[ LEAVEPILOT · LEGAL ]
Courtesy translation
This translation is provided to make the document easier to read. The text that binds the parties is the Italian one: in the event of any discrepancy the original prevails, and it is its fingerprint that is recorded when the agreement is accepted.
- Version
- cookies-2026-08-21-v2
- In force since
- 21 August 2026
- SHA-256 fingerprint of the text
- e761b4e20c0413c2d540bc5543abe8cb26332fefc7d6dcc8341e9cb67227ff1a
- Verifiable against a copy of the text with shasum -a 256 content/legal/cookies-2026-08-21-v2.en.md. If the fingerprint matches, the text has not been altered since publication.
Cookie Policy
Service: LeavePilot Data controller: MAXYMIZE BUSINESS DI GIURASTANTE ROMANO MAXIMILIAN, Via Delle Valli 57, 66010 Canosa Sannita (CH), Italy, tax code and VAT number IT02747200695, REA no. CH-420087 Contact: support@leavepilot.app Certified email (PEC): maximilian.giurastante@legalmail.it
This policy explains the use of cookies and similar technologies on leavepilot.app and within the platform, under Regulation (EU) 2016/679 and the guidelines of the Italian Data Protection Authority.
Here, "cookie" also refers to localStorage, sessionStorage, pixels and similar technologies that read or write data on your device.
The Italian version prevails / La versione italiana fa fede.
1. Controller
Data controller: MAXYMIZE BUSINESS DI GIURASTANTE ROMANO MAXIMILIAN, a sole proprietorship based at Via Delle Valli 57, 66010 Canosa Sannita (CH), Italy, tax code and VAT number IT02747200695, registered with the Chamber of Commerce under REA no. CH-420087.
Contact: support@leavepilot.app. For formal communications: maximilian.giurastante@legalmail.it.
2. Technical technologies
The technologies in this section serve the operation of the platform or of the banner itself, are first party, and require no consent under article 122 of the Italian Privacy Code.
2.1 Platform cookies and storage
The platform, that is the area you reach with a username and password, does not display the cookie banner: it uses only the technologies listed here, which are necessary to sign in and use the service.
| Name | Type | Purpose | Duration | Origin |
|---|---|---|---|---|
auth-token | HttpOnly cookie | Authentication session | 1 hour | First party |
refresh-token | HttpOnly cookie | Session renewal | 7 days | First party |
session-language, language-override | Cookie | Language manually chosen for the session, when it overrides the profile language | 30 days | First party |
session-language, language-override | sessionStorage | Same function, read and written client-side | Until the tab is closed | First party |
lp-theme | localStorage | Light, dark or system theme preference | Permanent | First party |
accessToken | localStorage | Copy of the access token for authenticated calls made from the browser | Until logout or a new sign-in | First party |
userData | localStorage | Minimal user data for the interface, with no sensitive information | Until logout | First party |
onboardingData | localStorage | Progress through the account activation flow | Until completion | First party |
admin-active-tab | sessionStorage | Active tab in the admin panel, to restore it after a page refresh | Until the tab is closed | First party |
dismissed-notifications | localStorage | Administrative notifications already seen | Permanent | First party |
pwa-install-dismissed | localStorage | Dismissal of the app installation prompt | Permanent | First party |
notifications_last_read | localStorage | Date and time of the last notification read | Permanent, updated at every read | First party |
timezone-setting, timezone-show-full, timezone-show-indicator | localStorage | Time zone display preferences | Permanent | First party |
lp_tenant_public_config_v2 | localStorage | Local copy of the organization's public configuration, e.g. name and logo | 24 hours | First party |
sw_cleanup_v2 | localStorage | Technical flag that removes outdated components after a service update | Permanent | First party |
chunk-error-reload | sessionStorage | Prevents repeated reloads when a page fails to load | Until the tab is closed | First party |
admin_employees, admin_departments, admin_holiday_requests, admin_system_settings, admin_stats | sessionStorage | Temporary copy of administrative data, to reduce requests to the server | 5 minutes, and in any case until the tab is closed | First party |
2.2 Consent management system
On the public website, where the banner described in section 3 is shown, the library that manages it records the choice made.
| Name | Type | Purpose | Duration | Origin |
|---|---|---|---|---|
c15t | Cookie and localStorage | Records the categories accepted or declined in the banner; it is the basis of the proof of consent | 365 days for the cookie; the localStorage entry has no expiry of its own | First party, dedicated database hosted by Neon in the European Union |
c15t-pending-consent-submissions, c15t-pending-identify-submissions, c15t:pending-consent-sync | localStorage | Queues the submission of your choice to the server when the connection is unavailable at the moment you choose | Until successfully submitted | First party |
3. Measurement and marketing
A consent management banner is active on the public website, with three categories: Necessary, always active because they are essential to the banner itself and described in section 2.2; Measurement; Marketing. The last two are switched off by default and are enabled only after explicit consent, which can be withdrawn at any time.
Measurement
| Name | Type | Purpose | Duration | Origin |
|---|---|---|---|---|
ph_<project key>_posthog | Cookie and localStorage | Aggregate statistics on the use of the public website: pages visited, events, response times | 365 days for the cookie; the localStorage entry has no expiry of its own | Provider: PostHog Inc., EU instance |
Google Analytics 4 is a category provided for in this banner but not installed: as of this version, no script is present and no data is collected through this tool.
Marketing
Meta Pixel is a category provided for in this banner but not installed: as of this version, no script is present and no data is collected through this tool.
The measurement tool listed above follows two distinct regimes, depending on the page you are using, not on who you are.
On the informational pages of the public site, those reachable without an account, where this banner is shown, such as the home page, the legal pages, the security and trust page, and the pages through which a new organization signs up for the service, the tool writes the cookie and storage entries listed above: for this reason it starts only after consent to the "Measurement" category. Without consent it does not start at all, and if you withdraw consent, collection stops and whatever had already been written, cookie and storage entries included, is removed.
On every other page, collection works without writing anything to your device: it leaves no cookie and no storage entry, and its memory ends with the browser session. This includes the entire authenticated area, but also the public pages for signing in, for a single user's registration, for password recovery and reset, for email verification, and for accessing your workspace. On these pages consent is not required, because there is nothing, on your device, to write or to withdraw; the purposes and legal basis of this collection are described in the privacy notice, section 5.
The choices made in the banner are recorded as proof of consent under article 7 of the Regulation, in the manner described in section 2.2.
4. Managing your preferences
You can change or withdraw your choices at any time through the "Cookie preferences" link in the website footer, and you can also manage or delete cookies from your browser settings. Disabling technical cookies may prevent the service from working properly, for example by blocking access to your account area.
Instructions for managing and deleting cookies in the main browsers:
- Google Chrome: https://support.google.com/chrome/answer/95647?hl=en
- Mozilla Firefox: https://support.mozilla.org/en-US/kb/clear-cookies-and-site-data-firefox
- Apple Safari: https://support.apple.com/guide/safari/manage-cookies-sfri11471/mac
- Microsoft Edge: https://support.microsoft.com/en-us/microsoft-edge/delete-cookies-in-microsoft-edge-63947406-40ac-c3b8-57b9-2a946a29ae09
For any question about cookies, write to support@leavepilot.app.
All published versions
Every version stays at its own address, with its own text and its own fingerprint, even once superseded. It is there for whoever is bound by an earlier version and needs to read back exactly that one.
- cookies-2026-08-21-v221 August 2026in force
- cookies-2026-08-12-v112 August 2026