above is first-party: it is written under https://tagjet.app by code running on our own origin, and no other site can read it. Who the data reaches is a separate question, and there are three answers:

  • Google Analytics. The measurement script is loaded from a Google domain and the events described above are sent to Google. The cookies are ours; the recipient is not. This happens only after you accept.
  • Stripe Checkout and the billing portal. When you start a subscription you are taken to a page hosted by Stripe, which sets its own cookies for payment processing and fraud prevention under Stripe’s privacy policy.
  • The interactive API console. The documentation loads its console bundle from our own origin; it sends requests only to api.tagjet.app using the key you supply.

Your browser may also store items for its own reasons – HTTP cache entries, autofill data, saved passwords – which are controlled by your browser, not by us.

7. Your choices

Analytics is off until you turn it on, and you can change your mind at any time. A “Cookie settings” control reopens the same banner with your current choice marked: on https://tagjet.app and the documentation it sits in the footer of every page; in the dashboard it sits at the bottom of the navigation sidebar, and beneath the sign-in, sign-up and password screens. It is never more than one navigation away from wherever you are. Art. 7(3) GDPR requires withdrawing consent to be as easy as giving it, which is why the two buttons in the banner are the same size and one click apart.

Declining after you had accepted takes effect immediately and without reloading the page: nothing further is sent, collection is disabled for the rest of the visit, and the _ga and _ga_<container id> cookies are deleted from your browser. The record of how you first reached us expires ninety (90) days after it was written, and clearing your site data removes it sooner.

One answer covers both https://tagjet.app and the dashboard. They are served from the same origin and share a single stored record, so accepting on the marketing site does not produce a second banner when you sign in, and withdrawing in either place reaches any tab you have open on the other.

You can also clear or block cookies in your browser settings at any time, or install Google’s opt-out browser add-on to stop Google Analytics on every site you visit. Because the sign-in items are strictly necessary, blocking them means you will be signed out on every page load and the dashboard will not be usable. The marketing site and the public documentation will still work.

Signing out clears the refresh cookie immediately. Deleting your account removes the associated server-side session records.

8. Backups, verification and no uptime guarantee

Nothing in this policy changes your responsibilities under the Terms: keep your own copies of Documents and results, verify Extracted Data before relying on it, and note that we do not guarantee any level of uptime absent a separate written service-level agreement.

9. Disclaimers and limitation of liability

The Service is provided “as is” and “as available”. Our total aggregate liability is capped at the greater of the fees you paid in the preceding twelve months or EUR 100, and we exclude indirect and consequential loss, as set out in §14 of the Terms, which governs in the event of any inconsistency. Nothing excludes liability that cannot lawfully be excluded.

10. Governing law

This policy is governed by the laws of the Republic of Latvia, with the courts of the Republic of Latvia having exclusive jurisdiction, without prejudice to mandatory consumer protections.

11. Changes and contact

We will update this policy if what we store changes, and the “last updated” date above always reflects the current version. Questions: privacy@tagjet.app, or SIA "MICRON", Aldaru iela 36/38 – 21, Liepāja, LV-3401, Latvia.

Who you are contracting with

Legal entity
SIA "MICRON", a sabiedrība ar ierobežotu atbildību (limited liability company)
Registration number
42103081578
Registered
7 November 2017, Republic of Latvia
VAT number
LV42103081578
Registered address
Aldaru iela 36/38 – 21, Liepāja, LV-3401, Latvia
Trading as
Tagjet (https://tagjet.app)

General enquiries support@tagjet.app · Privacy and data-protection enquiries privacy@tagjet.app