Cookie Policy
Version 1.1 · Effective 23 August 2026
This Cookie Policy explains how TALLUM FOUNDRY SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ ("Tallum Foundry", "we", "us" or "our") uses cookies and similar technologies on ideadrive.ai and the IdeaDrive web application (together, "IdeaDrive").
Company details:
- registered address: Floriańska St. 6, Unit 02, 03-707 Warsaw;
- KRS: 0001252744;
- NIP / EU VAT: 5214172327 / PL5214172327;
- REGON: 54523141800000;
- contact: info@tallumfoundry.com.
1. What cookies and similar technologies are
Cookies are small files stored on a browser or device. Similar technologies include local storage, pixels, software development kits and device identifiers. They can keep a user signed in, remember preferences, measure product use and help prevent fraud.
2. How consent works
Strictly necessary technologies are used because IdeaDrive cannot provide the requested account, authentication, security, checkout or preference functions without them. Where consent is required, optional analytics technologies remain disabled until the user makes a choice in the cookie banner.
The banner provides equally accessible Accept all, Reject all and preference-management options. Refusing optional technologies does not block access to IdeaDrive's core content or account functionality.
Users can withdraw or change consent at any time using the Update cookie preferences control available from the website footer or account privacy settings. Withdrawal does not affect processing that was lawful before consent was withdrawn.
US users can also opt out of sale, sharing and targeted advertising through Do Not Sell or Share My Personal Information. IdeaDrive recognizes supported browser-based universal opt-out signals, including Global Privacy Control (GPC), for the relevant browser or device.
Cookie consent is separate from any checkout request to begin providing a paid digital service before the Consumer's withdrawal period expires. Selecting an immediate-performance checkbox does not constitute consent to optional analytics or other non-essential browser storage. Evidence of that checkout request is kept with the purchase record rather than in optional browser tracking storage.
3. Production cookie and tracking specification
The following inventory is the required launch configuration and disclosure baseline. The production implementation must match this specification. Names containing * represent deployment-specific identifiers or chunked variants. Before publication, the deployed site must be checked to confirm the actual names, domains, consent states and lifetimes. Any additional cookie or similar technology must be classified and added to this Policy before it is enabled.
| Technology | Provider / party | Category | Purpose | Required maximum lifetime |
|---|---|---|---|---|
ideadrive_cookie_consent | IdeaDrive, first-party | Strictly necessary | Stores cookie category choices and evidence of consent | 6 months |
sb-*-auth-token, including chunked variants | Supabase Auth, first-party | Strictly necessary | Maintains the authenticated Supabase session for Google OAuth, Twitter/X OAuth and email magic-link users | Session/configured authentication lifetime |
AMP_* | Amplitude, first-party analytics storage | Analytics | Stores device, user and session identifiers and event sequencing metadata | Up to 12 months |
amplitude_cookie_test* | Amplitude, first-party | Analytics | Tests whether the browser accepts cookies | Removed after the test |
_ga | Google Analytics, first-party analytics cookie | Analytics | Distinguishes users for aggregated product and website analytics | Up to 2 years |
_ga_<container-id> | Google Analytics, first-party analytics cookie | Analytics | Persists session state for the relevant GA4 property | Up to 2 years |
__stripe_mid | Stripe | Payments and fraud prevention; necessary when checkout is requested | Helps Stripe prevent payment fraud | Up to 1 year |
__stripe_sid | Stripe | Payments; necessary when checkout is requested | Maintains a Stripe payment session | About 30 minutes |
Google and Twitter/X may use their own cookies on their domains when a user chooses the corresponding OAuth sign-in flow. Stripe may use its own cookies on Stripe-hosted checkout pages. Those providers control their own cookies under their respective policies.
4. Cookie categories
Strictly necessary
These technologies support authentication, session continuity, consent records and security. They are not used for advertising by IdeaDrive and cannot be disabled through the preference center where they are necessary to provide a feature requested by the user. Stripe payment and fraud-prevention technologies are used when a user requests checkout and are separately identified as payment technologies in the inventory above.
Analytics
Amplitude and Google Analytics measure how users interact with IdeaDrive, including pages or screens visited, feature events, session information, device/browser information, approximate location, referral and campaign information, and technical performance. Amplitude is configured with a United States data center and a 12-month analytics retention period. The Google Analytics 4 property is configured with a maximum user-level and event-level retention period of 14 months; standard aggregated reports may remain available for longer under Google's documented retention behavior.
Amplitude and Google Analytics are used only for product and website analytics at launch. IdeaDrive does not use Google Ads, advertising personalization, remarketing or conversion-tracking integrations at launch.
Amplitude tracking and the Google Analytics tag must not initialize before the required analytics consent is received. The launch configuration uses a basic consent approach that blocks Google Analytics before consent rather than sending cookieless measurement pings. Rejecting or later disabling analytics should stop further analytics tracking and clear optional Amplitude and Google Analytics browser storage where technically possible.
Email tracking
Transactional and marketing emails are delivered through Resend. Where enabled, marketing emails may use pixels or redirect links to record delivery, opens or clicks. Marketing emails include an unsubscribe mechanism. A user may also request an opt-out at info@tallumfoundry.com.
5. Providers
- Supabase — authentication, database and application storage. Privacy information
- Amplitude — product analytics. Privacy information and DPA
- Google — Google OAuth and Google Analytics product and website analytics. Privacy Policy, Google Analytics data safeguards and Google Ads Data Processing Terms
- Twitter/X — Twitter/X OAuth. Privacy Policy
- Stripe — hosted checkout, payment processing and fraud prevention. Privacy Policy
- Resend / Plus Five Five, Inc. — transactional and marketing email delivery. Privacy Policy
6. Browser controls
Users can also delete or block cookies through browser settings. Blocking strictly necessary cookies may prevent authentication, checkout or other requested functionality.
7. Updates
We review this inventory after material changes to authentication, analytics, payments or email integrations, and before introducing any advertising technology. We may update this Policy by publishing a revised version and changing its effective date. Where required, we will request consent again.
8. Contact
Questions or requests relating to cookies and tracking can be sent to info@tallumfoundry.com.