Cookie Policy

Last updated: June 30, 2025

Cookie Policy

Effective Date: June 30, 2025

This Cookie Policy explains how NotionSync uses cookies and similar technologies to provide our form builder service and Notion integration platform.

1. What Are Cookies?

Cookies are small text files stored on your device when you visit our website. They help us provide essential functionality like keeping you logged in and protecting your account security.

2. Our Approach to Cookies

NotionSync takes a privacy-first approach to cookies. We only use cookies that are essential for our service to function properly. We do not use advertising, marketing, or cross-site tracking cookies.

3. Cookies We Use

3.1 Essential Cookies (Required)

These cookies are necessary for NotionSync to function and cannot be disabled:

Cookie NamePurposeDurationLegal Basis
session-tokenKeep you logged in securely30 daysContract performance
csrf-tokenProtect against cross-site request forgery attacksSessionLegitimate interest (security)
auth-stateManage authentication flow and Notion OAuthSessionContract performance
form-builder-statePreserve your form building progressSessionContract performance

3.2 Functional Cookies (Optional)

These cookies enhance your experience and can be disabled:

Cookie NamePurposeDurationLegal Basis
user-preferencesRemember dashboard settings and theme1 yearLegitimate interest (user experience)
notion-connection-statusRemember your Notion workspace connection7 daysContract performance
form-list-viewRemember your preferred form list layout6 monthsLegitimate interest (user experience)

3.3 Security Cookies (Required)

These cookies protect your account and our service:

Cookie NamePurposeDurationLegal Basis
rate-limitPrevent API abuse and brute force attacks1 hourLegitimate interest (security)
login-attemptsTrack failed login attempts for security24 hoursLegitimate interest (security)

4. Third-Party Service Cookies

4.1 Stripe Payment Processing

When you subscribe to a paid plan, Stripe may set cookies for payment processing:

  • Purpose: Secure payment processing and fraud prevention
  • Duration: Varies (typically 1-2 years)
  • Control: Managed by Stripe's privacy policy
  • Legal Basis: Contract performance (payment processing)

4.2 Notion OAuth Integration

During Notion workspace connection, Notion may set temporary cookies:

  • Purpose: OAuth authentication flow
  • Duration: Session only
  • Control: Managed by Notion's privacy policy
  • Legal Basis: Contract performance (service integration)

5. What We Don't Use

NotionSync does not use:

  • Advertising cookies - We don't show ads or track for advertising
  • Marketing cookies - We don't track users across websites
  • Analytics cookies - We don't use Google Analytics or similar tracking
  • Social media cookies - We don't embed social media trackers
  • Cross-site tracking - We don't share data with advertising networks
  • Behavioral profiling - We don't build user behavior profiles

6.1 Browser Settings

You can control cookies through your browser settings:

Chrome: Settings → Privacy and Security → Cookies and other site data
Firefox: Settings → Privacy & Security → Cookies and Site Data
Safari: Preferences → Privacy → Cookies and website data
Edge: Settings → Cookies and site permissions → Cookies and site data

6.2 Essential vs Optional Cookies

  • Essential cookies: Cannot be disabled as they're required for basic functionality
  • Functional cookies: Can be disabled, but may affect your user experience
  • Third-party cookies: Controlled by respective service providers

When you first visit NotionSync:

  • Essential and security cookies are automatically enabled (necessary for service function)
  • Functional cookies require your consent
  • You can change your preferences anytime in your account settings

7.1 Automatic Deletion

  • Session cookies are deleted when you close your browser
  • Persistent cookies expire according to their set duration
  • We automatically clean up expired cookies from our systems

7.2 Manual Deletion

You can delete cookies at any time by:

  • Clearing your browser cookies
  • Logging out of NotionSync (removes session cookies)
  • Deleting your account (removes all associated cookies)

8.1 Policy Changes

If we change our cookie usage:

  • We'll update this policy with the new effective date
  • Material changes will be announced via email or platform notification
  • Continued use after changes constitutes acceptance

If we introduce new types of cookies (which we have no current plans to do):

  • We'll obtain your consent for non-essential cookies
  • Essential cookies for security/functionality may be added without consent
  • You'll be notified of any significant changes

9. Technical Details

All NotionSync cookies are:

  • Secure: Only transmitted over HTTPS connections
  • HttpOnly: Inaccessible to JavaScript to prevent XSS attacks
  • SameSite: Protected against cross-site request forgery
  • Encrypted: Sensitive data is encrypted before storage

9.2 Local Storage

In addition to cookies, we may use browser local storage for:

  • Form builder draft saving (cleared when you publish or delete forms)
  • Temporary OAuth state (cleared after authentication)
  • User interface preferences (persists until manually cleared)

10. GDPR and Privacy Rights

  • Essential cookies: Necessary for contract performance
  • Functional cookies: Legitimate interest (user experience)
  • Security cookies: Legitimate interest (security and fraud prevention)

10.2 Your Rights

Under GDPR, you have the right to:

  • Know what cookies we use and why
  • Withdraw consent for optional cookies
  • Request deletion of cookie data
  • Object to cookie processing based on legitimate interest

11. Contact and Support

For questions about our cookie usage:

Email: noreply@sales.notionsync.co
Subject: "Cookie Policy Question"

11.2 Technical Issues

If you experience issues with cookies:

  • Check your browser's cookie settings
  • Ensure JavaScript is enabled
  • Try clearing your browser cache
  • Contact our support team for assistance

12. Compliance and Monitoring

12.1 Regular Reviews

We regularly review our cookie usage to ensure:

  • Minimal data collection
  • Compliance with privacy laws
  • Alignment with our privacy-first principles

12.2 Audit Trail

We maintain records of:

  • Cookie consent preferences
  • Cookie policy updates
  • User requests regarding cookies

This cookie policy reflects our commitment to privacy and transparency. We only use cookies necessary for providing our form building service.