Public document
Raims Cookie Policy
This Policy explains how Raims uses cookies, local storage, technical identifiers, pixels, tags, and similar technologies across its sites, platform, public pages, and payment experiences. Before consent, Raims uses only cookies and technologies that are strictly necessary for security, session, operational preferences, checkout integrity, and platform operation. Optional metrics, advertising, or marketing cookies are only enabled after the user's valid acceptance, while considering the LGPD, ANPD guidance, the Brazilian Internet Civil Framework, and the available consent choices.
When this Policy applies
This Policy applies to the use of cookies and similar technologies on Raims official surfaces, including the public site, institutional pages, platform environment, support, communications, authentication flows, and payment pages made available by Raims.
We use cookies to refer to small pieces of information stored in the user's browser or device, as well as equivalent technologies such as local storage, session identifiers, pixels, tags, technical records, SDKs, and measurement mechanisms that may recognize a visit, preserve a choice, or record an interaction.
When cookies or similar technologies involve personal data, processing also follows Raims Privacy Policy. This Cookie Policy complements the Privacy Policy and explains categories, purposes, and management options more specifically.
Cookie and similar technology categories
Raims organizes these technologies by purpose. Before the user's choice, optional categories remain disabled and only technologies necessary for operation stay active. Availability of each category may vary according to the product, accessed route, environment, and integrations actually enabled.
Necessary
Support authentication, session, security, fraud prevention, routing, language preference, checkout integrity, abuse protection, availability, and essential operation. They are not used for behavioral advertising and cannot be disabled in the banner because the platform depends on them to operate.
Metrics and performance
Help understand stability, performance, availability, accessed routes, errors, aggregate feature usage, and experience improvements. When not strictly necessary, they should only be activated after the user's valid consent. Tools approved for this purpose must operate with IP-address anonymization or masking enabled before storage whenever navigation telemetry is collected.
Marketing and advertising
May support campaign measurement, institutional communications, remarketing, ad attribution, or conversion evaluation. When used, they depend on consent and should not load before the user's valid choice.
Descriptive table of cookies and technologies
The table below describes the main cookies and similar technologies used or contemplated on Raims official surfaces. The list may vary by environment, route, and enabled provider; optional categories must only load when configured and consented to.
- Cookie/technology
- __Host-sessionToken / sessionToken
- Category
- Necessary
- Responsible party
- Raims
- Purpose and retention
- Maintains the authenticated session through an opaque HttpOnly token. It expires according to the session policy: after up to 3 hours of inactivity and no later than 24 hours; when the remember-session option applies, after up to 48 hours of inactivity and no later than 7 days.
- Cookie/technology
- raims_cookie_consent
- Category
- Necessary
- Responsible party
- Raims
- Purpose and retention
- Records consent choices for optional categories in a compact format without sensitive data. It is automatically valid for 12 (twelve) months or until removed by the user, browser, or Raims.
- Cookie/technology
- __Host-trustedDeviceToken / trustedDeviceToken
- Category
- Necessary
- Responsible party
- Raims
- Purpose and retention
- Recognizes a trusted device for security controls and multifactor authentication when applicable. Retained for up to 30 days or until revocation, security logout, or browser removal.
- Cookie/technology
- __Host-googleAuthHandoff / googleAuthHandoff
- Category
- Necessary
- Responsible party
- Raims
- Purpose and retention
- Temporarily correlates the Google sign-in return with the browser without exposing the OAuth result in the URL. Short retention of up to 120 seconds and single use.
- Cookie/technology
- locale
- Category
- Necessary
- Responsible party
- Raims
- Purpose and retention
- Local storage used to preserve the user's language and regional experience. It remains until the preference is changed or removed by the user or browser.
- Cookie/technology
- auth-session
- Category
- Necessary
- Responsible party
- Raims
- Purpose and retention
- Local storage used to maintain session navigation state and data displayed in the dashboard. It remains until logout, session expiration or revocation, replacement of the local state, or removal by the user or browser; it does not replace the HttpOnly cookie or server-side validation.
- Cookie/technology
- theme / summary-dashboard
- Category
- Necessary
- Responsible party
- Raims
- Purpose and retention
- Local storage used to preserve operational interface preferences, such as theme, layout, summary period, and balance visibility. It remains until the preference is changed or removed by the user, browser, or Raims.
- Cookie/technology
- Temporary states in sessionStorage
- Category
- Necessary
- Responsible party
- Raims
- Purpose and retention
- Temporarily stores security challenges, sensitive authorization, password recovery, sign-in return, and loading recovery only in the current tab. Retention is limited to the tab's lifetime, completion or cancellation of the flow, challenge expiration, or automatic cleanup when the record becomes invalid.
- Cookie/technology
- Google identity provider cookies
- Category
- Necessary when Google sign-in is used
- Responsible party
- Google LLC
- Purpose and retention
- May be used on Google domains for authentication, security, and continuity of the OAuth flow. Retention follows the provider's policy and the user's choices in the Google environment.
- Cookie/technology
- Metrics cookies or pixels
- Category
- Metrics and performance
- Responsible party
- Raims or enabled provider
- Purpose and retention
- Only when configured and consented to, they measure stability, performance, accessed routes, and aggregate usage. Approved tools must anonymize or mask the IP address before storage when navigation telemetry is collected. Retention depends on the enabled tool and must respect the consent choice.
- Cookie/technology
- Marketing cookies, pixels, or tags
- Category
- Marketing and advertising
- Responsible party
- Raims or enabled provider
- Purpose and retention
- Only when configured and consented to, they support campaign measurement, attribution, and institutional communications. Retention depends on the enabled tool and must respect the consent choice.
| Cookie/technology | Category | Responsible party | Purpose and retention |
|---|---|---|---|
| __Host-sessionToken / sessionToken | Necessary | Raims | Maintains the authenticated session through an opaque HttpOnly token. It expires according to the session policy: after up to 3 hours of inactivity and no later than 24 hours; when the remember-session option applies, after up to 48 hours of inactivity and no later than 7 days. |
| raims_cookie_consent | Necessary | Raims | Records consent choices for optional categories in a compact format without sensitive data. It is automatically valid for 12 (twelve) months or until removed by the user, browser, or Raims. |
| __Host-trustedDeviceToken / trustedDeviceToken | Necessary | Raims | Recognizes a trusted device for security controls and multifactor authentication when applicable. Retained for up to 30 days or until revocation, security logout, or browser removal. |
| __Host-googleAuthHandoff / googleAuthHandoff | Necessary | Raims | Temporarily correlates the Google sign-in return with the browser without exposing the OAuth result in the URL. Short retention of up to 120 seconds and single use. |
| locale | Necessary | Raims | Local storage used to preserve the user's language and regional experience. It remains until the preference is changed or removed by the user or browser. |
| auth-session | Necessary | Raims | Local storage used to maintain session navigation state and data displayed in the dashboard. It remains until logout, session expiration or revocation, replacement of the local state, or removal by the user or browser; it does not replace the HttpOnly cookie or server-side validation. |
| theme / summary-dashboard | Necessary | Raims | Local storage used to preserve operational interface preferences, such as theme, layout, summary period, and balance visibility. It remains until the preference is changed or removed by the user, browser, or Raims. |
| Temporary states in sessionStorage | Necessary | Raims | Temporarily stores security challenges, sensitive authorization, password recovery, sign-in return, and loading recovery only in the current tab. Retention is limited to the tab's lifetime, completion or cancellation of the flow, challenge expiration, or automatic cleanup when the record becomes invalid. |
| Google identity provider cookies | Necessary when Google sign-in is used | Google LLC | May be used on Google domains for authentication, security, and continuity of the OAuth flow. Retention follows the provider's policy and the user's choices in the Google environment. |
| Metrics cookies or pixels | Metrics and performance | Raims or enabled provider | Only when configured and consented to, they measure stability, performance, accessed routes, and aggregate usage. Approved tools must anonymize or mask the IP address before storage when navigation telemetry is collected. Retention depends on the enabled tool and must respect the consent choice. |
| Marketing cookies, pixels, or tags | Marketing and advertising | Raims or enabled provider | Only when configured and consented to, they support campaign measurement, attribution, and institutional communications. Retention depends on the enabled tool and must respect the consent choice. |
Legal bases and purpose
Necessary cookies may be used to perform contracts, enable requested functionality, comply with legal or regulatory obligations, prevent fraud, protect the data subject and platform security, exercise rights, and maintain indispensable technical records.
Non-essential metrics, advertising, and marketing cookies depend on prior consent. Raims should not insert, load, or trigger those categories before the user's valid acceptance.
Technical records and logs may be retained for security, audit, abuse prevention, incident investigation, compliance with obligations, and defense of rights, respecting applicable law and the timeframes needed for each context.
How to manage preferences
When a surface allows optional cookies, Raims may show a banner or preference panel to accept all, refuse optional cookies, or adjust categories. Before that choice, optional cookies remain disabled. The choice is stored in the browser in a compact format without sensitive data.
The user may change preferences through controls provided in the experience when available. Refusing optional cookies keeps only necessary cookies and does not block essential functionality, but may reduce measurement, personalization, campaigns, and improvements based on aggregate data.
In addition to Raims controls, the browser may allow users to block, remove, or limit cookies and local storage. That configuration is external to Raims and may affect login, session, language, checkout, security, or other necessary functionality.
- Accept all keeps necessary cookies and authorizes metrics and marketing when those categories are enabled.
- Reject all keeps only necessary cookies and keeps optional categories controlled by local consent blocked.
- Manage cookies allows optional categories to be selected separately when the interface presents that option.
Third parties, partners, and transfers
Raims may use infrastructure, security, hosting, monitoring, support, analytics, communication, and marketing providers that process data on behalf of Raims or according to their own contractual and legal responsibilities. These providers should only be used when necessary for the service or stated purposes.
Raims does not sell personal data. Cookies and identifiers should not be used to commercialize personal information of users, business customers, payers, or visitors.
When processing or storage occurs outside Brazil, Raims will adopt mechanisms compatible with the LGPD, applicable contracts, and practices proportional to risk. Use of third-party technology may involve global infrastructure according to the purpose and provider.
Retention, security, and limits
Cookies may remain in the browser for the period defined for each purpose or until removed by the user, browser, or Raims. The local cookie that stores the user's privacy preferences is automatically valid for 12 (twelve) months. After that period, the preference expires and the preferences panel may be displayed again to renew consent.
Raims applies technical and administrative measures to protect records and identifiers against improper access, loss, alteration, unauthorized disclosure, or incompatible use. Even so, users must keep their browser, device, email, password, MFA, and session protected.
Rights, updates, and contact
Under the LGPD, data subjects may request information, access, correction, deletion when applicable, consent revocation, objection to unlawful processing, and other rights provided by law. Requests involving end customers may depend on the business customer acting as controller.
This Policy may be updated to reflect legal, regulatory, technical, operational, product, provider, or cookie category changes. When a material change affects categories, purposes, providers, retention, or privacy choices, Raims will notify applicable users through a banner, preferences panel, registered email, dashboard notice, or another reasonable channel. If the change requires new or renewed consent, optional technologies will not be activated before a valid choice. Merely editorial changes, corrections, or clarifications without a material change may be made by updating the version and date without individual notice. Urgent security changes or changes required by law may take effect immediately, with notice where applicable and as soon as reasonably possible.
Questions, privacy requests, or cookie-related requests may be sent to dpo@raims.com.