Citiveo uses only as many cookies as necessary. This page lists every cookie and browser storage key we use, one by one — this is not a generic statement but an inventory extracted directly from the code. Consistency between this list and the code is verified automatically with every release; if they diverge, the release is blocked.
1. Strictly Necessary Cookies
Without these cookies the site cannot function: you cannot sign in or submit forms. They do not require consent under applicable law.
| Name | Purpose | Duration | Party |
|---|---|---|---|
authjs.session-token (prefixed __Secure- over HTTPS) | Carries your signed-in session | 30 days | First party |
authjs.csrf-token | Cross-site request forgery (CSRF) protection on form submissions | Session | First party |
authjs.callback-url | Remembers which page to return to after sign-in | Session | First party |
citiveo_consent | Stores the cookie preferences you have chosen — without this cookie we would have to ask you again on every page | 180 days | First party |
citiveo_2fa_device | Security: written when you tick the "remember this device" box during two-factor authentication; suppresses the verification-code prompt on this browser for 30 days. Written only if you tick the box; contains a random key and carries no tracking purpose | 30 days | First party |
citiveo_health_ack | Remembers that you acknowledged the legal notice shown on your first visit to the health tourism section; without this cookie the notice appears again on every visit | 180 days | First party |
citiveo_bypass | Our team only: the key left by a one-time link used to access the site while maintenance mode is active | 30 days | First party |
__cf_bm, cf_chl_* | Cloudflare Turnstile human-verification challenge (only on forms that include a challenge) | 30 minutes – session | Third party (Cloudflare) |
2. Functional Cookies
Preferences that make the site usable. They are not used to build a personal profile.
| Name | Purpose | Duration | Party |
|---|---|---|---|
citiveo_locale | Remembers the language you yourself selected via the language switcher or a language suggestion. Written only if you have permitted functional cookies | 1 year | First party |
partner_biz | Business panel only: remembers which of your businesses you were working on in the panel, if you manage more than one | 90 days | First party |
citiveo_last_city | Remembers the short name of the last city you opened, so the "Right now" cards on the home page lead with your city. Written only if you have permitted functional cookies | 90 days | First party |
citiveo_claim_hide_home, citiveo_claim_hide_city, citiveo_claim_hide_owner | Hides, for a while, the business-claim strip you dismissed — on the home page, on a city page, or for an account that already owns a business | 30 days | First party |
3. Browser Storage (not cookies)
These are never sent to the server; they reside in your browser only.
| Key | Location | Purpose | When deleted |
|---|---|---|---|
citiveo:new-listing-draft:v1 | localStorage | Preserves what you have typed in the business-listing form (so it is not lost when email verification opens in a new tab) | When the application is completed |
citiveo:last-city | localStorage | Remembers the last city you opened; used by the "pick up where you left off" card and the nearby-cities feature on the home page | Until manually cleared |
citiveo:search-recents:v1 | localStorage | Remembers your recent searches in the search box | Until manually cleared |
citiveo:recent:v1 | localStorage | Remembers the last few cities, places, events or searches you opened, for the "pick up where you left off" row on the home page; stays on your device only | Until you clear it on the home page or delete browser data |
citiveo:pending-save | sessionStorage | Temporarily holds a save you pressed while signed out, so it can be completed after you sign in | When the tab is closed |
citiveo:a2-dismissed | localStorage | Business panel only: remembers that you dismissed the "payment cancelled" notice; it is not shown again for the same payment | Until manually cleared |
citiveo-security-nudge | sessionStorage | Remembers that you dismissed the security reminder during the current session | When the tab is closed |
citiveo:locale-suggestion-dismissed | sessionStorage | Remembers, for the current tab, that you dismissed the language suggestion shown when your browser language differs | When the tab is closed |
citiveo:palette-recents:v1 | localStorage | Admin panel only: recently used items in the command palette | Until manually cleared |
citiveo:admin-nav-groups:v1 | localStorage | Admin panel only: which navigation groups you have left expanded in the menu | Until manually cleared |
citiveo.iconpicker.recent | localStorage | Admin panel only: recently selected icons | Until manually cleared |
4. Analytics Cookies (optional)
We use Google Analytics 4 (provider: Google) to measure how the site is used. Google Analytics 4 is loaded only with your explicit consent — that is, only when you permit the Analytics category in your cookie preferences; if you do not permit it, it is never loaded and the cookies below are never written. These cookies are placed on our domain by Google's script.
| Name | Purpose | Duration | Party |
|---|---|---|---|
_ga | Google Analytics 4: distinguishes visitors using a pseudonymous identifier | 2 years | First party (placed by Google) |
_ga_* | Google Analytics 4: maintains session state (the asterisk represents the measurement ID) | 2 years | First party (placed by Google) |
With Google Analytics 4, the pages you view and your device and browser information are measured under a pseudonymous identifier; your IP address is anonymised and is not retained by Google Analytics. Data is transferred to Google's servers in the United States; that transfer is also based on your explicit consent. Full details are set out in the Privacy and Security Policy and the KVKK Aydınlatma Metni [Clarification Notice under the Turkish Personal Data Protection Law]. We do not use the Meta Pixel or any advertising-network tag.
Business-page views and contact-button interactions are counted on our own server without cookies and without any identifier: no IP address is stored, no user identifier is written, and the browser's Do Not Track signal is honoured. The business owner sees only aggregate counts in the panel.
5. Third-Party Content
Some pages load content from external sources, and those sources receive their own technical requests:
- OpenFreeMap / OpenStreetMap — map tiles (on pages where a map is displayed).
- Cloudflare — image and static-file delivery, Turnstile verification.
- Google — Google Analytics 4, only if you have permitted the Analytics category.
- iyzico — at the payment step you are redirected to iyzico's own secure page, where iyzico's own cookies apply. Your card details are entered on that page and never reach Citiveo.
6. Managing Cookies
You can delete or block cookies from your browser settings. If you block strictly necessary cookies you will not be able to sign in. If you delete functional cookies your language preference, the last city you opened, your panel business selection and the strips you dismissed will be reset.
7. Consent Management
Non-essential cookies are used only with your explicit consent. On your first visit, an information banner appears at the bottom of the page; the banner presents "Accept all", "Reject all" and "Manage preferences" options with equal prominence. Refusing is just as easy as accepting, and no choice locks any part of the site — we do not operate a cookie wall.
Categories
- Strictly Necessary — session management, form security and human verification. Consent is not requested for these; they are required for the site to function.
- Functional — language preference, the last city you opened, the selected business in the panel, dismissed strips and the convenience entries in browser storage (see Sections 2 and 3)
- Analytics — Google Analytics 4 (2 cookies; see Section 4). Loaded only with your explicit consent
- Marketing — not currently in use; nothing is loaded under this category
The Marketing category is currently empty: nothing is loaded unless a marketing tag is configured. When a new purpose is added, the consent version is incremented and everyone is asked again — consent given for a previous purpose cannot be carried over to a new one. This was done when Google Analytics 4 was added: decisions recorded under the previous version do not cover Google Analytics 4, so everyone is asked again and no analytics script is loaded until a new decision is made.
Our own page-view counter does not fall within any of these categories. It uses no cookies, stores no IP address or user identifier, honours the browser's Do Not Track signal and produces only aggregate counts; it therefore does not require consent.
Changing Your Preferences
You may change your decision at any time via the "Cookie preferences" link in the footer. Withdrawing consent is just as straightforward as giving it. When you disable a category, collection stops immediately; data already transmitted cannot be recalled.
Record of Consent
Your decision is held in two places:
- A cookie named
citiveo_consentin your browser: a random reference number, the consent version and your category preferences. Expires after 180 days. - A record on our server: the same reference number, the date, your category preferences, the consent-text version (v2) and the language. This record is deleted after 730 days.
No raw IP address is stored. In order to be able to indicate the network from which the record originated, the IP address is held as an irreversibly salted hash and is deleted together with the record.
Google Consent Mode (Consent Mode v2)
Immediately upon page load and before any tag — including Google Analytics 4 — is loaded, all consent signals are initialised as denied (ad_storage, ad_user_data, ad_personalization, analytics_storage, functionality_storage, personalization_storage, security_storage). An update is dispatched once your decision has been received. If you have not granted analytics consent, Google Analytics 4 is not loaded.