Cookie Policy
- Last updated
- Effective
What www.senitix.com and the Senitix application store in your browser, why, for how long, and how to control it. Our website loads Google Analytics only after you consent.
1. About this policy
This Cookie Policy explains how Senitix Teknoloji LTD. ŞTİ. (“Senitix,” “we,” “us” or “our”) uses cookies and similar technologies, and the choices you have about them. Senitix is a limited company organized under the laws of the Republic of Türkiye, with its registered office at Cevizli Mah. Zuhal Cad. A Blok No:46 İç Kapı No:50, Maltepe, İstanbul, Türkiye.
This policy covers:
- Our website at www.senitix.com, including senitix.com.
- The Senitix application: your Senitix account at app.senitix.com, Senitix CRM at crm.senitix.com, and the services those pages connect to, such as api.senitix.com.
- Our status page at status.senitix.com, which sets no cookies of its own, may receive the same Cloudflare security cookies described in section 4.2, and uses the error monitoring described in section 5.3.
As of the effective date below, senitix.com redirects to www.senitix.com, our canonical address. If you reach a page before that redirect takes effect, you may be looking at an earlier version of our site that used different technology; that earlier site’s own notice, not this one, describes what it used.
It supplements our Privacy Policy, which explains how we collect, use and disclose personal information and the rights you may have under U.S. state privacy laws. If your organization uses Senitix, our Terms of Service and Data Processing Addendum also apply. This policy does not cover other companies’ websites that we link to, or websites that our customers run themselves.
2. The short version
- We ask before we use analytics. The first time you visit, a banner lets you choose “Accept all,” “Reject all” or open “Cookie settings.” Until you accept, we load no analytics script and set no analytics cookie.
- If you accept, we use Google Analytics to understand site usage. It measures things like the pages people view and the events section 4.5 describes; it does not use the data for advertising, and Google Signals and ads personalization are off.
- Our security provider may set a security cookie. Cloudflare may set a strictly necessary cookie that helps block automated attacks.
- Videos load only when you press play. At that point, the video provider (YouTube or Vimeo) may set its own cookies.
- The application uses only what it needs. Its cookies and browser storage keep you signed in, protect your account, keep the service working and remember your language, settings and unsaved work.
- You are in control. Change your choice any time from “Cookie settings” in the footer of every page, or in your browser; we honor the Global Privacy Control signal as a request to keep analytics off. We do not sell or share personal information, and we do not use it for targeted advertising.
3. Cookies and similar technologies
A cookie is a small text file that a website stores in your browser so it can recognize that browser on later requests. A first-party cookie is set for the domain you are visiting; a third-party cookie is set for a different domain, such as the domain of a video player embedded in the page. A session cookie is deleted when you close your browser; a persistent cookie remains until it expires or you delete it.
Similar technologies work in comparable ways. Local storage keeps small pieces of information in your browser until they are removed, and session storage keeps them only until you close the browser tab. A pixel (also called a web beacon) is a tiny image that reports when a page or an email is opened.
We call a cookie or similar technology strictly necessary when the website or the application cannot provide what you asked for without it: for example, keeping you signed in, protecting you from forged requests, blocking automated attacks or remembering the cookie choice you made. We call one analytics when it only helps us understand, in aggregate, how visitors use our website. Analytics is not strictly necessary, so our website loads it only after you accept it, as sections 4.1 and 4.5 describe. On our website and in the application, we do not use cookies or similar technologies for advertising, social media or tracking you across other websites.
4. Our website
4.1 What loads before you choose, and what needs your consent
When you first visit www.senitix.com, before you make a cookie choice in the banner described in section 7, the website sets no analytics, advertising, social media or chat cookie and writes nothing else to your browser’s local or session storage. It loads no tag manager, advertising or retargeting pixel, social media plug-in, live chat, or heat-mapping or session-recording tool, whether or not you consent. Fonts, images and scripts are served from our own infrastructure, and the website’s security settings allow a script to run in the page only from a source we have listed, which, once you accept analytics, includes Google Analytics (section 4.5). As a result, loading a page sends information about your visit to the providers that host and protect the website for us and, only if you have accepted analytics, to Google as well.
Forms on the website, such as the contact form, send us the information you type when you submit them. They set no cookie of their own. If you have accepted analytics, submitting the contact or sales form, or clicking to start a free trial or sign up on app.senitix.com, is also recorded as an analytics event, as section 4.5 describes. Our Privacy Policy explains how we use what you send.
4.2 Security cookies from Cloudflare
We use Cloudflare, Inc. to protect our domains against attacks and automated abuse. Where Cloudflare’s protection is active, it may set a strictly necessary cookie that helps it tell people apart from bots and, if your browser is asked to complete a security check, a second cookie that records that you passed it. We use these cookies only for security. Cloudflare describes them in its cookie documentation.
4.3 Embedded videos
Some pages may include a video. The video player is not loaded with the page: you see a play button, and nothing is requested from the video provider until you press it. When you press play, your browser loads the player from YouTube’s privacy-enhanced domain (youtube-nocookie.com), operated by Google, or from Vimeo, depending on where the video is hosted.
From that moment, the provider receives the information your browser sends with any request, such as your IP address, information about your browser and the site you are viewing, and it may set its own cookies or use similar technologies. The provider controls those technologies under its own privacy policy; see Google’s Privacy Policy and Vimeo’s privacy information. Closing the video removes the player from the page, but cookies the provider has already set remain until they expire or you delete them.
4.4 Cookies for website editors
People who sign in to edit the website for Senitix receive the standard cookies of WordPress, the software the website runs on. These cookies are set only when an editor signs in. Visitors cannot create an account on the website and never receive them.
4.5 Google Analytics, only with your consent
If you accept analytics (by choosing “Accept all” in the cookie banner, or turning on the “Analytics” category in “Cookie settings”), we load Google Analytics 4 (measurement ID G-JQ32B8VWLV), provided by Google, to understand how visitors use our website. Until you accept, no Google Analytics script runs and no Google Analytics cookie is set. You can withdraw your consent at any time in “Cookie settings”; doing so stops Google Analytics from running on your next page view and deletes the _ga cookies listed in section 4.6.
We use Google Consent Mode v2. Every signal defaults to denied. If you accept analytics, only the analytics_storage signal changes to granted; the signals used for advertising (ad_storage, ad_user_data and ad_personalization) stay denied whatever you choose, because we do not use Google Analytics, or any other tool, for advertising. Google Signals and ads personalization are turned off in our Google Analytics property.
If your browser sends a Global Privacy Control (GPC) signal, we treat it the same as choosing “Reject all”: analytics stays off unless you later turn it on yourself in “Cookie settings.”
With your consent, Google Analytics measures the pages you view, the site or search engine you arrived from, your device, browser and language, and your approximate location at the city level, which Google derives from your IP address; Google Analytics does not log or store the IP address itself. It also records two events: submitting our contact or sales form (“generate_lead”), and clicking to start a free trial or sign up on app.senitix.com. We keep this analytics data in Google Analytics for 14 months.
Google Analytics is provided by Google Ireland Limited for visitors in the EEA, the UK and Türkiye, and by Google LLC, based in the United States, for other visitors. Google processes this data as our service provider (in EU and UK terms, our processor), under Google’s own data processing terms, and does not use it for Google’s own purposes. Where Google transfers this data to the United States, it relies on the standard contractual clauses in those terms and, for Google LLC, its certification under the EU-U.S. Data Privacy Framework; section 9 says more about where this information is processed. Using Google Analytics with your consent is not a sale or sharing of personal information: Senitix does not sell or share personal information, and does not use it for cross-context behavioral advertising.
Your choice itself is recorded in a strictly necessary first-party cookie, sx_consent, listed in section 4.6, so that we do not ask you again and so that analytics loads only when you have agreed to it.
The home page and your country. When you open the home page, www.senitix.com, from Türkiye, it sends you to our Turkish site, www.senitix.com/tr/. This uses only the country our content delivery network derives from your connection for that one request; nothing is stored and no cookie is set. Every other page opens as the address you asked for. If you choose a language from the language menu, the sx_lang cookie listed in section 4.6 remembers it, and the home page stops redirecting you.
4.6 Website cookie list
| Cookie | Set by | Purpose | Duration | Category |
|---|---|---|---|---|
__cf_bm | Cloudflare, for Senitix (first party) | May be set on any visit to help tell people apart from automated bots, so abusive traffic can be blocked. | 30 minutes | Strictly necessary |
cf_clearance | Cloudflare, for Senitix (first party) | Set only if your browser is asked to complete a security check; records that you passed it so you are not asked again. | 30 minutes by default | Strictly necessary |
sx_consent | Senitix (first party) | Records the cookie choice you made (accept, reject, or which categories), so we do not ask again and so analytics loads only if you agreed. Holds no personal data. | 180 days | Strictly necessary |
sx_lang | Senitix (first party) | Set only when you choose a language in the site’s language menu; remembers that choice so the home page opens in the language you picked rather than the one suggested by your location. Holds no personal data. | 1 year | Strictly necessary |
| Named by the provider | Google (YouTube) or Vimeo (third party) | Set only after you press play on a video; used by the provider to play the video and for the purposes described in its own privacy policy. | Set by the provider | Loads only at your request |
_ga | Google Analytics, for Senitix (first party) | Set only if you accept analytics; distinguishes one visitor’s browser from another. | 2 years | Analytics, only with consent |
_ga_JQ32B8VWLV | Google Analytics, for Senitix (first party) | Set only if you accept analytics; stores session state for Google Analytics. | 2 years | Analytics, only with consent |
wordpress_logged_in_*, wordpress_sec_* | Senitix (first party) | Keep a website editor signed in. Editors only. | Until the browser closes, or 14 days if the editor chooses “Remember me” | Strictly necessary |
wordpress_test_cookie | Senitix (first party) | Checks that an editor’s browser accepts cookies on the sign-in page. Editors only. | Until the browser closes | Strictly necessary |
wp-settings-*, wp-settings-time-* | Senitix (first party) | Remember an editor’s screen settings in the editing tools. Editors only. | 1 year | Preference |
5. The Senitix application
The application uses a small number of cookies and browser storage entries to work. Senitix sets them on senitix.com domains, except the Cloudflare and Amazon Web Services cookies noted below, which those providers set for us on our domains. None of them is used for advertising or to track you on other websites.
5.1 Cookies
Some of these cookies are set for senitix.com and all of its subdomains, so that signing in to your account also signs you in to Senitix CRM. Your browser may therefore send them when you visit our website as well; the website does not read or use them. Cookies that carry sign-in secrets are marked HttpOnly, so scripts on the page cannot read them, and Secure, so they are sent only over encrypted connections.
| Cookie | Set by | Purpose | Duration | Category |
|---|---|---|---|---|
crm_session, app_session | Senitix (first party) | Keeps you signed in while you use Senitix CRM and, where enabled, your account, by linking your browser to a secure session held on our servers. | Until you close your browser; the session behind it ends after 2 hours without activity and after 24 hours at most | Strictly necessary |
refresh_token | Senitix (first party) | Signs you back in when your short-lived access expires, so you do not have to re-enter your password each time. Deleted when you sign out. | 7 days | Strictly necessary |
senitix_launch_verifier | Senitix (first party) | A one-time security value used when you open Senitix CRM from your account, so the hand-off between the two cannot be intercepted. | 10 minutes | Strictly necessary |
XSRF-TOKEN | Senitix (first party) | Helps protect you against cross-site request forgery, in which another website tries to send requests to Senitix in your name. | Up to 2 hours | Strictly necessary |
senitix-language | Senitix (first party) | Remembers the language you chose in your account. | Until you close your browser | Preference |
AWSALB, AWSALBCORS | Amazon Web Services, for Senitix (first party) | May be set when the application opens its real-time connection, to keep that connection on the same server so live updates and notifications keep arriving. | 1 day | Strictly necessary |
__cf_bm, cf_clearance | Cloudflare, for Senitix (first party) | May be set for security, as described in section 4.2. | 30 minutes | Strictly necessary |
5.2 Browser storage
The application also keeps some information in your browser’s local storage and session storage. This information stays on your device and, unlike a cookie, is not sent to our servers automatically with every request.
| Purpose | Examples | Storage | How long |
|---|---|---|---|
| Sign-in state | senitix-auth, which records only whether you are signed in, not your name or email address; senitix-current-tenant, the workspace you are using | Local storage | Until the application removes it or you clear your browser’s site data |
| Returning you to the right page after you sign in | sso_auth, senitix-bff-redirect | Session storage | Until you close the tab |
| Language | senitix-language, senitix-locale | Local storage | Until you change the language or clear your browser’s site data |
| Interface settings | senitix-ui, tcl-right-open, senitix-setup-checklist, senitix-email-account (the connected email account you selected), and column and panel layouts | Local storage | Until you change the setting or clear your browser’s site data; some are removed when you sign out |
| Unsaved drafts | form-draft:* in Senitix CRM; senitix:draft:* in your account | Session storage in Senitix CRM; local storage in your account | In Senitix CRM, until you save the form, close the tab or sign out; in your account, until you submit the form or clear your browser’s site data |
| Recently viewed records and your first setup conversation | senitix-recently-viewed, senitix-onboarding-chat | Session storage | Until you close the tab; recently viewed records are also removed when you sign out |
| Error monitoring | sentryReplaySession | Session storage | Until you close the tab (see section 5.3) |
A draft can include personal information you typed into a form, such as a contact’s name or email address. It stays in your browser and is not sent to us until you save the form. If you use a shared computer, sign out and close the browser when you finish.
5.3 Error and performance monitoring
To find and fix problems, the application and our status page use Sentry, an error-monitoring service provided by Functional Software, Inc. Sentry sets no cookies. When an error occurs, it records technical details about the error and may record a short replay of the screen leading up to it, with all text masked and images and media blocked. Replays are turned off on payment screens. While a replay is being recorded, Sentry keeps an identifier in your browser’s session storage, which is deleted when you close the tab. Sentry also measures page-load performance for a sample of visits. We use this information only to operate, secure and improve the service; see section 9 for where Sentry processes it.
5.4 Connected accounts and single sign-on
When you sign in with a Google, Microsoft or GitHub account, connect a Google or Microsoft account to Senitix CRM, or sign in through your organization’s single sign-on provider, you are taken to that provider’s own pages to approve the connection or sign in. The provider sets and controls its own cookies there, under its own policies. We do not receive or control those cookies.
6. Emails
Emails from Senitix. We send account, security and billing emails through Twilio SendGrid. To confirm that important notices arrive, SendGrid records whether each email was delivered and, where tracking is enabled, when it was opened or a link in it was clicked, using a pixel and links that pass through SendGrid. This tracking does not rely on cookies.
Emails our customers send with Senitix CRM. Senitix CRM can tell a customer whether an email it sent to one of its own contacts was opened and whether a link in it was clicked. When that tracking is on, the email contains a pixel and links that pass through our servers, and by default a short line in the email says that opens and clicks may be tracked. This tracking does not rely on cookies. The customer decides whether to use tracking and is responsible for it; we process the resulting information on the customer’s behalf under our Data Processing Addendum. If you received such an email and have questions, please contact the company that sent it.
7. How to control cookies and browser storage
The cookie banner. The first time you visit www.senitix.com, a banner offers “Accept all” and “Reject all,” shown with equal prominence, and “Cookie settings,” which opens a panel with two categories: Strictly necessary, which is always on because the website cannot work as intended without it, and Analytics, which is off unless you turn it on. Your choice is saved in the sx_consent cookie described in section 4.6, so we do not ask again on your next visit in the same browser.
Changing your choice. A “Cookie settings” link in the footer of every page reopens the panel at any time, so you can turn analytics on or off. Withdrawing your consent to analytics stops Google Analytics from running on your next page view and deletes the _ga cookies described in section 4.6. We also honor the Global Privacy Control (GPC) browser signal, described in section 8, as a request to keep analytics off.
Browser settings. Every major browser, including Chrome, Safari, Firefox and Edge, lets you see, block and delete cookies and clear the information a site keeps in local and session storage, usually in its privacy or site data settings. A private or incognito window discards cookies and storage when you close it. Blocking cookies on our website mainly means the choice you make in the cookie banner is not remembered between visits, so the banner reappears; the site otherwise keeps working. The application cannot keep you signed in without its cookies, so blocking them will prevent you from using it, and clearing its site data will sign you out and delete any unsaved drafts.
Signing out. Signing out ends your session, removes your sign-in cookies, and clears the drafts and recently viewed records that Senitix CRM keeps in your browser.
Videos. If you do not want a video provider to receive information about you, do not press play. You can delete a provider’s cookies at any time in your browser and manage your settings with the provider directly.
Your privacy rights. To learn about your rights to know about, delete or correct your personal information, and how to exercise them, see our Privacy Policy.
8. Do Not Track and Global Privacy Control
Do Not Track. Some browsers can send a “Do Not Track” (DNT) signal. There is no common industry standard for how a website should respond to it. Our website does not change its behavior when it receives a DNT signal; whether analytics runs for your browser is controlled by the cookie consent choice described in section 7, not by DNT.
Tracking by third parties. We do not allow third parties to collect personal information about your online activities over time and across different websites when you use our website or the application. Google, our analytics provider, is one exception under your control: if you accept analytics, Google processes your visit as our service provider to measure how the website is used, as section 4.5 describes, and because Google Signals and ads personalization are off, it does not use that data to build cross-site advertising profiles. The other exception is a video: if you press play on an embedded video, the video provider receives information from your browser and may use cookies under its own policy, as described in section 4.3. Cloudflare, Amazon Web Services, Google, Sentry and our other service providers process information about your visit on our behalf, to provide their services to us.
Global Privacy Control. Global Privacy Control (GPC) is a browser setting that tells websites you want to opt out of the sale or sharing of your personal information and of targeted advertising. We do not sell or share personal information and do not use it for targeted advertising, as those terms are defined in the California Consumer Privacy Act and other U.S. state privacy laws, so a GPC signal has nothing to switch off on that score. It does control one thing: we treat a GPC signal from your browser as a request to keep the Analytics category off, the same as choosing “Reject all” in the cookie banner (section 7), unless you later turn analytics on yourself in “Cookie settings.” You can learn more at globalprivacycontrol.org.
9. Where this information is processed
Senitix is based in Türkiye. Our website and the application are hosted by Amazon Web Services in the European Union, in Frankfurt, Germany, with disaster recovery in Ireland. Cloudflare operates a global network, so your requests may be handled at a location near you. If you accept analytics, Google Analytics is provided by Google Ireland Limited for visitors in the EEA, the UK and Türkiye, and by Google LLC in the United States for other visitors, and processes information there and, for transfers to the United States, under the safeguards section 4.5 describes. Email delivery information is processed by Twilio SendGrid in the United States, and our error-monitoring provider, Sentry, may process information in the United States or the European Union. Video providers process information under their own policies and may do so in the United States and other countries. Our Privacy Policy explains how we protect personal information that is transferred between countries.
10. Changes to this policy
This policy is effective as of September 12, 2026. We will update it when the technologies we use change, and always before we add any further optional technology. The date at the top of this page shows when the policy was last updated. If we make a material change, we will post a notice on our website and, for customers, notify account administrators by email or in the application before the change takes effect.
11. Contact us
If you have questions about this policy or our use of cookies and similar technologies, email privacy@senitix.com or write to us at Senitix Teknoloji LTD. ŞTİ., Cevizli Mah. Zuhal Cad. A Blok No:46 İç Kapı No:50, Maltepe, İstanbul, Türkiye. For anything else, use our contact page.
