Product transparency

Cookie and browser-storage notice

What signagenius.com and panel.signagenius.com store in your browser, what is sent to Google before and after you answer the banner, and which parts of this arrangement are still open.

Updated 31 August 2026

Who is responsible, and what this page cannot yet tell you

Magpie Nexus, the company that operates SignaGenius from Spain, decides why and how the site measurement described here happens on signagenius.com and on panel.signagenius.com. For that measurement it is the controller, and it answers for it.

This page is not yet complete. A provider established in Spain has to publish its registered company name, its registered address, its tax identification number, its commercial register entry, and an email address at which it can be contacted. None of those appear on this site yet. A privacy notice also has to give a contact point for data protection questions, and say whether a data protection officer has been designated. Those are missing too. They are not omitted because they do not apply; they are missing because they have not been supplied, and they must be published here before this notice is treated as final.

Until they are, questions about anything on this page can be sent through the contact page on this site.

The record of your choice is kept in your browser only

When you accept or reject on the banner, the answer is written to a first-party cookie called sg_consent. It holds three things: a version number for the disclosure you were shown, the word granted or denied, and the time you answered. It lasts about six months, and it is written on the shared parent domain so the same answer applies on the marketing site and in the signed-in panel.

Your answer is also recorded on our side, because the law asks the operator to be able to demonstrate that consent was given and a value in your own browser does not demonstrate anything. That record holds four things: a random reference, whether you accepted or declined, which version of this notice was on screen, and when. It holds no network address, no browser fingerprint, and no account. The reference is generated in your browser and stored in your own cookie, so you can produce it and we cannot trace it back to you. Records are deleted after three years.

You can change your mind at any time using the control at the top of this page. It shows what this browser currently has recorded and lets you switch analytics on or off in one click. Switching it off also deletes the Google Analytics cookies already in your browser, rather than merely stopping new ones.

Essential authentication storage

Supabase authentication uses browser cookies or equivalent browser storage to establish and refresh a signed-in session. These values are necessary for login, account security, authorization, and session continuity. Disabling them can prevent authenticated parts of the service from working. They are not covered by the banner, because a service you asked for cannot run without them.

Preference storage

The theme control stores the selected light, dark, or system appearance locally. Locale routing can retain or infer the selected language so links and pages continue in the chosen locale. These are your own settings, they stay in your browser, and they build no profile.

Google Tag Manager: nothing loads until you answer

Google Tag Manager is not requested until you accept. Before that, no part of Google is contacted: not the container, not Google Analytics, and nothing that would tell Google you were here. A small script from this site sets the measurement defaults to denied and then waits.

That is stricter than the usual arrangement, in which the container loads immediately and individual tags hold back on the consent signals. The usual arrangement means a visitor who declines still causes a request to Google on every page. This one means declining is what it sounds like.

The denial is the same in every country. No analytics cookie is written, and no request reaches Google, for any visitor anywhere before the banner is answered.

Google Tag Manager is a container rather than a single tool, and further measurement tags can be added to it later without any change to this site's code. Anything loaded through it is covered by this notice and by the answer you gave.

What accepting changes, and what rejecting does not stop

If you accept, Google Analytics 4 is allowed to use browser storage. It sets two cookies, _ga and _ga_BLCD5FN3PW, which by Google's default last up to two years and identify the browser rather than the person using it.

Advertising remains switched off either way. The advertising signals stay denied even after you accept, the container holds no advertising, remarketing, or conversion-linker tag, and Google is told to redact advertising identifiers and not to pass identifiers in link addresses.

If you reject, nothing is sent to Google at all. The container is never requested, no cookie is written, and no signal of any kind - not even a cookieless one - leaves your browser for Google. The decision is remembered for six months so you are not asked on every visit, and the site works exactly as it does for someone who accepted.

One setting does prevent all of it. If your browser sends Do Not Track or Global Privacy Control, no banner is shown, the container is never requested, no analytics cookie is written, and the attribution cookie described below is not written either. That signal is treated as an answer, and the answer is no.

What is sent to Google

For a visitor who has accepted: the address of each page viewed, including any query string, the address of the page that referred you, an approximate location that Google derives from your network address, your device type, browser, operating system, and preferred language, and the interactions the site reports as events, such as opening the signature generator, choosing a template, copying a signature, or clicking a pricing call to action.

The values attached to those events are filtered before they are sent. A single check drops anything named like an email address, a person's name, a phone number, a company, a customer domain, a referrer, or a network address, and drops any value that looks like an email address or a hostname wherever it appears. Nothing typed into the free signature generator is measured: the events record which field was edited first, how many fields were filled, and which template was chosen, never their contents.

The filter applies to event values. Page addresses are handled separately, because the measurement tag reads the address of the page directly: on the two kinds of page whose address is itself sensitive - a public profile page, which is addressed by the name of the person it belongs to, and a self-service page, whose address contains a single-use access token - the tag container is not loaded at all. No measurement of any kind runs on those pages, so neither the name nor the token reaches Google.

Public profile pages are also outside this measurement for a second reason. The person on that page is an employee of a customer rather than a visitor of ours, and views of it are recorded for that customer under their own settings, not for our marketing.

Once a workspace exists, it is identified to Google by a sixteen-character value derived from the workspace identifier by a one-way hash with a secret that is never shared with Google. It cannot be reversed without that secret, and it is pseudonymous rather than anonymous: it still points at one workspace, and it is still personal data under the GDPR.

Measurement sent from our servers

Four events do not happen in a browser and are sent to Google from our own servers instead: a workspace being created, a workspace deploying its first signature, a paid subscription starting, and a subscription being cancelled. They carry the pseudonymous workspace value described above, the first-touch source, the plan, and a coarse bucket for how old the workspace is. They carry no name, address, domain, or account identifier.

Where the visitor who created the workspace had refused consent, none of these are sent at all. The refusal is recorded on the workspace when it is created, and no server-side event is ever sent for it. No identifier is invented to stand in for the missing one.

To make those events join up with the visit they came from, Google's own client and session identifiers are read from its cookies at the moment a workspace is created and stored on the workspace record, together with whether consent was in force and when they were captured. They are kept for as long as that workspace record exists. No shorter retention has been set for them, and one should be.

Google's role, transfers, and retention

Google processes this measurement on the operator's instructions under the data processing terms that apply to a Google Analytics property, which is a processor relationship. Those terms have to be accepted, and the identity of the contracting Google entity recorded, before this measurement starts.

The data can be processed outside the European Economic Area, including in the United States. Where a transfer is not covered by a European Commission adequacy decision, the safeguard relied on is the set of standard contractual clauses contained in Google's data processing terms, and a copy can be requested through the contact address once it is published. This notice deliberately does not name a specific adequacy decision or claim a certification for a specific Google entity, because that has not been verified for this deployment. Verifying it, recording the result in a transfer assessment, and naming the mechanism precisely here is one of the steps still outstanding.

How long Google keeps the event-level data is a setting on the Analytics property. The intended setting is fourteen months, and it has not been confirmed as applied. The exact period must be stated here before this notice is published.

The acquisition attribution cookie

When a visitor arrives from a campaign link or from another website, a single first-party cookie called sg_first_touch records how they arrived: the campaign parameters in the link, the host name of the referring site, and the page they landed on. It is not readable by scripts, it holds no name, address, identifier, or full referring address, it is never shared with another company, and it expires after thirty days. It is not written for a visitor arriving directly, nor for one whose browser sends Do Not Track or Global Privacy Control.

It is read once, when a workspace is created, so that the account can be credited to the channel that introduced it, and it is deleted from the browser at that point. What it contained is copied onto the workspace record first, and that copy is kept for as long as the workspace exists.

This cookie is only written if you accept. It is first-party and it is measurement rather than advertising, but it is not necessary for the service to work, so it waits for the same consent everything else waits for. If you decline, it is never set, and a signup that follows is recorded as having arrived directly.

One consequence is worth being straight about. If you accept on a later page rather than the one you arrived on, the campaign parameters have gone from the address bar and the referring site is no longer visible, so there is nothing left to record and the signup counts as direct. Asking first costs some accuracy here, and that is the right way round.

First-party page counting

Where a cookie-less analytics service is configured, it is loaded from a host the operator runs, counts page views without storing or reading anything in your browser, and makes no third-party request. Because it stores nothing on your device it is not gated by the banner; it still processes your network address in the moment, on the basis of the operator's legitimate interest in knowing how many people read its pages. It is not loaded at all for a visitor whose browser sends Do Not Track or Global Privacy Control.

Where the banner is and is not shown

The banner is shown on the public site. The signed-in panel shows no banner of its own and relies on the answer given on the public site, which it can read because the consent cookie is written on the shared parent domain.

Someone whose first contact is the panel - an employee following a link sent by their own employer, or anyone opening a bookmark - is asked there instead. The banner appears in the panel as well, and the answer is stored on the shared domain, so a decision made in either place is honoured in both and nobody is asked twice.

Cookies set by other companies

When you choose Google or Microsoft sign-in, open Stripe checkout or the billing portal, or follow another flow hosted by a provider, that provider can set its own cookies on its own domain. Those values are governed by that provider's notice, not by this one, and the banner on this site has no control over them.

Managing storage, and complaining about it

Your browser settings can inspect and remove cookies and local storage for this site. Removing the session values signs you out. Removing the preference values resets appearance and language. Removing the attribution cookie means a later signup is recorded as direct. Removing the consent cookie brings the banner back.

If you are in the European Economic Area you can complain to a supervisory authority about any of this. For a company established in Spain that is the Agencia Española de Protección de Datos, at www.aepd.es, and you may also complain to the authority where you live or work.