SPONA ERP — LEGAL DOCUMENTS 2026-09-17 · 1.1 English is the governing language of the Terms to the extent permitted by law. # Cookies & browser storage ## 1. Website storage and your choices The website stores spona.website.consent in first-party localStorage to remember your privacy choice for up to 180 days. It contains the policy/provider version, choice time, expiry, language and category choices; no account identifier is added. Accept and reject choices use the same duration. The record expires on the next visit or while the page is active; the browser may retain expired bytes until the site runs again or you clear storage. Expired, missing, malformed or outdated records do not enable optional services. If storage is unavailable, the choice applies to the current page session and the site may ask again on reload. Necessary preference storage is used to honour your choice, not to advertise. When you select a website language, spona.website.language remembers that choice in first-party localStorage for up to 180 days, with the language, save time and expiry only. You can change it using the language switcher or remove it by clearing site storage. On a homepage visit without an explicit language, we use your saved choice first, then a country code supplied by Cloudflare from your connection, or your browser language if that code is unavailable. This feature does not request precise device location or store your IP address in the language preference. Explicit language links remain available. ## 2. ERP authentication The API sets a first-party HttpOnly cookie named token for authenticated sessions. The source sets no explicit cookie expiry, so browser session handling applies; restoring a browser session may preserve it. The dashboard and command centre also use spona.session in sessionStorage and localStorage to maintain and restore sign-in. Session storage normally lasts for the tab session; local storage has no automatic expiry in the reviewed implementation. Logout clears these client-side records and the current server session. Clearing browser storage alone does not establish that every server session has been revoked. ## 3. Accept, refuse or withdraw Use Reject optional to keep optional services off, Accept all to enable only the configured and disclosed categories, or Manage choices to choose individual categories. Unconfigured categories are disabled; no advance permission is recorded for them. Close or Escape dismisses the settings panel without saving. Cookie settings remains available below the footer and in the legal centre. You can change or withdraw permission there at any time; refusal does not block navigation, calculators or contact features. Changes apply to open tabs on this same origin through browser storage events. This choice does not cover another device, browser, subdomain or ERP application, marketing email, AI training or contractual acceptance. ## 4. Your controls You can clear cookies and site storage in your browser settings and sign out of the ERP. Clearing authentication data may require you to sign in again; clearing preferences resets the saved layout. On a shared device, sign out when finished. Privacy requests about server-side records should be sent to connect@spona.io or to your organisation for its ERP records; browser deletion does not delete those records. ## 5. Google Analytics 4 — planned live integration Spona has selected Google Analytics 4 for website measurement. It remains disconnected until the live measurement ID is configured. The implementation uses basic consent gating: no Google tag is loaded and no analytics requests or denied-consent pings are sent by this integration before analytics permission. Once enabled and accepted, GA4 measures page views and usage, using browser/device information and cookie identifiers; Google receives network information such as IP addresses in the request. Our explicit page-view events use an allowlisted page route and exclude query strings, form fields and referrer values. Google advertising signals and advertising consent are disabled. Production Enhanced Measurement settings must be reviewed before activation. This is website measurement, not access to ERP records. ## 6. Analytics cookies and withdrawal When analytics is connected and accepted, the integration configures first-party _ga and _ga_ cookies on the current hostname and root path, with a 180-day lifetime and rolling updates disabled. Withdrawal sets Google’s measurement-disable flag, stops our page-view listener, removes the tag and accessible _ga cookies, clears its local command queue and reloads the page to unload already executed Google code. Requests already sent cannot be recalled and withdrawing consent does not automatically erase data already received by Google. Contact connect@spona.io for a separate data-rights request. We cannot delete cookies belonging to unrelated sites or applications.