Cookie Policy
Effective date: 28 June 2026 Last updated: 1 October 2026
This Cookie Policy explains how Maven Advertising SRL (operating the ReviewMix service, "ReviewMix", "we") uses cookies and similar technologies on our own websites: reviewmix.eu, app.reviewmix.eu and other subdomains of reviewmix.eu operated by us.
This policy does not apply to customer websites that embed the ReviewMix widget. How those sites use cookies is their own responsibility; see Section 7 below.
1. What cookies are
Cookies are small text files stored on your device by your browser when you visit a website. They allow the site to remember information about your visit. Similar technologies include local storage, session storage, pixels, and web beacons. In this policy we use "cookies" to refer to all of these.
2. Categories of cookies we use
We group cookies by purpose. For each, we state whether it requires your consent.
2.1 Strictly necessary — no consent required
These are essential to provide the service you have requested. They cannot be disabled.
| Name | Purpose | Duration | Set by |
|---|---|---|---|
reviewmix_session | Authenticated session (opaque token, not a JWT) | 30 days (sliding) | ReviewMix |
csrf_token | CSRF protection (double-submit cookie pattern). Compared against X-CSRF-Token header on state-changing requests; mismatch returns 403. Not HttpOnly — JavaScript reads the value to populate the request header. | Session (Max-Age tied to session lifetime) | ReviewMix |
gbp_oauth_state | OAuth CSRF protection for the Google Business Profile connect flow. Holds a session-bound, single-use signature verified when Google redirects back to /api/auth/google/callback; cleared on every callback. HttpOnly, path-scoped to /api/auth/google. | 10 minutes (single connect attempt) | ReviewMix |
signin_oauth_state | CSRF protection for the optional "Sign in with Google" flow. Holds a keyed digest of a one-time value that the callback recomputes and compares. HttpOnly, path-scoped to the sign-in handlers. | 10 minutes (single sign-in attempt) | ReviewMix |
signin_pending | Carries the in-progress sign-in between the start of the Google flow and its completion. HttpOnly, same path scope and lifetime as the cookie above. | 10 minutes (single sign-in attempt) | ReviewMix |
reviewmix_business | Remembers which of your businesses the dashboard is currently showing, after you pick one. HttpOnly. Exempt as a user-input cookie: it records a selection you made inside the service and does nothing else. | Until you close your browser | ReviewMix |
rm_onboarding_dismissed | Records that you dismissed the setup guide, so it stays dismissed. Exempt on the same user-input ground. | 30 days | ReviewMix |
reviewmix.notices.dismissed (browser local storage, not a cookie) | Inside the app dashboard: dashboard notices you dismissed that come back after a while, and when you dismissed them, so they stay away until then. Holds notice names and dates only. Not tied to your account and not deleted when you sign out. Exempt on the same user-input ground. | Until you clear your browser storage | ReviewMix |
reviewmix.draft.replies.<account id> (browser local storage, not a cookie) | Inside the app dashboard: the text of a reply to a Google review that you started and have not sent yet, from the reviews list or the conversations inbox, so it is still there if the page reloads or you come back to it. Deleted when you send or discard the reply, and when you sign out. Exempt on the same user-input ground: it keeps only what you typed, on your device. | 7 days from your last change | ReviewMix |
reviewmix.draft.widget.<account id> (browser local storage, not a cookie) | Inside the app dashboard: widget settings you changed and have not saved yet, so you can restore or discard them when you come back. Never saved to your widget unless you save it. Deleted when you save or discard, and when you sign out. Same ground. | 7 days from your last change | ReviewMix |
reviewmix.draft.onboarding.<account id> (browser local storage, not a cookie) | Inside the app dashboard: the Google locations you ticked, unticked or gave a website address while adding businesses, with the website address beside each one, so they survive a reload. Nothing is connected until you press the button. Deleted when the businesses are added, and when you sign out. Same ground. | 24 hours from your last change | ReviewMix |
reviewmix.draft.printables.<account id> (browser local storage, not a cookie) | Inside the app dashboard: the text, colours and design options you chose for printed QR material, per business and format, and the share message and the colour of a business's QR code. Your logo is not stored. Deleted when you put them back to the defaults, and when you sign out. Same ground. | 7 days from your last change | ReviewMix |
reviewmix_consent | Remembers your cookie-consent choices across the marketing site and the app; set before any opt-in, including to remember a refusal | 12 months | ReviewMix; .reviewmix.eu, Path=/, SameSite=Lax, Secure |
reviewmix-cookie-consent (browser local storage, not a cookie) | The previous home of your cookie-consent choice, on the marketing site only. It is read once on your next visit, copied into the reviewmix_consent cookie above, and then deleted. It is listed because this policy covers local storage as well as cookies (Section 1), and because it is not always short-lived: if your browser refuses the cookie, this entry is deliberately kept, since it would otherwise be the only record of a choice you already made | Until it is copied into the cookie above — normally your next visit; kept if your browser blocks cookies | ReviewMix |
2.2 Functional — consent required
These remember preferences you have set. They are not essential.
We set no optional preference cookies. Two cookies do remember something you chose — which business the dashboard shows, and that you dismissed the setup guide — and both are listed in Section 2.1, because each only records a selection you made inside the service and neither is used for anything else. The same ground applies to the dashboard's local-storage entries listed there: dismissed notices, and the drafts that keep your unsent replies, unsaved widget settings, onboarding choices and printables options on your device until you finish, discard or reset them, or sign out. The functional category is still offered on the banner and your answer is still recorded: it decides whether we tell Google Analytics that functionality and personalisation storage are permitted, and it governs any genuine preference cookie we add later. If we add one, it is listed here before it is set.
2.3 Analytics — consent required
With your analytics consent, we use PostHog Cloud EU, provided by PostHog Inc., for product analytics on our marketing site, reviewmix.eu, and Google LLC for Google Analytics 4 (GA4) on the same site. PostHog also runs inside the app dashboard at app.reviewmix.eu, on the same analytics choice: the app reads the choice you made on reviewmix.eu, and shows the same consent banner only when no choice is stored on your device — for example after signing up directly, on a new device or in a private window. A choice already stored is not asked for again. It does not run on the app pages used by people who are not our customers — testimonial collection pages, self-service links and the sign-in page. PostHog stores data in Frankfurt, EU; PostHog Inc. is a US recipient covered by Standard Contractual Clauses (SCCs).
Session replay is part of the analytics category: PostHog records interactions and a reconstruction of the page. What you type into a form field is always masked. On reviewmix.eu, which shows only our own content, the rest of the page's text is recorded as it appears, except a help-centre search that the page repeats back to you, which stays masked. Inside the dashboard, whose pages show our customers' own data — testimonials, reviews and the names of the people who wrote them — page text is masked except our own interface text, such as navigation, headings, labels and buttons, which we mark as readable one element at a time. Any text we have not marked stays masked, so our customers' data, and the figures and dates shown from their accounts, stay masked. Replay blocks every image on both sites. Inside the dashboard it also masks element attributes, and every page address and link is sent without its query string, which is where a search you type would otherwise appear. PostHog identifies your browser only by an anonymous, randomly generated identifier. If you have allowed analytics on reviewmix.eu in the same browser, the dashboard can pick up the identifier from that visit, so both sites can count your browser once rather than twice. We do not send PostHog your name, your email address or your account identity, and we do not link that anonymous identifier to your ReviewMix account.
PostHog client requests use our own first-party /ingest path, which forwards to PostHog's EU services; this changes the network path while PostHog Inc. remains the third-party recipient.
Some analytics does not come from your browser at all. With the same analytics consent, our servers send PostHog a small number of events recording that a step you took reached a defined point — an account created, a sign-in completed, a checkout started, an account closure requested. Our server reads your analytics choice from the reviewmix_consent cookie listed in Section 2.1, and the anonymous identifier from the PostHog cookie listed in the table below. It writes nothing to your device, and sends nothing at all when the choice is absent, unreadable or refused, or when that identifier is missing — we do not create one in order to send an event. Because they add no storage, these events appear in no row of the table below. They are also the one case where something is recorded about pages the analytics library never runs on, such as sign-in and sign-up: we record that the step finished, and nothing about the page itself.
| Name | Purpose | Duration | Set by |
|---|---|---|---|
ph_<project-key>_posthog | Holds the anonymous identifier PostHog uses to tell one browser from another, and the state that ties your interactions to a single visit | 12 months | PostHog Inc., through ReviewMix |
ph_<project-key>_posthog (browser local storage, not a cookie) | The same anonymous identifier, kept a second time in your browser's local storage, which is how the analytics library is built to store it | Until you clear it or withdraw consent | PostHog Inc., through ReviewMix |
ph_<project-key>_window_id, ph_<project-key>_primary_window_exists and ph_<project-key>_posthog (browser session storage, not cookies) | Tell one browser tab from another and hold the current visit's state, so a visit opened in several tabs is not counted as several visits | Until you close the tab; also deleted when you withdraw consent | PostHog Inc., through ReviewMix |
ph_<project-key>_session_registered_properties (browser session storage, not a cookie) | A list of the names of the diagnostic settings the analytics library used for this visit — for example whether session recording started and why. It contains no identifier and nothing about you | Until you close the tab. Unlike the entries above it may be written once more after you withdraw consent, so we do not promise it is removed at that moment | PostHog Inc., through ReviewMix |
__ph_opt_in_out_<project-key> (browser local storage, not a cookie) | Remembers that you REFUSED analytics, so we do not start PostHog again on your next visit. Set only if you refuse, and deliberately kept when you withdraw — deleting it would make us forget your refusal | Until you clear your browser storage | ReviewMix |
_ga | Tells one marketing-site visitor from another | 2 years | Google LLC, through ReviewMix |
_ga_<container-id> | Keeps Google Analytics session state on the marketing site | 2 years | Google LLC, through ReviewMix |
These analytics cookies and the equivalent browser storage require your consent under Art. 5(3) ePrivacy Directive and Art. 6(1)(a) GDPR. PostHog is not started, and session replay does not record, until you opt in. The Google tag on the marketing site is loaded with every storage permission denied. Until you opt in it writes nothing to your device — no cookie, no other identifier. The pings it sends still reach Google LLC carrying your IP address and browser user-agent, as any request to a server does, and Google uses them for an estimated, non-cookie measurement. An IP address is personal data, so we say so plainly rather than calling these pings anonymous.
2.4 Advertising — we do not use any
We do not use advertising cookies. We do not share data with ad networks. The banner offers an advertising category and records your answer, and the advertising permissions we pass to Google are refused for everyone regardless of what you choose there. If that ever changes, this policy is updated and your recorded choice is honoured before any advertising cookie is set.
2.5 Third parties that receive data from our sites
Some cookies are set by a third party directly; others are set by our own code on our own domain, but the data they carry reaches a third party. Both are listed here:
- Stripe checkout (only when you initiate a paid upgrade) — required for secure payment processing and fraud prevention. Governed by Stripe's own cookie policy.
- Cloudflare — may set a
__cf_bmcookie for bot detection as part of service delivery. Categorised as strictly necessary. - PostHog Inc. — product analytics and masked session replay after analytics opt-in; first-party cookies and browser storage as listed under “Analytics — consent required”.
- Google LLC — GA4 on the marketing site; analytics cookies after analytics opt-in, and cookieless measurement pings while you have not yet answered the banner. Section 4 gives our basis for those and how to stop them.
3. Your choices
3.1 On first visit
You see a consent banner with two buttons and a preferences control:
- Accept all — every category enabled
- Deny — only the strictly necessary cookies in Section 2.1 are used
- a preferences control, which opens the categories so you can allow functional, analytics and advertising separately
Accepting everything and refusing everything both take one click.
Nothing writes an analytics or advertising cookie, or any other identifier, on your device before you decide. One thing does happen before you decide, and we would rather state it than bury it: on the marketing site the Google tag loads in a fully denied state and sends Google measurement pings that set nothing on your device. Section 2.3 says what those contain.
Your preference is stored for 12 months in the reviewmix_consent cookie on .reviewmix.eu, shared by the marketing site and the app. The app dashboard shows the same banner, with the same buttons, when that cookie holds no choice; once it does, neither site asks again.
3.2 Changing your preferences later
You can change or withdraw your choices at any time from the floating cookie button on reviewmix.eu, which reopens the banner. Inside the app dashboard, Cookie settings in the account menu opens the same choices and changes them in the same place. Withdrawing analytics consent, in either place, stops further collection. The identifiers listed in Section 2.3 are deleted at once from the site where you withdraw; the marketing site and the app each keep their own copy in browser storage, and the other deletes its copy the next time you open reviewmix.eu or the app dashboard.
3.3 Browser-level controls
You can also control cookies through your browser settings. Most browsers allow you to:
- Block all cookies
- Block third-party cookies
- Delete cookies on exit
- Block cookies from specific sites
Blocking strictly necessary cookies may prevent the service from functioning.
4. Legal basis
- Strictly necessary cookies: Art. 5(3) ePrivacy Directive exemption; no consent required
- Analytics cookies and storage (PostHog and GA4), including PostHog session replay: your consent under Art. 6(1)(a) GDPR and Art. 5(3) ePrivacy Directive
- The Google tag's measurement pings, sent only while you have not yet answered the banner: these store and read nothing on your device, so Art. 5(3) ePrivacy does not apply to them. For the IP address and browser information they do carry, our basis is legitimate interest under Art. 6(1)(f) GDPR — our interest in knowing how many people reach the site and by what route, weighed against your interest in not being measured before you have answered. Because this rests on legitimate interest you have the right to object (Art. 21). Refusing analytics on the banner stops them from the next page you load, provided your browser lets us store the refusal, and we aim to stop them on the page where you refuse as well. You can also write to privacy@reviewmix.eu. No identifier is stored on your device, and we send Google a refusal on all three advertising permissions for every visitor, whatever they choose.
- All other non-essential cookies (functional): your consent under Art. 6(1)(a) GDPR and Art. 5(3) ePrivacy Directive
Refusing consent does not affect your ability to use our marketing website or sign up for an account.
5. How long cookies last
Session cookies expire when you close your browser. Persistent cookies last for the durations shown in the tables above.
You can delete any cookie at any time via your browser.
6. Changes to this policy
We may update this policy to reflect changes in our use of cookies or in applicable law. The current version is always at app.reviewmix.eu/legal/cookie-policy. Material changes are notified via the consent banner. Customers are separately notified by email before a change to our sub-processors takes effect, as described in our sub-processor register.
7. Cookies on customer websites that embed our widget
The ReviewMix widget embedded on a customer's website does not set cookies by default. It is designed to integrate with the host site's Consent Management Platform (Cookiebot, Iubenda, Usercentrics, and others) and to run in a cookie-free degraded mode when consent is not granted or when the site operates without a CMP. To render, the widget requests its review data and one font file from ReviewMix's own EU servers, fronted by Cloudflare as listed in our sub-processor register; these requests set nothing on the visitor's device, carry no identifier, and use no third-party font service.
If you are a visitor to a customer's website, the applicable cookie policy is that customer's — not ours. Our role is strictly that of a data processor embedded in their site.
If you are a ReviewMix customer, it remains your responsibility to:
- Disclose the use of our widget in your own privacy and cookie policies
- Respect visitor consent choices before the widget loads (our integration guide explains how)
- Keep your CMP configuration current
8. Contact
Questions about cookies: privacy@reviewmix.eu.
Changelog
- 1 October 2026 — Added to § 2.1: five browser local-storage entries in the app dashboard. One,
reviewmix.notices.dismissed, already existed and was not listed; it remembers the dashboard notices you dismissed. Four are new and keep work you have not finished on your device: an unsent review reply, unsaved widget settings, onboarding choices and printables options, each for at most 7 days (onboarding 24 hours), deleted when you finish, discard or reset them and when you sign out. All five keep only what you chose or typed inside the service, on your device, and are exempt on the user-input ground, like thereviewmix_businesscookie; nothing new is sent to us or to anyone else. § 2.2's preference sentence now names them. Non-material: no new purpose, no new recipient. The four draft entries take effect when deployed. - 12 September 2026 — Added to § 2.3: with the same analytics consent, our servers now send PostHog a small number of events recording that a step finished — an account created, a sign-in completed, a checkout started, an account closure requested. They read your analytics choice from the
reviewmix_consentcookie in § 2.1 and the anonymous identifier from the PostHog cookie in § 2.3's table, write nothing to your device, and send nothing when the choice is absent, unreadable or refused, or when that identifier is missing, so no row of the storage table changes. Stated plainly because it is the one case where something is recorded about pages PostHog never loads on, such as sign-in and sign-up: what is recorded is that the step finished. No new recipient. It takes effect when deployed. - 11 September 2026 — Session replay now records the text of our own pages. On reviewmix.eu, which shows only our own content, page text is recorded as it appears; what you type stays masked, so does a help-centre search the page repeats back, and images stay blocked. Inside the dashboard, text stays masked except our own interface text, which is marked readable one element at a time, so our customers' data and the figures and dates shown from their accounts stay masked, as do element attributes. Also corrected: when a customer added a testimonial by hand in the dashboard, the star rating they chose was recorded, although this policy said customer data was not; that control is now excluded from replay. Non-material: no new purpose and no new recipient; the newly readable text is our own content, and what we record about your visit is otherwise unchanged. It takes effect when deployed to each site.
- 10 September 2026 (fifth entry) — The app dashboard now shows the consent banner when no choice is stored on your device. The previous entry assumed every customer passes through reviewmix.eu's banner first; someone who signs up directly, or opens the dashboard on a new device or in a private window, never does, and was never asked. Same banner, same buttons, same cookie, nothing pre-selected, and a stored choice is still never asked for again. Also stated: the dashboard can reuse the anonymous PostHog identifier from an earlier reviewmix.eu visit, which has been the case since PostHog reached the dashboard and which the previous entry did not say. No new processing purpose and no new recipient. The banner takes effect when deployed to the app.
- 10 September 2026 (fourth entry) — PostHog now also runs inside the app dashboard, on the analytics choice already made on reviewmix.eu, and the dashboard's account menu gains Cookie settings to change or withdraw that choice. On dashboard pages replay also blocks images and masks element attributes, and page addresses and links are sent without query strings, because those pages show our customers' own data. A refusal made on one site now also clears the other site's identifiers the next time you open it. PostHog is not loaded on collection pages, self-service links or the sign-in page. Non-material: nobody is measured who has not already opted in, and there is no new recipient. It takes effect when deployed to the app.
- 10 September 2026 (third entry) — One session-storage entry,
ph_<project-key>_session_registered_properties, is separated out and its retention stated precisely. Withdrawal was tested on the live site: three of the four session entries go immediately, and this one is written once more shortly afterwards. It holds a list of diagnostic setting names, no identifier and nothing about the visitor. Rather than promise a removal that a timing race can defeat, the row now says what actually happens. The two entries the policy calls identifiers ARE deleted on withdrawal, verified in a browser. - 10 September 2026 (second entry) — Session-storage row corrected: it listed two keys where the library writes four. Found by testing a withdrawal on the live site rather than by reading, which is also what found that the withdrawal was not deleting the two main identifiers at all — fixed the same day. Non-material for anyone's rights; the entries were always deleted on withdrawal, and the correction is to the description.
- 10 September 2026 — Storage inventory completed for PostHog, which was installed today. Three entries are added to the strictly-necessary and analytics tables that the previous drafts did not list: two session-storage keys the analytics library uses to tell browser tabs apart, and the record that remembers a REFUSAL. That last one is set only if you refuse and is deliberately not deleted when you withdraw, because it is what stops analytics starting again — the opposite of the others, and stated so nobody reads its retention as an oversight. No new processing, no new recipient; this closes a gap between what was stored and what was written down.
- 9 September 2026 (second entry) — The
reviewmix_consentcookie described in Section 2.1 now exists: it was built the same day, with the name, domain, path,SameSite,Secureflag and 12-month lifetime this policy had already published. Nothing in that row changed; what changed is that it became true. Added alongside it: thereviewmix-cookie-consentlocal-storage entry, which is where the choice used to be kept and which is read once, copied into the cookie, and deleted. It was not previously listed, and is listed now because Section 1 brings local storage inside this policy's scope. Non-material for anyone's rights: no new processing, no new recipient, and a choice already made is carried across rather than re-asked. - 9 September 2026 — Analytics reversal: legitimate interest (Art. 6(1)(f)) named as the basis for the Google tag's pre-consent measurement pings, with the right to object stated beside it; consent-required PostHog Cloud EU product analytics and masked session replay; retained marketing GA4 and its Consent Mode v2 behavior; named both recipients, disclosed the analytics storage each one sets, and corrected the description of the consent banner and of how to withdraw. Reverses the June 2026 consent exemption for analytics. Also removes two functional cookies and a Global Privacy Control commitment that this policy listed but that the service never implemented. A cookie-settings control inside the app is added when analytics reaches the app.
- 19 August 2026 — Accuracy correction: the
reviewmix_sessionrow described the cookie as an "encrypted JWT"; it is an opaque, high-entropy token held server-side as a keyed digest, and the row now says so. Companion to the same-day DPA Annex II corrections. Non-material — a mechanism description only; the cookie's purpose, lifetime and attributes are unchanged. - 2 July 2026 — Editorial: legal-review attribution reworded impersonally; policy URL and site-scope wording corrected; internal review-status note refreshed. Non-material.
- 22 June 2026 — Determinations applied: self-hosted Plausible reclassified as consent-exempt (cookieless; outside Art. 5(3) ePrivacy scope) subject to immediate IP hashing and no granular profiling; legal-basis section updated accordingly.
- 28 June 2026 — Initial publication.