Cookie Policy

Last updated: 2026-09-01

This Cookie Policy describes how GiBSeS OÜ (Estonian registry code 17231761, registered office Juhkentali tn 8, 10132 Tallinn, Estonia) uses cookies and similar technologies on gibses.com and rocket.gibses.com. The only cookies actually used are strictly technical ones, necessary for the site to function: they do not require prior consent, which is why no cookie banner is shown. Traffic analysis is performed using Umami, a self-hosted analytics tool that does not use cookies or persistent identifiers.

1. What cookies are

Cookies are small text files that the browser stores on your device when you visit a website. They allow the site to recognize the device on subsequent visits and to remember preferences and authentication state. Similar technologies (e.g. local storage) are treated in this policy in the same way as cookies.

2. Legal basis

All cookies actually used on gibses.com and rocket.gibses.com are technical cookies, strictly necessary to provide the service requested by the user (Art. 5.3 of the ePrivacy Directive 2002/58/EC, transposed in Estonia by the Electronic Communications Act): their installation does not require consent. The site does not install profiling, marketing or analytics cookies subject to consent, and therefore does not show a cookie banner. Traffic analysis via Umami falls outside the scope of Art. 5.3 ePrivacy: the tool is configured in cookieless mode and does not store or read any information on the user's device.

3. Categories of cookies and other data collected

Technical cookies — essential for the site to function (managing the promotional popup, recognizing returning visitors, authentication in the members area). No consent required. Analytics — traffic is analyzed with Umami, self-hosted on GiBSeS infrastructure and configured without cookies: it uses no persistent identifiers, does not track users across sites, and the data stays on GiBSeS infrastructure without being shared with third parties. Marketing and profiling — not used. No advertising pixels, no third-party tools for profiling purposes. Server access logs — for security and diagnostic purposes the server records access logs (IP address, requested page, date and time, user agent), with limited retention. These are not cookies, but data processed directly by the server as part of its normal operation.

4. Cookie list

Technical cookies set by gibses.com: • eb_popup_dismissed — remembers that you dismissed the promotional popup, so it is not shown again — first-party — duration configurable (set by the site administrator) • gb_returning — recognizes returning visitors, solely for the popup display logic — first-party — duration 1 year Technical cookies set by rocket.gibses.com: • gibses-sales-session — user authentication in the members area — first-party, httpOnly — duration 30 days • gibses_ref — affiliate code pending application at checkout — first-party — duration 30 days • gibses-sales-google-state — cross-site request forgery (CSRF) protection during Google sign-in — first-party, httpOnly — duration 5 minutes • gibses-sales-google-verifier — PKCE verification for the Google authentication flow — first-party, httpOnly — duration 5 minutes • gibses-sales-google-locale — retains the selected language during the redirect to Google — first-party, httpOnly — duration 5 minutes No analytics, marketing or profiling cookie is set on either domain. This list is updated whenever the cookie inventory changes.

5. Managing your preferences

Since no cookie in use requires consent, the site does not show a preference management banner. You can still delete or block cookies at any time through your browser settings. Disabling technical cookies does not prevent access to the site's public content, but on rocket.gibses.com it will prevent access to the members area and the automatic application of an affiliate code. For the most common browsers: Chrome (chrome://settings/cookies), Firefox (about:preferences#privacy), Safari (Preferences → Privacy), Edge (edge://settings/privacy).

6. Third-party services

Some integrated services may set their own cookies: • Stripe (stripe.com/privacy) — during checkout, for fraud prevention and 3D Secure authentication. • Resend (resend.com/privacy) — tracking pixel in transactional emails for delivery and open metrics (opt-out via account preferences). Their privacy notices are available at the links above. These parties act as autonomous data controllers for data collected via their own cookies.

7. Transfers outside the EU

Some providers (Stripe, Resend) may transfer data outside the European Economic Area. Such transfers are covered by adequate safeguards under Arts. 44-49 GDPR (EU Standard Contractual Clauses adopted by the Commission, adequacy decisions where available).

8. Data subject rights

As a data subject you have the right to access, rectify, erase, restrict and port your data, to object to processing, and to withdraw consent at any time (Arts. 15-22 GDPR). You also have the right to lodge a complaint with the Estonian data protection authority (Andmekaitse Inspektsioon, www.aki.ee) or the Authority of your EU country of residence. To exercise your rights write to info@gibses.com.

9. Updates

This Cookie Policy is reviewed at least annually and whenever the cookie inventory changes. The current version is always available on this page with the "Last updated" date indicated at the top.

Last review: 1 September 2026. GiBSeS OÜ — registry no. 17231761 — Juhkentali tn 8, 10132 Tallinn, Estonia. Questions: info@gibses.com.