This Cookie Policy explains how DealQ Ltd. (“DealQ,” “we,” “us,” or “our”) uses cookies and similar browser-storage technologies when you use DealQ and its related websites, applications, and services (the “Service”). It supplements our Privacy Policy and our Terms and Conditions.
1. What Are Cookies?
Cookies are small text files placed on your device by a website you visit. They are widely used to make websites work, to improve the user experience, and to provide information to the operators of the site.
Cookie and storage keys are prefixed negoiq_, DealQ’s internal codename; they are set by DealQ. This Policy also covers other browser-storage technologies we rely on, including localStorage and sessionStorage. These work similarly to cookies — they store small pieces of data in your browser — but they are accessed by the Service’s JavaScript rather than transmitted with every HTTP request.
2. How We Use Cookies and Browser Storage
We use cookies and browser storage only for strictly necessary and functional purposes — to authenticate you, keep your session secure, protect against cross-site request forgery, and remember interface preferences such as whether the sidebar is collapsed.
We do not use any third-party advertising, marketing, analytics, or behavioral-tracking cookies. We do not embed third-party trackers, pixels, or tag managers in the Service. We do not sell or share cookie data with advertisers or data brokers.
3. Cookies We Set
3.1 Strictly Necessary Cookies (First-Party)
These cookies are essential for the Service to function. You cannot use the Service without them.
| Cookie | Purpose | Type | Duration |
|---|---|---|---|
negoiq_at / __Host-negoiq_at |
Carries your short-lived access token so the server can identify your authenticated requests. | HttpOnly, SameSite=Lax, Secure (in production) | Short-lived (refreshed automatically) |
negoiq_rt / __Secure-negoiq_rt |
Carries your refresh token, used only against the token-refresh endpoint to issue a new access token. | HttpOnly, SameSite=Lax, Secure (in production), scoped to /api/v1/auth/refresh |
Up to 7 days |
oauth_state |
Anti-CSRF nonce used during the “Sign in with Google” flow to ensure the OAuth callback is the one you initiated. | HttpOnly, SameSite=Lax | 5 minutes |
3.2 Functional Cookies (First-Party)
These cookies remember your interface preferences. They are not required for the Service to work, but disabling them will reset preferences on each visit.
| Cookie | Purpose | Type | Duration |
|---|---|---|---|
sidebar_state |
Remembers whether your application sidebar is expanded or collapsed. | Set by the browser via client-side JavaScript | 7 days |
4. Browser Storage We Use
In addition to cookies, the Service stores a small amount of data in your browser’s localStorage and sessionStorage. These are used solely to operate the Service.
4.1 localStorage
| Key | Purpose |
|---|---|
negoiq_user |
Caches a copy of your account profile (id, email, name, picture, linked sign-in providers) so the app can render the signed-in UI before the server confirms the session. Cleared on sign-out. |
negoiq_business |
Caches your current workspace context (workspace id, name, email, logo, domain). Cleared on sign-out or when you switch workspaces. |
negoiq_workspace_name_banner_dismissed |
Remembers which workspaces you’ve dismissed the rename banner in, so we don’t show it again. |
negoiq_admin_user |
The equivalent of negoiq_user for the separate Admin surface, used only by internal administrative users. |
sidebar_state |
A mirror of the sidebar preference described above, used by the app’s UI shell. |
4.2 sessionStorage
| Key | Purpose |
|---|---|
negoiq_debugging |
Set when you load a page with ?debugging=true in the URL. Enables additional in-browser diagnostics for the current tab and is cleared when the tab closes. |
5. Third-Party Cookies
We do not use third-party cookies. The Service does not load Google Analytics, Google Tag Manager, Meta/Facebook Pixel, LinkedIn Insight, TikTok Pixel, HubSpot, Intercom, Hotjar, FullStory, Mixpanel, PostHog, or any equivalent third-party tracking or marketing technology. The Service also does not embed third-party widgets (such as YouTube, social-media share buttons, or chat overlays) that would set cookies on your device.
If a Third-Party AI Provider sets cookies during their own back-end processing of your User Content, those cookies are set on the provider’s domain and are governed by that provider’s privacy policy — they are not set by, and not readable by, DealQ in your browser.
6. Your Choices
You can control cookies and browser storage at any time using your browser’s settings:
- Block or delete cookies through your browser preferences. Note that blocking the strictly necessary cookies listed in Section 3.1 will prevent you from signing in and using the Service.
- Clear browser storage by clearing site data for the DealQ domain. This will sign you out and reset interface preferences.
- Private / incognito browsing prevents most storage from persisting after you close the window.
For instructions, see the help pages for your browser:
Because we do not run analytics or advertising cookies, there is no consent banner or category-level opt-out to configure within the Service itself.
7. Changes to This Cookie Policy
We may update this Cookie Policy from time to time to reflect changes in the cookies and storage we use, or for other operational, legal, or regulatory reasons. Material changes will be communicated through the Service or by other reasonable means. The “Last Updated” date above indicates when this Policy was last revised.
8. Contact Us
For questions about this Cookie Policy, contact us at:
DealQ Ltd. Email: manuel@dealq.io