Cookies Policy
Last Updated: 03 August 2026
This Cookie Policy governs your ("you" or "your") access to and use of the Greenda® platform, including the website greenda.ai, the Greenda® web application at app.greenda.ai, and the Greenda® mobile application (available on iOS and Android), operated by GreendaAI GmbH ("we", "our" or "us"). It explains what cookies are, which cookies and tracking technologies we use, why we use them, and how you can manage your preferences. It should be read alongside our Privacy Policy (greenda.ai/privacy-policy).
The mobile application is used both by individual users (independent farmers and independent experts) and by farmers onboarded through a cooperative. The device identifiers and SDKs described in Section 3.3 apply to all mobile-app users.
1. What Are Cookies?
Cookies are small text files placed on your browser or device when you visit a website. They allow the website to recognise your device and remember information about your visit. Cookies may be:
- Session cookies: temporary cookies deleted automatically when you close your browser.
- Persistent cookies: stored on your device for a defined period or until you delete them.
In addition to cookies, we use similar tracking technologies such as pixel tags, tag-management containers, software development kits (SDKs), and device identifiers (e.g. in our mobile application).
2. Your Consent and Legal Basis
Under the GDPR and the German Telecommunications Digital Services Data Protection Act (TDDDG, formerly TTDSG), we are required to obtain your prior consent before placing non-essential cookies or similar technologies on your device. The legal bases we rely on are:
- Strictly necessary cookies and technologies: no consent required. These are placed on the basis of our legitimate interest in operating a secure and functional service (Art. 6(1)(f) GDPR) and are exempt from consent requirements under Art. 5(3) ePrivacy Directive.
- All other cookies and technologies (functionality, analytics, attribution, tracking, advertising): placed only with your explicit consent (Art. 6(1)(a) GDPR). You may withdraw consent at any time without affecting the lawfulness of prior processing.
You can manage or withdraw your consent at any time via our cookie preference centre at greenda.ai/updatecookies, through your browser settings, or (for the mobile application) through your device settings (see Section 4).
3. Cookies and Tracking Technologies We Use
The tables and lists below set out the cookies and tracking technologies currently active on the platform, grouped by surface and category.
Tags on greenda.ai are deployed through Google Tag Manager (container GTM-NJ5333R4, provided by Google). Google Tag Manager itself does not store cookies, but it manages the consent-gated loading of the analytics and advertising tags listed below, so that non-essential tags fire only after you have given consent. The tags currently deployed through this container include Google Analytics (GA4 properties G-0KL2FVRWMK and G-N63HPE9DNN) together with an associated Google tag (GT-K55FBB98), Google Ads conversion tracking (AW-17360009107), the LinkedIn Insight Tag, the Meta pixel, HubSpot tracking and chat, and the AppsFlyer Web SDK smart banner.
3.1 Website Cookies, greenda.ai
| Cookie Name | Category | Provider | Purpose | Legal Basis | Expiry |
|---|---|---|---|---|---|
| __cf_bm | Strictly Necessary | Cloudflare (via HubSpot CDN) | Bot protection and abuse prevention | Strictly necessary, no consent required | 30 minutes |
| __cfruid | Strictly Necessary | Cloudflare (via HubSpot CDN) | Detects malicious actors on the CDN layer | Strictly necessary, no consent required | Session |
| __cfuvid | Strictly Necessary | Cloudflare (via HubSpot CDN) | Rate limiting and abuse detection on the CDN layer | Strictly necessary, no consent required | Session |
| __hs_opt_out | Functionality | HubSpot | Remembers that the visitor has already been asked to accept cookies | Consent (Art. 6(1)(a) GDPR) | 6 months |
| __hs_do_not_track | Functionality | HubSpot | Prevents tracking code from sending information to HubSpot when visitor opts out | Consent (Art. 6(1)(a) GDPR) | 6 months |
| __hs_initial_opt_in | Functionality | HubSpot | Prevents the cookie banner from displaying repeatedly to visitors in strict mode | Consent (Art. 6(1)(a) GDPR) | 7 days |
| __hs_cookie_cat_pref | Functionality | HubSpot | Records the cookie categories the visitor consented to | Consent (Art. 6(1)(a) GDPR) | 6 months |
| __hs_gpc_banner_dismiss | Functionality | HubSpot | Records dismissal of the Global Privacy Control banner | Consent (Art. 6(1)(a) GDPR) | 180 days |
| __hs_notify_banner_dismiss | Functionality | HubSpot | Records dismissal of the HubSpot notify consent banner | Consent (Art. 6(1)(a) GDPR) | 180 days |
| __hssrc | Functionality | HubSpot | Determines if the visitor has restarted their browser session | Consent (Art. 6(1)(a) GDPR) | Session |
| _ga | Analytics | Google (GA4) | Distinguishes unique website users by assigning a randomly generated client ID | Consent (Art. 6(1)(a) GDPR) | 2 years |
| _ga_0KL2FVRWMK | Analytics | Google (GA4) | Tracks session state and page interactions for the first GA4 property | Consent (Art. 6(1)(a) GDPR) | 2 years |
| _ga_N63HPE9DNN | Analytics | Google (GA4) | Tracks session state and page interactions for the second GA4 property | Consent (Art. 6(1)(a) GDPR) | 2 years |
| __hstc | Tracking | HubSpot | Primary tracking cookie for visitor identification across sessions | Consent (Art. 6(1)(a) GDPR) | 6 months |
| hubspotutk | Tracking | HubSpot | Tracks visitor identity and is passed to HubSpot on form submission to prevent duplicate contacts | Consent (Art. 6(1)(a) GDPR) | 6 months |
| __hssc | Tracking | HubSpot | Tracks session activity to determine whether to increment the session number in __hstc | Consent (Art. 6(1)(a) GDPR) | 30 minutes |
| messagesUtk | Tracking | HubSpot | Identifies visitors who interact with the HubSpot chat widget so conversations can be linked across sessions | Consent (Art. 6(1)(a) GDPR) | 6 months |
| _fbp | Advertising | Meta (Facebook) | Identifies browser and device to deliver, measure, and improve the relevance of Meta ads | Consent (Art. 6(1)(a) GDPR) | 3 months |
| _fbc | Advertising | Meta (Facebook) | Captures the ad click referral code from Facebook/Instagram ad campaigns | Consent (Art. 6(1)(a) GDPR) | 3 months |
| _gcl_au | Advertising | Google (Google Ads / Conversion Linker) | Stores click information for Google Ads conversion linking and attribution | Consent (Art. 6(1)(a) GDPR) | 90 days |
| _gcl_aw | Advertising | Google (Google Ads) | Stores the Google Ads click identifier (GCLID) to attribute conversions to ad campaigns | Consent (Art. 6(1)(a) GDPR) | 90 days |
| li_fat_id | Advertising | LinkedIn (Microsoft Ireland) | Enables conversion tracking, retargeting and analytics via the LinkedIn Insight Tag | Consent (Art. 6(1)(a) GDPR) | 30 days |
| ln_or | Advertising | LinkedIn (Microsoft Ireland) | Determines whether LinkedIn analytics can be carried out for the visit | Consent (Art. 6(1)(a) GDPR) | Session |
In addition to the cookies listed above, the LinkedIn Insight Tag may cause LinkedIn to set its own third-party cookies (e.g. bcookie, lidc, UserMatchHistory, AnalyticsSyncHistory) under the linkedin.com domain, and the AppsFlyer Web SDK (used for the mobile-app smart banner) stores attribution identifiers (e.g. afUserId) in your browser's local storage rather than as cookies. Both operate only where you have given consent.
3.2 Web Application Cookies and Local Storage, app.greenda.ai
The Greenda® web application at app.greenda.ai (the sign-in dashboard for experts and cooperatives) uses the following cookies and browser local storage:
| Name | Category | Provider | Purpose | Legal Basis | Expiry |
|---|---|---|---|---|---|
| greendaai_session | Strictly Necessary | Greenda | Keeps you securely signed in | Strictly necessary, no consent required | 2 hours of inactivity |
| XSRF-TOKEN | Strictly Necessary | Greenda | Protects against cross-site request forgery | Strictly necessary, no consent required | 2 hours of inactivity |
| cc_cookie | Strictly Necessary | Greenda | Stores your cookie-consent choices | Strictly necessary, no consent required | 6 months |
| Interface preferences (local storage) | Functionality | Greenda | Remembers interface settings you choose (language, menu state, table layout) | User-requested functionality, no consent required | Until you clear your browser storage |
| Mixpanel (local storage) | Analytics | Mixpanel | Tracks feature interactions and usage patterns to support product development | Consent (Art. 6(1)(a) GDPR) | Until you withdraw consent, sign out, or clear your browser storage |
Until you accept the analytics category, Mixpanel operates in a fully anonymous mode and stores no identifier on your device; if you withdraw consent, stored analytics data is cleared automatically. Web-application analytics data is ingested via Mixpanel's EU data-residency endpoint. The consent banner also offers a "marketing" category, which is reserved for future use.
The web application is delivered through the bunny.net content delivery and security network (BunnyWay d.o.o., Slovenia, EU), which does not set any cookies and does not use any tracking technologies. See our Privacy Policy for details of this processing.
3.3 Mobile Application, Device Identifiers and SDKs
The Greenda® mobile application does not use browser cookies. However, it uses the following device-level identifiers and SDKs:
- Firebase Cloud Messaging (FCM) token (Google LLC, USA): a device-specific push notification token stored to enable delivery of treatment plan notifications and service alerts. Necessary for the core service and processed on the basis of contractual necessity (Art. 6(1)(b) GDPR). Transfers to the USA are governed by Standard Contractual Clauses (SCCs).
- Firebase Remote Config (Google LLC, USA): uses a Firebase installation identifier and, for signed-in users, your account identifier (sent as a configuration signal) to deliver feature configuration and control the rollout of app features. Processed on the basis of legitimate interests in operating and maintaining the app (Art. 6(1)(f) GDPR). Transfers to the USA are governed by SCCs.
- Mixpanel SDK (Mixpanel Inc., USA): tracks in-app feature interactions and usage patterns (pseudonymised) to support product analytics and development. Analytics data is ingested via Mixpanel's EU data-residency endpoint. Active only where you have provided consent (Art. 6(1)(a) GDPR). Transfers to the USA are governed by SCCs.
- Sentry SDK (Functional Software, Inc., USA): collects crash reports and application error diagnostics (including performance measurements on a sample of sessions) so we can keep the app reliable and secure. Processed on the basis of our legitimate interests in operating a stable and secure service (Art. 6(1)(f) GDPR). Transfers to the USA are governed by SCCs.
- AppsFlyer SDK (AppsFlyer Ltd.): mobile attribution and marketing analytics. The SDK initialises in anonymised mode, in which data is not associated with an identifiable user. Where you have provided consent (Art. 6(1)(a) GDPR), it uses device and advertising identifiers (e.g. Google Advertising ID / Apple IDFA where permitted and, on iOS, only where you have also permitted tracking via App Tracking Transparency) to measure app installs, attribute marketing campaigns, and analyse in-app events. International transfers are governed by appropriate Chapter V safeguards (adequacy decision and/or SCCs).
The application also authenticates users by email one-time password (OTP) and, optionally, via Google Sign-In (OAuth). Where you choose Google Sign-In, Google processes your sign-in as an identity provider; this is described further in our Privacy Policy.
4. Managing and Withdrawing Consent
You have full control over non-essential cookies and tracking technologies. You can manage your preferences at any time through:
- Greenda® Cookie Preference Centre: visit greenda.ai/updatecookies to review and update your consent choices for the website.
- Web application cookie settings: in the web application (app.greenda.ai) you can reopen the cookie preferences at any time by visiting app.greenda.ai/?cookiePreferences=1, which reopens the cookie preferences dialog so you can review and update your choices.
- Browser settings: you can block or delete cookies directly in your browser. Note that disabling certain cookies may affect the functionality of the greenda.ai website.
- Mobile device settings: on the mobile application you can (i) reset or limit your advertising identifier through your device's privacy settings, (ii) on iOS, decline tracking under App Tracking Transparency, and (iii) withdraw analytics and attribution consent in the app's privacy settings. This controls the Mixpanel and AppsFlyer SDKs. The Firebase Cloud Messaging token cannot be disabled without losing push notifications, as it is necessary for the service.
Browser-specific instructions:
- Google Chrome: Settings, Privacy and Security, Cookies and other site data
- Mozilla Firefox: Options, Privacy & Security, Cookies and Site Data
- Apple Safari: Preferences, Privacy, Manage Website Data
- Microsoft Edge: Settings, Cookies and site permissions, Manage and delete cookies
Disabling strictly necessary cookies is not recommended: on the website they support security and performance (Cloudflare), and on the web application the sign-in and security cookies are required to stay signed in. Disabling functionality, analytics, or attribution cookies and SDKs will not prevent you from using the core platform.
5. Third-Party Providers and International Transfers
Some cookies and technologies on our platform are set or operated by third-party providers. We do not control these third parties' use of data once their technologies are active. The following third parties set cookies or process data collected via cookies, SDKs, or tags:
- Google LLC (USA): Google Tag Manager (tag deployment), GA4 analytics (two properties), Google Ads conversion tracking, Firebase Cloud Messaging, and Firebase Remote Config. Where you use Google Sign-In, Google also acts as an identity provider. Transfers to the USA are governed by SCCs. Google's privacy policy: policies.google.com/privacy.
- HubSpot, Inc. (USA, EU instance): CRM tracking, consent management, chat widget, and form-submission cookies. Data is processed on HubSpot's EU instance (app-eu1.hubspot.com); transfers to HubSpot's US entity are governed by SCCs. HubSpot's privacy policy: legal.hubspot.com/privacy-policy.
- Cloudflare, Inc. (USA): bot protection and CDN security cookies (set via HubSpot CDN). Cloudflare's privacy policy: cloudflare.com/privacypolicy.
- Meta Platforms Ireland Ltd. (Ireland / USA): advertising and conversion tracking cookies (_fbp, _fbc). Data may be transferred to Meta's US servers under SCCs. Meta's privacy policy: facebook.com/privacy/policy.
- LinkedIn Ireland Unlimited Company (part of Microsoft): LinkedIn Insight Tag for conversion tracking, retargeting and campaign analytics (li_fat_id, ln_or, and associated linkedin.com cookies). Transfers to the USA are governed by SCCs. LinkedIn's privacy policy: linkedin.com/legal/privacy-policy.
- Mixpanel, Inc. (USA): product analytics in the mobile application, the web application, and on the website. Data from the mobile and web applications is ingested via Mixpanel's EU data-residency endpoint (api-eu.mixpanel.com). Transfers to the USA are governed by SCCs. Mixpanel's privacy policy: mixpanel.com/legal/privacy-policy.
- Sentry (Functional Software, Inc., USA): error and crash monitoring SDK for our applications; stores no cookies on your device. Transfers to the USA are governed by SCCs. Sentry's privacy policy: sentry.io/privacy.
- AppsFlyer Ltd.: mobile attribution and marketing analytics SDK, and the AppsFlyer Web SDK used for the smart app-download banner on greenda.ai. International transfers are governed by appropriate Chapter V safeguards (adequacy decision and/or SCCs). AppsFlyer's privacy policy: appsflyer.com/legal/services-privacy-policy.
6. How Long Do Cookies Last?
Cookie durations vary by type and provider. As a general guide:
- Session cookies: expire when you close your browser.
- Short-lived cookies (30 minutes to 7 days): primarily HubSpot consent and session management cookies.
- Medium-duration cookies (3 to 6 months): HubSpot tracking, Meta advertising, and Google Ads conversion cookies.
- Long-duration cookies (2 years): Google Analytics (GA4) identifiers.
Web application: the sign-in and security cookies expire after 2 hours of inactivity; the consent cookie lasts 6 months; analytics data in local storage persists until you withdraw consent, sign out, or clear your browser storage.
Mobile SDK identifiers persist until you reset your advertising identifier, withdraw consent, or uninstall the app. Exact expiry periods for each website cookie are listed in the table in Section 3.
7. Updates to This Policy
We may update this Cookie Policy from time to time to reflect changes to the cookies and technologies we use, our services, or applicable law. The date of the latest revision is shown at the top of this document. We will notify you of material changes via our cookie preference centre or by displaying a notice on greenda.ai. Previous versions may be requested at contact@greenda.ai.
8. Contact Us
For any questions about this Cookie Policy or your cookie preferences:
GreendaAI GmbH
c/o Design Offices München Macherei
Weihenstephaner Str. 12
81673 Munich
Germany
Email: contact @ greenda.ai