Cookie Policy

StayClean rules for cookies and similar technologies: essential functions, optional purposes, consent, refusal, withdrawal and tracking transparency.

Version dated 16 September 2026.

1. Publisher, purpose and scope

This policy governs cookies and similar technologies on StayClean websites, applications and interfaces. The publisher is StayClean Global Services OÜ, an Estonian company registered under number 17490333, with its registered office at Harju maakond, Tallinn, Kesklinna linnaosa, Tornimäe tn 5, 10145, Estonia. Contact: william.rudent@stayclean.io.

It supplements the privacy policy. Acceptance of this document is not a basis for indiscriminately placing trackers. Each technology must be assessed according to its actual function, the information involved and the rules applicable to the user's device.

2. Technologies covered

A cookie is a file or identifier stored on, or read from, a device. Depending on their operation, local storage, session storage, pixels, tags, advertising identifiers, mobile SDKs, individualised links and fingerprinting techniques are also covered.

A technology remains subject to the relevant rules even if it does not use the word “cookie”, contains no directly identifying name or subsequently forwards events between servers. A pseudonymous identifier may be personal data where it enables an individual or device to be distinguished or linked.

3. Classification by purpose

Classification depends on actual purpose: essential operation, optional preferences, audience measurement or marketing. A technical provider, short lifespan or economic interest does not automatically make a tracker necessary.

This policy describes permitted categories and their activation conditions; it does not mean all categories are currently present on every page. A tool serving multiple purposes must be configured to respect the conditions for each. Optional tracking must not be concealed inside a security feature.

4. Strictly necessary technologies

Where genuinely essential to a service expressly requested, this category may include maintaining an authenticated session, preventing fraudulent requests, preserving a checkout process, necessary technical load balancing or remembering tracking choices.

An exemption from consent for storage or access does not remove transparency, minimisation, security or legal-basis requirements for associated personal-data processing. These tools must not be repurposed for advertising targeting or behavioural analysis without meeting the corresponding conditions.

5. Optional preferences and personalisation

Features may remember a language, display setting or interface preference. Classification depends on context: a preference needed to fulfil an explicit request is not equivalent to marketing personalisation or persistent recognition across services.

Where consent is required, these features remain disabled before a positive choice. Refusal must not remove essential functions that can operate without that personalisation. Users retain the ability to change their choice.

6. Audience measurement and usage analysis

Measurement tools, if deployed, may help understand traffic, errors or feature usage. They do not enjoy a blanket exemption merely because they improve the product or present aggregated results.

An exemption may be used only if all applicable local conditions are actually met, including limited purposes, tracking scope, recipients and duration. Otherwise, storage, access and events requiring consent remain blocked before authorisation. Anonymising information after collection does not cure unlawful collection.

7. Marketing, attribution and advertising

Conversion pixels, advertising identifiers, remarketing audiences and cross-site matching, where used, are optional and require the appropriate choices before activation. Subscribing to a newsletter or accepting a commercial contract does not constitute consent to these activities.

The entities involved and their purposes must be identified before the choice. No general consent to unidentified partners may be inferred from browsing. Rejecting marketing does not invalidate an already valid booking, cleaning job or subscription.

8. Third-party services and embedded content

Maps, videos, messaging, external sign-in, payment services and other modules may communicate with third-party domains. Their loading must be assessed before deployment. Where it involves optional tracking, the module must remain blocked or use a genuinely exempt mode until the relevant consent is obtained.

A third party's own policy does not discharge StayClean's obligations concerning the integration it chooses. Conversely, processing following a deliberate visit to a separate service is also governed by that service's information and responsibilities.

9. Obtaining a valid choice

Consent must be freely given, specific, informed and expressed through a positive action. Pre-ticked boxes, continued browsing, closing a banner or general acceptance of terms are insufficient. Optional purposes must be capable of being accepted or refused intelligibly.

Refusal must be as accessible as acceptance, without artificially discouraging steps. The interface must permit purpose-specific selection and, where required, selection of the entities involved. No technology requiring consent may be triggered while a choice is pending.

10. Withdrawal and preference changes

A permanent, easily accessible preference control must allow users to change their decision as easily as they accepted. Requests may also be sent to the stated contact, without this channel replacing a direct interface control where one is required.

Withdrawal stops future activation based on the relevant consent. Affected trackers are removed or disabled to the extent technically controlled; instructions may be needed for storage controlled directly by a third party. Withdrawal does not affect the lawfulness of earlier processing or require deletion of the limited consent evidence legally needed.

11. Lifespans and renewal of choices

Expiry periods must be defined for each technology, disclosed before activation and limited to what is necessary. Session cookies normally end with the session; persistent storage requires an explicit duration. Technical convenience alone cannot justify a lengthy lifespan.

The reference schedule under this policy provides for remembering acceptance or refusal for six months, unless different local requirements or a relevant change justify presenting the choice again. This is not a universal lifespan for all cookies. Evidence of a choice is retained separately and proportionately to compliance-demonstration needs. A new purpose or recipient requiring consent cannot be added retrospectively.

12. Inventory and deployment controls

Before optional technologies are activated, the inventory accessible from the preference interface must specify, for each relevant tool, its name or identifier, the entity placing or operating it, domain, purpose, duration, category and useful recipient or transfer information. Mobile versions and authenticated journeys must also be examined.

This classification is not a technical inventory resulting from a browser audit and does not claim to identify unverified cookies. An uninventoried optional technology must not be activated before the necessary information and choice are provided. Changes to tags, SDKs and suppliers require configuration review.

13. Cloud, CDNs and international routing

StayClean's declared infrastructure involves AWS, Vultr, DigitalOcean and Railway depending on the component. A content delivery network or traffic-protection service may process IP addresses and connection data to route or secure a request. That does not automatically make all its identifiers necessary.

International reach, technical replication or a CDN point of presence does not remove data protection duties. Access and transfers outside the European Economic Area must be governed by the privacy policy and applicable safeguards. Consent to a cookie is not indiscriminate permission to transfer every piece of data everywhere.

14. Server logs and separate processing

Some connection information reaches servers without placing a cookie. It may be needed to deliver the page, authenticate a user or maintain security. Where personal, it remains subject to minimisation, retention limits and a suitable legal basis.

Server-side tracking must not circumvent a refusal concerning an operation that still requires consent. An event needed for invoicing must not automatically be repurposed for advertising merely because it already exists in the system.

15. Browser and device settings

Browsers generally allow certain storage to be inspected, blocked or deleted. Deletion may erase a remembered choice and lead to a new request. Blocking necessary technologies may affect authentication or a specifically requested feature; refusing only optional tools must not artificially produce that result.

Device settings, preference signals and choices made in another browser do not necessarily synchronise. Their handling must comply with applicable obligations and features actually deployed. This policy does not claim unverified universal support for every technical preference signal.

16. Rights, complaints and changes

For questions, write to william.rudent@stayclean.io. Access, correction, deletion, restriction, objection, withdrawal and complaint rights are explained in the privacy policy. Estonia's data protection authority is Andmekaitse Inspektsioon; other authorities may be competent depending on your situation.

Estonian law and applicable European rules provide the reference framework without excluding mandatory territorial requirements, particularly on consent. This policy must remain aligned with actual deployments. No update constitutes consent to a new purpose or waiver of a statutory right.

Version dated 16 September 2026.

1. Publisher, purpose and scope

This policy governs cookies and similar technologies on StayClean websites, applications and interfaces. The publisher is StayClean Global Services OÜ, an Estonian company registered under number 17490333, with its registered office at Harju maakond, Tallinn, Kesklinna linnaosa, Tornimäe tn 5, 10145, Estonia. Contact: william.rudent@stayclean.io.

It supplements the privacy policy. Acceptance of this document is not a basis for indiscriminately placing trackers. Each technology must be assessed according to its actual function, the information involved and the rules applicable to the user's device.

2. Technologies covered

A cookie is a file or identifier stored on, or read from, a device. Depending on their operation, local storage, session storage, pixels, tags, advertising identifiers, mobile SDKs, individualised links and fingerprinting techniques are also covered.

A technology remains subject to the relevant rules even if it does not use the word “cookie”, contains no directly identifying name or subsequently forwards events between servers. A pseudonymous identifier may be personal data where it enables an individual or device to be distinguished or linked.

3. Classification by purpose

Classification depends on actual purpose: essential operation, optional preferences, audience measurement or marketing. A technical provider, short lifespan or economic interest does not automatically make a tracker necessary.

This policy describes permitted categories and their activation conditions; it does not mean all categories are currently present on every page. A tool serving multiple purposes must be configured to respect the conditions for each. Optional tracking must not be concealed inside a security feature.

4. Strictly necessary technologies

Where genuinely essential to a service expressly requested, this category may include maintaining an authenticated session, preventing fraudulent requests, preserving a checkout process, necessary technical load balancing or remembering tracking choices.

An exemption from consent for storage or access does not remove transparency, minimisation, security or legal-basis requirements for associated personal-data processing. These tools must not be repurposed for advertising targeting or behavioural analysis without meeting the corresponding conditions.

5. Optional preferences and personalisation

Features may remember a language, display setting or interface preference. Classification depends on context: a preference needed to fulfil an explicit request is not equivalent to marketing personalisation or persistent recognition across services.

Where consent is required, these features remain disabled before a positive choice. Refusal must not remove essential functions that can operate without that personalisation. Users retain the ability to change their choice.

6. Audience measurement and usage analysis

Measurement tools, if deployed, may help understand traffic, errors or feature usage. They do not enjoy a blanket exemption merely because they improve the product or present aggregated results.

An exemption may be used only if all applicable local conditions are actually met, including limited purposes, tracking scope, recipients and duration. Otherwise, storage, access and events requiring consent remain blocked before authorisation. Anonymising information after collection does not cure unlawful collection.

7. Marketing, attribution and advertising

Conversion pixels, advertising identifiers, remarketing audiences and cross-site matching, where used, are optional and require the appropriate choices before activation. Subscribing to a newsletter or accepting a commercial contract does not constitute consent to these activities.

The entities involved and their purposes must be identified before the choice. No general consent to unidentified partners may be inferred from browsing. Rejecting marketing does not invalidate an already valid booking, cleaning job or subscription.

8. Third-party services and embedded content

Maps, videos, messaging, external sign-in, payment services and other modules may communicate with third-party domains. Their loading must be assessed before deployment. Where it involves optional tracking, the module must remain blocked or use a genuinely exempt mode until the relevant consent is obtained.

A third party's own policy does not discharge StayClean's obligations concerning the integration it chooses. Conversely, processing following a deliberate visit to a separate service is also governed by that service's information and responsibilities.

9. Obtaining a valid choice

Consent must be freely given, specific, informed and expressed through a positive action. Pre-ticked boxes, continued browsing, closing a banner or general acceptance of terms are insufficient. Optional purposes must be capable of being accepted or refused intelligibly.

Refusal must be as accessible as acceptance, without artificially discouraging steps. The interface must permit purpose-specific selection and, where required, selection of the entities involved. No technology requiring consent may be triggered while a choice is pending.

10. Withdrawal and preference changes

A permanent, easily accessible preference control must allow users to change their decision as easily as they accepted. Requests may also be sent to the stated contact, without this channel replacing a direct interface control where one is required.

Withdrawal stops future activation based on the relevant consent. Affected trackers are removed or disabled to the extent technically controlled; instructions may be needed for storage controlled directly by a third party. Withdrawal does not affect the lawfulness of earlier processing or require deletion of the limited consent evidence legally needed.

11. Lifespans and renewal of choices

Expiry periods must be defined for each technology, disclosed before activation and limited to what is necessary. Session cookies normally end with the session; persistent storage requires an explicit duration. Technical convenience alone cannot justify a lengthy lifespan.

The reference schedule under this policy provides for remembering acceptance or refusal for six months, unless different local requirements or a relevant change justify presenting the choice again. This is not a universal lifespan for all cookies. Evidence of a choice is retained separately and proportionately to compliance-demonstration needs. A new purpose or recipient requiring consent cannot be added retrospectively.

12. Inventory and deployment controls

Before optional technologies are activated, the inventory accessible from the preference interface must specify, for each relevant tool, its name or identifier, the entity placing or operating it, domain, purpose, duration, category and useful recipient or transfer information. Mobile versions and authenticated journeys must also be examined.

This classification is not a technical inventory resulting from a browser audit and does not claim to identify unverified cookies. An uninventoried optional technology must not be activated before the necessary information and choice are provided. Changes to tags, SDKs and suppliers require configuration review.

13. Cloud, CDNs and international routing

StayClean's declared infrastructure involves AWS, Vultr, DigitalOcean and Railway depending on the component. A content delivery network or traffic-protection service may process IP addresses and connection data to route or secure a request. That does not automatically make all its identifiers necessary.

International reach, technical replication or a CDN point of presence does not remove data protection duties. Access and transfers outside the European Economic Area must be governed by the privacy policy and applicable safeguards. Consent to a cookie is not indiscriminate permission to transfer every piece of data everywhere.

14. Server logs and separate processing

Some connection information reaches servers without placing a cookie. It may be needed to deliver the page, authenticate a user or maintain security. Where personal, it remains subject to minimisation, retention limits and a suitable legal basis.

Server-side tracking must not circumvent a refusal concerning an operation that still requires consent. An event needed for invoicing must not automatically be repurposed for advertising merely because it already exists in the system.

15. Browser and device settings

Browsers generally allow certain storage to be inspected, blocked or deleted. Deletion may erase a remembered choice and lead to a new request. Blocking necessary technologies may affect authentication or a specifically requested feature; refusing only optional tools must not artificially produce that result.

Device settings, preference signals and choices made in another browser do not necessarily synchronise. Their handling must comply with applicable obligations and features actually deployed. This policy does not claim unverified universal support for every technical preference signal.

16. Rights, complaints and changes

For questions, write to william.rudent@stayclean.io. Access, correction, deletion, restriction, objection, withdrawal and complaint rights are explained in the privacy policy. Estonia's data protection authority is Andmekaitse Inspektsioon; other authorities may be competent depending on your situation.

Estonian law and applicable European rules provide the reference framework without excluding mandatory territorial requirements, particularly on consent. This policy must remain aligned with actual deployments. No update constitutes consent to a new purpose or waiver of a statutory right.