Skip to main content
CyberLab.Team

Cookie Policy

Last updated: 23 September 2026

This Cookie Policy explains how we use cookies and similar technologies on our public website cyberlab.team and our client portal my.cyberlab.team. We respect your privacy and do not use cookies for cross-site profiling or selling advertisements.

1. Strictly Necessary Cookies (No Consent Required)

These cookies are essential for the Platform and Website to function securely and correctly. These cookies are set on the basis of technical necessity under the EU ePrivacy Directive and the Estonian Electronic Communications Act (Elektroonilise side seadus). No prior consent is required for these strictly necessary cookies.

  • Auth and session cookies: used on my.cyberlab.team to authenticate you, keep you logged in securely, and prevent Cross-Site Request Forgery (CSRF).
  • Consent preferences: cookie-consent-v1 (stored in localStorage) remembers your cookie choice so we don't repeatedly ask you. Your choice is kept for 12 months. After that, or when we update this policy, the banner asks you again; you can change your choice at any time via "Cookie settings".
  • Stripe security and fraud prevention: as we use Stripe for payment processing, Stripe sets strictly necessary cookies (such as __stripe_mid and __stripe_sid) to ensure the security of financial transactions and to prevent fraud. Refusal of these cookies is not possible if you intend to make payments on our Platform.
  • Google OAuth authentication: if you log into the Platform using "Sign in with Google", Google will set its own strictly necessary cookies in the authentication popup or redirect to securely verify your identity and protect your Google account. We do not control these cookies, but they are essential for the OAuth 2.0 login mechanism to function.

Warning: disabling these strictly necessary cookies in your browser settings will render the Client Cabinet entirely unusable, as core security and authentication mechanisms will fail.

2. Cloudflare Web Analytics (Cookieless)

We use Cloudflare Web Analytics to gather anonymous, aggregated site statistics. It does not use cookies, local storage, or device fingerprinting, and it does not collect personal data. Data is aggregated momentarily at Cloudflare's edge. Because no terminal equipment storage occurs, this operates without requiring your consent (exempt under ePrivacy Directive Art. 5(3)).

3. Analytics (Consent Required)

We use the Google tag (gtag.js) to run Google Analytics 4 (GA4) on our Website (cyberlab.team).

  • Consent gated: these services (provided by Google Ireland Ltd.) are activated strictly and only if you explicitly click "Accept all" in our cookie consent banner. If you ignore the banner or click "Reject all", these analytics cookies will not be loaded.
  • Purpose: to understand user behavior, site interactions, and marketing campaign performance. IP anonymization is enabled by default in GA4.
  • Remarketing: advertising features (remarketing audiences) are enabled in GA4. After you click "Accept all", Google may load a pixel from a Google country domain (for example www.google.pl/ads/ga-audiences) so that visitors of our Website can later be shown our own ads in Google services. If you reject or ignore the banner, this pixel is not loaded.
  • Duration: analytics data is retained in GA4 for up to 14 months.
  • Withdrawal: you can change your preferences or withdraw consent at any time via the "Cookie settings" button in our website footer.

4. Embedded Media (Third-Party Cookies)

Our Website may feature embedded video content hosted on third-party platforms such as YouTube (Google Ireland Ltd.) and Vimeo (Vimeo.com, Inc.).

  • When you interact with or play an embedded video, these platforms may set their own third-party cookies to track video performance, remember playback preferences, and gather analytics for their own purposes.
  • These cookies are governed strictly by the respective privacy and cookie policies of Google and Vimeo.
  • Disclaimer of liability: we have no control over, and disclaim all legal liability for, the tracking and data collection practices of third-party platforms once you interact with their embedded media or external links.

5. Hosting and Security Infrastructure

We use Cloudflare for DNS, hosting, security, and CDN services. Technical logs (such as IP addresses and user agents) are processed momentarily at the edge network strictly for security purposes (such as DDoS protection and Web Application Firewall) under our legitimate interest (GDPR Art. 6(1)(f)).

6. Advertising and Targeting Cookies (Consent Required)

If you provide explicit consent via our cookie banner, we may use advertising pixels and tags (such as Meta Pixel, LinkedIn Insight Tag, or Google Ads Conversion Linker) on our public Website (cyberlab.team).

  • Purpose: these are used to measure the effectiveness of our own marketing campaigns and to serve you relevant advertisements for our agency services on other platforms.
  • Scope: these tracking cookies operate exclusively on our public Website and are not active inside the logged-in Client Cabinet (my.cyberlab.team).

7. Strict Isolation of Google API Data

We guarantee that no tracking cookies, marketing pixels, or advertising tags (such as Meta Pixel or Google Analytics) are ever used to track, harvest, or retarget based on the sensitive Google Ads or Google Business Profile data fetched into your logged-in Client Cabinet. Marketing trackers operate strictly on our public-facing Website and are completely isolated from your connected Google API data.

Managing Cookies in Your Browser

In addition to our cookie banner, you can configure your web browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. Please note that blocking strictly necessary cookies will prevent you from logging into my.cyberlab.team and using our Client Cabinet.

For instructions on how to manage, block, or delete cookies in your specific browser, please visit the official support pages for Google Chrome, Mozilla Firefox, Apple Safari, or Microsoft Edge. Alternatively, you can visit allaboutcookies.org for a comprehensive independent guide on cookie management.

8. Client Web Properties

This Cookie Policy applies solely to CyberLab.Team OÜ's web properties (cyberlab.team and my.cyberlab.team). It does not govern the websites of our clients. Clients are solely responsible for maintaining their own compliant Cookie Policies on their respective websites in accordance with Google's requirements (e.g., Google Consent Mode v2) and applicable EU and Estonian laws.

Changes to This Policy

We reserve the right to update this Cookie Policy at any time to reflect changes in our technical stack, third-party providers, or legal requirements. Continued use of our Platform and Website signifies your understanding of the current policy.