Legal
Cookies.
Updated 2026-05-22. We keep cookies minimal — auth, your preferences, opt-in analytics.
Strictly necessary
These are required for the site to work. They store your sign-in session, CSRF tokens, and our cookie-consent decision. You can’t disable them from us; you can block them in your browser, but you won’t be able to sign in or stay signed in.
sb-*— Supabase auth session (httpOnly, SameSite=Lax).vl_2fa— two-factor verification stamp (httpOnly, Strict, 8h).pk_auth_challenge— short-lived (5m) WebAuthn challenge.cookie_consent— your choice on this banner.
Analytics — opt-in
If you accept the analytics cookie, we use PostHog to record page views + feature usage. We use this to find bugs and decide what to build next. We don’t sell this data and don’t share it with ad networks.
ph_*— PostHog identification + session id (1 year).
Decline these and we don’t set them. You can change your mind any time by clearing site data in your browser and visiting Orvica again.
What we don't use
No third-party ad cookies. No cross-site retargeting pixels. No Facebook/Meta pixel. No Google Ads. No Twitter pixel. No LinkedIn Insight tag. No A/B testing cookies that sell behavioral data.
Browser controls
You can block or delete cookies from any browser’s settings. Chrome / Edge / Firefox / Safari all expose per-site cookie controls. Blocking strictly-necessary cookies will sign you out and prevent sign-in.
Contact
Questions about our cookie use → privacy@orvica.co.