Sandbox environment: no real transactions are processed.

Public document

Raims Cookie Policy

This Policy explains how Raims uses cookies, local storage, technical identifiers, pixels, tags, and similar technologies across its sites, platform, public pages, and payment experiences. Before consent, Raims uses only cookies and technologies that are strictly necessary for security, session, operational preferences, checkout integrity, and platform operation. Optional metrics, advertising, or marketing cookies are only enabled after the user's valid acceptance, while considering the LGPD, ANPD guidance, the Brazilian Internet Civil Framework, and the available consent choices.

1

When this Policy applies

This Policy applies to the use of cookies and similar technologies on Raims official surfaces, including the public site, institutional pages, platform environment, support, communications, authentication flows, and payment pages made available by Raims.

We use cookies to refer to small pieces of information stored in the user's browser or device, as well as equivalent technologies such as local storage, session identifiers, pixels, tags, technical records, SDKs, and measurement mechanisms that may recognize a visit, preserve a choice, or record an interaction.

When cookies or similar technologies involve personal data, processing also follows Raims Privacy Policy. This Cookie Policy complements the Privacy Policy and explains categories, purposes, and management options more specifically.

2

Cookie and similar technology categories

Raims organizes these technologies by purpose. Before the user's choice, optional categories remain disabled and only technologies necessary for operation stay active. Availability of each category may vary according to the product, accessed route, environment, and integrations actually enabled.

Necessary

Support authentication, session, security, fraud prevention, routing, language preference, checkout integrity, abuse protection, availability, and essential operation. They are not used for behavioral advertising and cannot be disabled in the banner because the platform depends on them to operate.

Metrics and performance

Help understand stability, performance, availability, accessed routes, errors, aggregate feature usage, and experience improvements. When not strictly necessary, they should only be activated after the user's valid consent. Tools approved for this purpose must operate with IP-address anonymization or masking enabled before storage whenever navigation telemetry is collected.

Marketing and advertising

May support campaign measurement, institutional communications, remarketing, ad attribution, or conversion evaluation. When used, they depend on consent and should not load before the user's valid choice.

Descriptive table of cookies and technologies

The table below describes the main cookies and similar technologies used or contemplated on Raims official surfaces. The list may vary by environment, route, and enabled provider; optional categories must only load when configured and consented to.

Cookie/technology
__Host-sessionToken / sessionToken
Category
Necessary
Responsible party
Raims
Purpose and retention
Maintains the authenticated session through an opaque HttpOnly token. It expires according to the session policy: after up to 3 hours of inactivity and no later than 24 hours; when the remember-session option applies, after up to 48 hours of inactivity and no later than 7 days.
Cookie/technology
raims_cookie_consent
Category
Necessary
Responsible party
Raims
Purpose and retention
Records consent choices for optional categories in a compact format without sensitive data. It is automatically valid for 12 (twelve) months or until removed by the user, browser, or Raims.
Cookie/technology
__Host-trustedDeviceToken / trustedDeviceToken
Category
Necessary
Responsible party
Raims
Purpose and retention
Recognizes a trusted device for security controls and multifactor authentication when applicable. Retained for up to 30 days or until revocation, security logout, or browser removal.
Cookie/technology
__Host-googleAuthHandoff / googleAuthHandoff
Category
Necessary
Responsible party
Raims
Purpose and retention
Temporarily correlates the Google sign-in return with the browser without exposing the OAuth result in the URL. Short retention of up to 120 seconds and single use.
Cookie/technology
locale
Category
Necessary
Responsible party
Raims
Purpose and retention
Local storage used to preserve the user's language and regional experience. It remains until the preference is changed or removed by the user or browser.
Cookie/technology
auth-session
Category
Necessary
Responsible party
Raims
Purpose and retention
Local storage used to maintain session navigation state and data displayed in the dashboard. It remains until logout, session expiration or revocation, replacement of the local state, or removal by the user or browser; it does not replace the HttpOnly cookie or server-side validation.
Cookie/technology
theme / summary-dashboard
Category
Necessary
Responsible party
Raims
Purpose and retention
Local storage used to preserve operational interface preferences, such as theme, layout, summary period, and balance visibility. It remains until the preference is changed or removed by the user, browser, or Raims.
Cookie/technology
Temporary states in sessionStorage
Category
Necessary
Responsible party
Raims
Purpose and retention
Temporarily stores security challenges, sensitive authorization, password recovery, sign-in return, and loading recovery only in the current tab. Retention is limited to the tab's lifetime, completion or cancellation of the flow, challenge expiration, or automatic cleanup when the record becomes invalid.
Cookie/technology
Google identity provider cookies
Category
Necessary when Google sign-in is used
Responsible party
Google LLC
Purpose and retention
May be used on Google domains for authentication, security, and continuity of the OAuth flow. Retention follows the provider's policy and the user's choices in the Google environment.
Cookie/technology
Metrics cookies or pixels
Category
Metrics and performance
Responsible party
Raims or enabled provider
Purpose and retention
Only when configured and consented to, they measure stability, performance, accessed routes, and aggregate usage. Approved tools must anonymize or mask the IP address before storage when navigation telemetry is collected. Retention depends on the enabled tool and must respect the consent choice.
Cookie/technology
Marketing cookies, pixels, or tags
Category
Marketing and advertising
Responsible party
Raims or enabled provider
Purpose and retention
Only when configured and consented to, they support campaign measurement, attribution, and institutional communications. Retention depends on the enabled tool and must respect the consent choice.
3

Legal bases and purpose

Necessary cookies may be used to perform contracts, enable requested functionality, comply with legal or regulatory obligations, prevent fraud, protect the data subject and platform security, exercise rights, and maintain indispensable technical records.

Non-essential metrics, advertising, and marketing cookies depend on prior consent. Raims should not insert, load, or trigger those categories before the user's valid acceptance.

Technical records and logs may be retained for security, audit, abuse prevention, incident investigation, compliance with obligations, and defense of rights, respecting applicable law and the timeframes needed for each context.

4

How to manage preferences

When a surface allows optional cookies, Raims may show a banner or preference panel to accept all, refuse optional cookies, or adjust categories. Before that choice, optional cookies remain disabled. The choice is stored in the browser in a compact format without sensitive data.

The user may change preferences through controls provided in the experience when available. Refusing optional cookies keeps only necessary cookies and does not block essential functionality, but may reduce measurement, personalization, campaigns, and improvements based on aggregate data.

In addition to Raims controls, the browser may allow users to block, remove, or limit cookies and local storage. That configuration is external to Raims and may affect login, session, language, checkout, security, or other necessary functionality.

  • Accept all keeps necessary cookies and authorizes metrics and marketing when those categories are enabled.
  • Reject all keeps only necessary cookies and keeps optional categories controlled by local consent blocked.
  • Manage cookies allows optional categories to be selected separately when the interface presents that option.
5

Third parties, partners, and transfers

Raims may use infrastructure, security, hosting, monitoring, support, analytics, communication, and marketing providers that process data on behalf of Raims or according to their own contractual and legal responsibilities. These providers should only be used when necessary for the service or stated purposes.

Raims does not sell personal data. Cookies and identifiers should not be used to commercialize personal information of users, business customers, payers, or visitors.

When processing or storage occurs outside Brazil, Raims will adopt mechanisms compatible with the LGPD, applicable contracts, and practices proportional to risk. Use of third-party technology may involve global infrastructure according to the purpose and provider.

6

Retention, security, and limits

Cookies may remain in the browser for the period defined for each purpose or until removed by the user, browser, or Raims. The local cookie that stores the user's privacy preferences is automatically valid for 12 (twelve) months. After that period, the preference expires and the preferences panel may be displayed again to renew consent.

Raims applies technical and administrative measures to protect records and identifiers against improper access, loss, alteration, unauthorized disclosure, or incompatible use. Even so, users must keep their browser, device, email, password, MFA, and session protected.

7

Rights, updates, and contact

Under the LGPD, data subjects may request information, access, correction, deletion when applicable, consent revocation, objection to unlawful processing, and other rights provided by law. Requests involving end customers may depend on the business customer acting as controller.

This Policy may be updated to reflect legal, regulatory, technical, operational, product, provider, or cookie category changes. When a material change affects categories, purposes, providers, retention, or privacy choices, Raims will notify applicable users through a banner, preferences panel, registered email, dashboard notice, or another reasonable channel. If the change requires new or renewed consent, optional technologies will not be activated before a valid choice. Merely editorial changes, corrections, or clarifications without a material change may be made by updating the version and date without individual notice. Urgent security changes or changes required by law may take effect immediately, with notice where applicable and as soon as reasonably possible.

Questions, privacy requests, or cookie-related requests may be sent to dpo@raims.com.