Cookie Policy
This Cookie Policy explains how Ciosanna ("we", "us", or "our") uses cookies and similar browser storage technologies on CiosannaConnect.com (the "Site"). It identifies the technologies we use, what they do, the categories they fall into, and the choices you have to control them.
IMPORTANT: Although this document is titled "Cookie Policy" for familiarity, it covers the broader category of information stored on your device — including browser storage technologies such as localStorage and sessionStorage — which are treated equivalently to cookies under the European Union ePrivacy Directive (2002/58/EC, as amended), the United Kingdom Privacy and Electronic Communications Regulations (PECR), and similar regulations in other jurisdictions. Where this policy refers to "cookies," that reference should be read to include these other browser storage technologies unless the context clearly requires otherwise.
This Cookie Policy works alongside our Privacy Policy. The Cookie Policy describes the technical mechanisms used to store information on your device and the categories of those mechanisms. The Privacy Policy describes the personal data we collect (whether through these mechanisms or otherwise), how we use it, who we share it with, and your rights. If you have questions about personal data, please consult the Privacy Policy at /legal/privacy.
1. Introduction
1.1 Scope
This Cookie Policy applies to CiosannaConnect.com (the Site), Ciosanna's public sales and marketing website. The Site operates separately from the Ciosanna property management platform at Ciosanna.com, which has its own privacy notices and tenant-specific terms governing how data is collected and used within the platform's user portals. This policy describes the cookies and browser storage technologies the Site sets when you visit, regardless of whether you sign up for an account, subscribe to a plan, or browse without subscribing.
1.2 Relationship to the Privacy Policy
The Cookie Policy and the Privacy Policy serve distinct but related purposes. The Cookie Policy describes the technical mechanisms used to store information on your device — what is stored, by whom, for how long, and under which consent category. The Privacy Policy describes the personal data Ciosanna collects (through these and other means), the legal bases for processing, the parties with whom we share it, the rights you have over it, and how to exercise those rights. When questions concern personal data, the Privacy Policy governs; when questions concern storage technologies, this Cookie Policy governs.
1.3 Contact
For questions about this Cookie Policy, contact us at support@ciosanna.com. To exercise rights related to personal data — including access, correction, deletion, or objection to processing — please use our visitor data request form at /legal/privacy-request, or consult the Privacy Policy for the complete list of regional rights and the procedures for invoking them.
2. What Cookies and Browser Storage Are
2.1 Cookies
Cookies are small text files that a website places on your device when you visit. They are returned to the website on subsequent requests, allowing the site to recognize your device and remember information across pages or visits. Cookies are classified as session cookies, which are deleted when you close your browser, or persistent cookies, which remain until they expire or are explicitly deleted. They are also classified as first-party cookies, which are set by the site you are visiting, or third-party cookies, which are set by other domains whose resources are loaded by the site. Ciosanna does not set any first-party cookies on the Site; the only cookies you may receive are set by the limited third-party services described in Section 5.
2.2 Browser Storage
In place of first-party cookies, the Site uses browser storage technologies — specifically the localStorage and sessionStorage APIs provided by modern web browsers. These APIs allow a site to store data on your device and read it back during later visits (localStorage) or during the same browser session (sessionStorage). Unlike cookies, browser storage values are not automatically transmitted to the server with every HTTP request, which makes them better suited to storing local preferences and short-lived form state. Under the EU ePrivacy Directive, the UK PECR, and similar regulations in other jurisdictions, browser storage is treated equivalently to cookies for the purpose of disclosure and consent obligations, which is why this policy describes them in detail. Section 3 lists each browser storage key the Site uses.
3. First-Party Storage We Use
3.1 Consent Record (ciosanna-consent)
This entry records the consent choices you make through our consent banner. It is stored in your browser's localStorage under the key ciosanna-consent.
The stored value is a JSON object containing four boolean flags (one per consent category — essential, analytics, cioAgent, marketing), the action that produced the record (for example, "accept_all", "essential_only", or "gpc_auto" when triggered by your browser's Global Privacy Control signal), an ISO-8601 timestamp of when the choice was made, and a policy version identifier. The value does not contain your name, email address, IP address, or any other directly identifying information.
This entry is essential. Without it, the Site cannot honor your stated preferences across pages or visits, and the consent banner would reappear on every page load. The entry persists until you clear your browser's storage for this Site or use the in-banner control to change your choices. It is set by the Site itself (first-party) and is not transmitted to any third party.
3.2 Locale Preference (ciosanna-locale)
This entry records your selected display language. It is stored in your browser's localStorage under the key ciosanna-locale.
The stored value is a short language code such as "en" for English, "es" for Spanish, "ja" for Japanese, and so on, for the twelve languages the Site supports. The value does not contain any personally identifying information.
The Site uses this entry to render the interface in your chosen language on subsequent visits without requiring you to select the language again. The entry persists until you clear your browser's storage. It is set by the Site itself (first-party), is not transmitted to any third party, and falls under the Functional Preferences category described in Section 4.
3.3 Theme Preference (ciosanna-theme)
This entry records your selected color theme (light mode or dark mode). It is stored in your browser's localStorage under the key ciosanna-theme.
The stored value is one of the strings "light" or "dark". The value does not contain any personally identifying information.
The Site uses this entry to render the interface in your chosen color theme on subsequent visits without requiring you to select it again. The entry persists until you clear your browser's storage. It is set by the Site itself (first-party), is not transmitted to any third party, and falls under the Functional Preferences category described in Section 4.
3.4 Signup Form Continuity (ciosanna_signup_form)
This entry temporarily holds the information you enter into our subscription signup form. It is stored in your browser's sessionStorage under the key ciosanna_signup_form.
The stored value is a JSON object containing the fields you have entered: company name, billing address (street, city, state or region, postal code, country), unit count, plan selection, owner name, owner email, and owner phone number. This entry contains personal data, which makes it categorically different from the other entries described above. It exists for a single purpose: to preserve the data you have already typed if you proceed to Stripe Checkout and then return to the Site — for example, by clicking your browser's back button or cancelling the checkout. Without this entry, you would have to re-enter every field from the beginning.
This entry is essential to the signup workflow. It is automatically removed from your browser when your signup completes successfully, when you close the browser tab (because sessionStorage does not persist across sessions), or when you clear your browser's storage. It is set by the Site itself (first-party), is not transmitted to any third party, and is never sent to a server prior to your decision to submit the form.
4. Functional Preferences
4.1 Why These Preferences Are Not Consent-Gated
Two of the entries described in Section 3 — ciosanna-locale and ciosanna-theme — fall into a category commonly referred to as "functional preferences." These are settings that you initiate yourself by selecting a language or theme, do not involve any tracking or profiling, are not transmitted to any third party, and do not contain personal data. We store them automatically once you make the selection because that is the only way to honor the choice on your next visit.
For these reasons, the consent banner does not present a separate toggle for functional preferences. Disclosing them in this Cookie Policy rather than gating them behind the consent banner reflects the limited scope of these entries and the user-initiated nature of the storage. If you prefer the Site not to remember your language or theme between visits, you can prevent this storage entirely by browsing in your browser's private or incognito mode, or by clearing the relevant keys after each session as described in Section 4.2.
The signup form continuity entry (ciosanna_signup_form), although it contains personal data, is similarly not consent-gated because it is strictly necessary to deliver a service you have actively initiated by beginning the signup form. It is automatically deleted at the end of your session.
4.2 How to Clear These Preferences
To clear the Site's browser storage entries — including the consent record, locale preference, theme preference, and any signup form data — you can do any of the following:
- Clear site data through your browser. All modern browsers provide a way to clear stored data for a single Site. The specific menu varies by browser, but you can typically reach it through Settings → Privacy → Site Settings, then search for "ciosannaconnect.com" and choose Clear data.
- Use developer tools. If you are comfortable with developer tools (most browsers expose them via F12 or Ctrl+Shift+I), open the Application or Storage tab, locate "Local Storage" and "Session Storage" under this Site's origin, and delete the ciosanna- prefixed keys you wish to remove.
- Browse in private or incognito mode. In this mode, your browser will not retain the Site's storage entries after you close the window.
Clearing the consent record will cause the consent banner to reappear on your next visit, allowing you to make new choices. Clearing locale or theme preferences will cause the Site to revert to its defaults. The signup form continuity entry, if present, is cleared automatically when you close the browser tab.
5. Third-Party Services
5.1 Cloudflare Turnstile
Cloudflare Turnstile is a CAPTCHA-replacement service we use to verify that requests submitted through the Site come from human visitors rather than automated systems. We use it on forms that accept user input, including the signup form, contact form, and visitor data request form.
When you load a page that contains a Turnstile challenge, your browser loads a script from `challenges.cloudflare.com`. Cloudflare may set cookies or other identifiers on that domain to perform the challenge — these are managed by Cloudflare, not by Ciosanna, and they are set on Cloudflare's domain rather than on CiosannaConnect.com. Cloudflare describes its data handling for Turnstile in its Cookie Policy and Privacy Policy at cloudflare.com.
The Turnstile challenge collects technical signals about your browser and connection (for example, browser type, IP address, and timing data) to distinguish humans from bots. These signals are processed by Cloudflare and are not used by Ciosanna for advertising, profiling, or any purpose other than bot prevention. Turnstile is classified under the Essential category because the Site cannot accept form submissions without it.
5.2 Stripe Checkout
Stripe is the payment processor we use to handle subscription payments. When you complete the signup form and proceed to payment, the Site sends your form data to our server, which creates a Stripe Checkout session and then redirects your browser to `checkout.stripe.com`. Stripe handles the payment process entirely on its own domain.
Because the redirect to Stripe takes place on Stripe's domain rather than CiosannaConnect.com, Stripe sets its own cookies and storage entries on the `stripe.com` domain — not on CiosannaConnect.com. We do not load Stripe.js or any other Stripe script on CiosannaConnect.com itself. Once payment is complete or cancelled, Stripe redirects your browser back to a confirmation page on our Site.
Stripe's cookie practices, the data Stripe processes, and your choices regarding Stripe are described in Stripe's Cookie Policy and Privacy Policy at stripe.com. Stripe is classified under the Essential category for the same reason as Turnstile: the Site cannot complete a subscription transaction without it.
5.3 No Other Third Parties
Beyond Cloudflare Turnstile and Stripe Checkout, the Site does not load scripts, fonts, images, analytics, advertising trackers, or any other resources from third-party origins. The Inter typeface used throughout the Site is hosted on our own origin rather than fetched from Google Fonts or any other external font service. We do not use Google Analytics, Meta Pixel, or any equivalent analytics or advertising product. We do not embed social media widgets. We do not load chat tools from third-party vendors.
This deliberate constraint is part of how we minimize the personal data that flows to parties outside Ciosanna. If we add a new third-party service in the future, we will update this Cookie Policy and, where the new service is not strictly essential, gate it behind the appropriate consent category in the consent banner.
6. Consent Categories
6.1 Essential
The Essential category covers cookies, browser storage entries, and third-party services that are strictly necessary for the Site to function. These cannot be disabled through the consent banner because without them, the Site cannot deliver core features you have actively requested.
Entries and services classified as Essential include: the consent record (`ciosanna-consent`), the signup form continuity entry (`ciosanna_signup_form`), Cloudflare Turnstile bot verification, and Stripe Checkout payment processing. The functional preferences described in Section 4 (locale and theme) are also stored without consent gating, on the same strictly-necessary rationale, even though they are sometimes separately categorized in other policies.
You can clear Essential entries through your browser's storage controls as described in Section 4.2, but doing so will cause the consent banner to reappear, will reset any in-progress signup, and will reset your locale and theme preferences.
6.2 Analytics
The Analytics category is reserved for first-party measurement of how visitors use the Site — for example, which pages are viewed, how long a typical visit lasts, and which links are clicked. Analytics data is used to improve the Site, prioritize content, and identify problems.
At the time this Cookie Policy was last updated, the Site does not load any analytics service that requires consent under this category. When you accept the Analytics category in the consent banner, the Site additionally records a server-side acknowledgment that you opted into analytics; this acknowledgment contains your country code (derived from your IP address by Cloudflare) and the timestamp of your choice, and is stored as part of our compliance audit trail.
If we add analytics measurement in the future, it will be first-party (running on our own servers and domain) and will only activate when you have accepted the Analytics category. We will not transmit analytics data to third-party analytics providers such as Google Analytics or Meta.
6.3 Cio AI Assistant
The Cio AI Assistant category is reserved for the Cio sales assistant, an interactive chat experience we plan to introduce on the Site to help visitors learn about Ciosanna and answer common questions. At the time this Cookie Policy was last updated, the Cio AI Assistant is not yet active on the Site, so this category does not currently control any cookies or browser storage entries.
When the Cio AI Assistant launches, accepting this category will allow the chat widget to operate and may store data such as a session identifier or conversation history locally so that the agent can maintain context across multiple messages. Declining this category will prevent the chat widget from loading and from storing any conversational data.
If you accept this category before the Cio AI Assistant launches and later wish to change your choice, you can update your selection at any time through the consent controls described in Section 7.
6.4 Marketing
The Marketing category is reserved for cookies and browser storage entries used for advertising, retargeting, or campaign measurement. At the time this Cookie Policy was last updated, the Site does not load any marketing service that requires consent under this category.
If we introduce marketing tools in the future — for example, conversion tracking pixels used to measure the effectiveness of advertising campaigns we run on third-party platforms — those tools will only activate when you have accepted the Marketing category. We will update this Cookie Policy at that time to disclose each tool, the third party operating it, and the data it processes.
7. Managing Your Preferences
7.1 The Consent Banner
The consent banner is the primary control you use to express your preferences across the four categories described in Section 6. The banner is presented to you on your first visit, before any non-essential storage is written or any non-essential third-party service is activated.
The Site presents the banner in one of three modes depending on where you appear to be visiting from, as determined by your network connection. Visitors in the European Union and European Economic Area see a full-screen overlay that must be acknowledged before continuing; all non-essential categories default to declined, and you must affirmatively opt in to each category you wish to enable. Visitors in the United States and other regions see a less intrusive banner at the bottom of the page with "Accept all" and "Essential only" options, and may continue using the Site while choosing. Visitors whose browser signals a Global Privacy Control preference, as described in Section 7.3, do not see the banner at all; the Site automatically records an essential-only choice on their behalf.
You can change your consent choices at any time after the initial visit. Clearing your browser's storage for the Site, as described in Section 4.2, will cause the banner to reappear on your next visit.
7.2 Browser Controls
In addition to the consent banner, you can control cookies and browser storage through your browser's own settings. Most browsers allow you to view stored cookies and storage entries, block cookies from specific sites, block all third-party cookies, clear all stored data, or browse in a private or incognito mode that prevents persistent storage entirely.
For the third-party services described in Section 5 — Cloudflare Turnstile and Stripe Checkout — any cookies those services set are stored on their own domains (`cloudflare.com` and `stripe.com` respectively) rather than on CiosannaConnect.com. Clearing data for those domains is done through your browser's site-data controls in the same way as clearing data for any other site you visit.
Note that blocking all cookies or storage may prevent essential features from working correctly. For example, the Site cannot remember your consent choice, render in your selected language, or accept form submissions if the relevant essential entries cannot be stored.
7.3 Global Privacy Control (GPC)
Global Privacy Control is a browser-level signal that allows you to express a do-not-sell-or-share preference across every website you visit, without configuring each site individually. It is supported by browsers such as Firefox, Brave, and DuckDuckGo, and through several browser extensions.
When your browser sends a Global Privacy Control signal with your request, the Site automatically treats your visit as if you had selected "Essential only" in the consent banner. No non-essential storage is written, no non-essential third-party service is activated, and the banner is not displayed. A record of this automatic choice is stored in your consent record with the action `gpc_auto` so that the Site can confirm the choice was honored.
If you later turn off Global Privacy Control or visit from a different browser, the Site will re-evaluate your region and present the appropriate consent flow on your next visit.
7.4 Regional Rights
Your rights regarding cookies and personal data depend on where you reside. This Cookie Policy summarizes the rights most directly tied to cookies and browser storage; the Privacy Policy describes the complete set of rights and the procedures for exercising them.
If you are in the European Union, European Economic Area, or United Kingdom, you have rights under the General Data Protection Regulation (GDPR), the UK GDPR, the ePrivacy Directive, and the UK Privacy and Electronic Communications Regulations, including the right to give and withdraw consent for non-essential cookies and storage at any time.
If you are in California, Virginia, Colorado, Connecticut, Utah, or another United States state with a comprehensive privacy law, you have rights under those laws, which may include the right to opt out of the sale or sharing of personal information, the right to access information about how the Site uses your data, and the right to direct deletion of personal information. As described in Section 7.3, the Site automatically honors Global Privacy Control as a signal that you are exercising the opt-out right.
To exercise any of these rights, please use our visitor data request form at `/legal/privacy-request` or contact us at support@ciosanna.com. The Privacy Policy lists the specific procedures, response timelines, and verification steps for each category of request.
8. Changes to This Policy
8.1 Updates
We may update this Cookie Policy from time to time to reflect changes in the technologies the Site uses, the third parties involved, the categories presented in the consent banner, or applicable law. When we do, we will update the "Last updated" date at the top of this page and, where the change is material, we will reset the consent record so that the banner reappears on your next visit and gives you the opportunity to confirm or change your choices.
We encourage you to review this Cookie Policy periodically. Continued use of the Site after an updated version takes effect indicates your awareness of the changes; it does not, by itself, indicate consent to any non-essential category, which always requires affirmative action through the consent banner.
8.2 How to Reach Us
For questions about this Cookie Policy, the cookies or browser storage described in it, or the choices available to you, you can reach us at:
- Email: support@ciosanna.com
- Postal mail: 714 W 2nd St, Waitsburg, WA 99361
- Visitor data request form: /legal/privacy-request
For matters relating to personal data more broadly, including the rights described in Section 7.4, please consult the Privacy Policy, which contains complete contact information and the procedures for invoking each right under applicable law.
If you are a visitor in the European Union or European Economic Area and wish to contact our designated representative under Article 27 of the GDPR, please refer to the Privacy Policy for those contact details.
End of Cookie Policy.
The information provided on this page is for general informational purposes only and does not constitute legal advice. For advice regarding your specific situation, please consult a qualified attorney licensed in your jurisdiction.
Questions about this document? Contact us at support@ciosanna.com