Cookie Policy
Last updated: 3 August 2026
1. About this policy
This Cookie Policy explains how Job Avion ("we", "us") uses cookies and similar local-storage technologies on our website and web application, and the choices available to you. It should be read together with our Privacy Policy. We use these technologies in line with the EU General Data Protection Regulation (GDPR), the ePrivacy Directive, and applicable national law.
2. What are cookies and local storage?
Cookies are small text files stored on your device by your browser. We also use the browser's localStorage and sessionStorage, which work similarly but keep data on your device rather than sending it with every request. In this policy we refer to all of these collectively as "cookies".
- Strictly necessary — required for the service to function (sign-in, security, your language and consent choice). These do not require consent but are listed below for transparency.
- Preferences — remember optional, non-essential choices to personalise your experience. Used only with your consent.
- Analytics — would help us understand anonymous, aggregated usage. Not active today; reserved for future use and used only with your consent.
- Marketing — lets us measure whether an advert brought you to the site, and can let the advertising provider recognise your browser across other sites. Used only with your consent; the items are listed in table 3.4.
2.1 How long each item lives
- Session items disappear the moment you close the browser tab. We use these only as short-lived caches, to avoid asking our own servers for the same thing twice while you are working.
- Persistent items remain on your device after you close the browser, so that a choice you made once — your language, your consent, your notification-sound setting — is still there when you come back. They stay until they expire or until you clear them.
- You can delete either kind at any time from your browser, and you can delete our persistent items without deleting anything belonging to another website.
2.2 The legal basis
Article 5(3) of the ePrivacy Directive allows storage on your device without consent only where it is strictly necessary to provide the service you asked for. That is the basis for everything in table 3.1, and only for those items. Everything in tables 3.2, 3.3 and 3.4 requires your consent under Article 5(3) ePrivacy and Article 6(1)(a) GDPR, and we do not place it until you have given that consent.
2.3 What we do not do
- We do not set advertising or cross-site tracking cookies unless you switch the Marketing category on. While it is off, nothing in table 3.4 exists on your device and the advertising script is never even fetched. There is no social-network tracking widget anywhere on the site or in the app.
- We do not build advertising profiles about you and we do not sell or share your data with data brokers or ad networks.
- We do not use device fingerprinting, and we do not try to identify you across other websites.
- We do not put the platform behind a cookie wall. Rejecting every optional item costs you nothing — you keep full access to the service, and the only difference is that some conveniences will not be remembered between visits.
- We do not design the banner to push you towards "accept". Accepting and rejecting are equally easy and equally prominent, and there is no pre-ticked box.
3. Cookies and storage we use
4. Third-party services
All cosmetic assets (web fonts, flag images, map libraries and scripts) are served directly from our own domain — no third party receives your IP address for these. The only services your browser contacts directly, strictly when you use the related feature (e.g. viewing a map), are:
- Map tiles (CARTO / OpenStreetMap) — interactive maps load their background imagery from CARTO (basemaps.cartocdn.com) on our homepage and from OpenStreetMap inside the app. Your browser requests the map images directly from these providers, which technically transmits your IP address. No cookies are set. See CARTO Privacy Notice and OSMF Privacy Policy.
- Real-time messaging (WebSocket) — notifications and messaging within the app connect to our messaging infrastructure (operated by our hosting provider under a data processing agreement). Strictly necessary for the app's real-time features.
- Stripe — payment processing (only on payment pages). See Stripe Privacy Policy.
- Google OAuth — optional "Sign in with Google" authentication. See Google Privacy Policy.
- OpenAI Whisper — optional voice-to-text transcription in Avion Copilot (via our AI provider). The audio file is deleted immediately after transcription; no cookies are set. See OpenAI Privacy Policy.
5. Managing and withdrawing your consent
You can change or withdraw your choices at any time — withdrawing consent is as easy as giving it:
- Use the "Cookie settings" link in the footer of any page, or the button below, to reopen your preferences.
- You can also clear cookies and site data through your browser settings. Note that blocking strictly necessary items may stop parts of the platform from working.
5.1 What happens when you withdraw
Withdrawal takes effect immediately and applies from that moment forward. It does not undo anything that lawfully happened while your consent was in force, which is what Article 7(3) GDPR means when it says withdrawal does not affect the lawfulness of processing already carried out. In practice: the optional items stop being written, and the ones already on your device can be cleared from your browser at any time. Nothing about your account, your data or your access changes.
5.2 The record we keep of your choice
Your choice is stored on your own device, together with the date you made it and the version of this policy it relates to. We keep it so that we do not ask you the same question on every page, and so that we can show, if we are ever asked, that consent was given rather than assumed. If we materially change the categories, the stored version no longer matches and you will be asked again. Your choice is per browser and per device: choosing on your laptop does not change anything on your phone.
5.3 Controlling this in your browser
Every major browser lets you see, block and delete cookies and site data independently of us. The relevant settings are documented by each vendor: Chrome, Firefox, Safari and Edge. Private or incognito windows discard everything when you close them, which also means you will see the consent banner again each time.
We do not currently act on the "Do Not Track" header, which was never standardised and which most sites ignore. It makes little practical difference here: the only items that could be called tracking are in table 3.4, and those require you to switch the Marketing category on.
6. Advertising
We are a new platform and we run advertising campaigns to tell people that it exists. The Marketing category was added to the banner before any advertising tool existed, and every stored choice was reset at that point, so that nobody's earlier answer to a shorter question could be read as agreement to this one. It now controls two conversion tags — Google Ads and the Meta Pixel — which measure whether an advert we paid for ended in a sign-up.
Both tags are loaded by the same gate and behave identically: the script is fetched only after you switch the category on, and switching it off again stops the next send and clears the items listed in table 3.4 from your browser. We have deliberately left off the options each provider offers for sending us more than that — Google's enhanced conversions and Meta's automatic advanced matching, which would transmit a hashed form of your e-mail address or telephone number, and Meta's Conversions API, which would send the event from our server and so bypass this gate entirely. What reaches them is the fact that a sign-up happened and the identifier in the table, nothing that identifies you by name.
What this commits us to:
- The Marketing category is off by default and stays off unless you switch it on yourself.
- Not a single byte reaches an advertising provider while it is off. We gate the loading of the script itself, not merely the consent signal sent to it — so nothing contacts Google or Meta at all, not even to be told "no".
- Table 3.4 above names the provider, the exact items and their duration. It is updated before a new provider is switched on, never afterwards.
- Rejecting it costs you nothing. You keep the full service; the only thing we lose is the ability to tell which advert worked.
We will not quietly add tracking to an existing consent.
7. Server logs are not cookies
Separately from anything stored on your device, our servers keep ordinary technical logs of requests — IP address, time, page requested, browser type — which are needed to run the service securely and to investigate abuse. This is not cookie-based, does not require consent, and rests on our legitimate interest in keeping the platform available and secure. Retention is set out in section 12 of the Privacy Policy.
8. Changes to this policy
If we materially change how we use cookies — for example, when analytics is introduced — we will update this policy and, where required, ask for your consent again through the cookie banner.
9. Complaints
If you believe we have handled cookies or your consent improperly, please write to us first at office@jobavion.com. You also have the right to complain to the Bulgarian Commission for Personal Data Protection (Комисия за защита на личните данни), Prof. Tsvetan Lazarov Blvd. 2, Sofia 1592, cpdp.bg, or to the supervisory authority in your own EU country of residence.
10. Contact & Data Controller
- Data Controller: Avion Technic Ltd.
- Company ID (EIK): 208530294
- VAT ID: BG208530294
- Address: j.k. Mladost 3, bl. 376, ent. 1, fl. 8, app. 35, 1712 Sofia, Bulgaria
- Email: office@jobavion.com