Cookie Policy
Last updated: June 9, 2026
This Cookie Policy explains how MB Covra. ("Covra.", "we", "us", or "our") uses cookies and similar technologies on the Covra. website, Business User workspaces, public booking pages, and platform administration environment.
It should be read together with our Privacy Policy. Where Covra. acts as processor on public booking pages operated by Business Users, the Business User may also operate additional tracking technologies under their own policies.
What Are Cookies and Similar Technologies
Cookies are small text files placed on your device when you visit a website. Similar technologies include local storage, session storage, and pixels. Cookies may be set by Covra. (first-party cookies) or by third parties providing integrated services (third-party cookies).
Cookies can be session cookies (deleted when you close your browser) or persistent cookies (remaining until they expire or you delete them).
How We Use Cookies
Covra. uses cookies to:
- Keep you signed in to your workspace using secure session management
- Remember your language preference across Lithuanian, English, and Russian interfaces
- Protect platform administration access with dedicated session controls
- Enable payment checkout through Stripe where subscriptions or deposits are processed
- Maintain security and basic functionality necessary for the Service to operate
We do not use advertising or cross-site tracking cookies on the core Covra. application.
Legal Basis for Cookies
Under the GDPR and the Lithuanian Law on Electronic Communications, we rely on:
- Strictly necessary cookies - legitimate interest and/or legal obligation to provide a secure, functional service; these cookies do not require consent
- Functional preference cookies (such as locale) - legitimate interest in delivering a consistent user experience; you may disable them via browser settings, though some preferences may not persist
- Third-party Stripe cookies on checkout - necessary to complete payment transactions you initiate; governed by Stripe's policies when their pages or embedded components load
Essential Platform Cookies
The following first-party cookies are essential for Covra. Business User and staff workspaces:
- session - Purpose: maintains authenticated workspace session after magic link login. Duration: up to 30 days. Type: Strictly necessary, httpOnly.
- locale - Purpose: stores your selected interface language (lt, en, or ru). Duration: up to 1 year. Type: Functional preference.
Without the session cookie, you will need to authenticate again using a magic link each time you access protected areas of the Service.
Platform Administration Cookies
Authorised Covra. platform administrators access a separate administration environment protected by two-factor authentication. The following cookie applies only to that environment:
- covra_admin_session - Purpose: maintains authenticated platform administrator session with enhanced security controls. Duration: session or short-lived persistent period aligned with security policy. Type: Strictly necessary, httpOnly.
This cookie is not set for Business Users, End Clients, or visitors to public booking pages.
Public Booking Pages and Token Portals
End Clients visiting public booking pages at /book/[slug] or using token-based portals (cancel, manage, reschedule, review, design review) may receive:
- locale - to display pages in the Business User's or visitor's selected language where supported
- Short-lived functional cookies or local storage entries supporting booking flow state, token validation, or form progress where technically required
These technologies are limited to delivering the booking or portal experience and are not used for behavioural advertising by Covra.
Third-Party Cookies - Stripe
When you complete a subscription payment, deposit, or other checkout flow processed by Stripe, Stripe may set cookies on your device to:
- Prevent fraud and authenticate transactions
- Remember payment session state during checkout
- Comply with financial regulations and security requirements
Stripe cookies are controlled by Stripe, Inc. and its affiliates. Their use is governed by Stripe's privacy policy and cookie disclosures. Covra. does not control Stripe cookie names, which may change as Stripe updates its services.
Stripe cookies are only loaded when you interact with a payment or checkout flow, not during ordinary browsing of marketing pages.
Cookie Duration Summary
Summary of Covra. first-party cookies:
- session - up to 30 days - Business User and staff authentication
- locale - up to 1 year - language preference
- covra_admin_session - session or short fixed term - platform administrator authentication
Third-party cookie durations are determined by the respective provider. Refer to Stripe's documentation for current checkout cookie information.
Managing and Deleting Cookies
You can control cookies through your browser settings. Most browsers allow you to:
- View which cookies are stored and delete them individually
- Block third-party cookies
- Block all cookies from specific sites
- Delete all cookies when you close the browser
If you block or delete strictly necessary cookies, parts of the Service - including magic link login sessions and checkout - may not function correctly.
For Stripe cookies, you may also review controls available through Stripe's checkout interface and privacy resources.
Do Not Track and Similar Signals
Some browsers transmit "Do Not Track" (DNT) signals. There is no universally accepted standard for how services should respond to DNT. Covra. does not currently respond to DNT signals, but we limit cookie use to necessary and functional purposes as described in this Policy.
Updates to This Cookie Policy
We may update this Cookie Policy to reflect changes in cookies we use, integrated providers, or legal requirements. The "Last updated" date at the top indicates when this Policy was last revised.
Where changes are material, we will provide notice through the Service or other appropriate channels. We encourage Business Users to review this Policy periodically and to disclose relevant cookie practices to their End Clients where required.
Contact Us
If you have questions about our use of cookies, contact:
- MB Covra.
- Email: hello@covra.lt
- Phone: +370 621 10999
For complaints about personal data processing related to cookies, you may also contact the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija) at www.ada.lt.