CoraSend logo CoraSend
SendReceiveCollectionsTalk to Cora
Become a Partner
ES / EN / PT
Legal

Cookie Policy – CoraSend

CoraSend's cookie policy: what cookies and local storage we use, their purposes, and how to manage them.

LEGAL-006 · v2.0 · Effective: 2026-08-17 · Last updated: 2026-08-17

Published under product-owner authorisation. Subsequent legal review scheduled.

1. What Are Cookies and Local Storage

Cookies are small text files that a website stores on a user's device when the user visits the site. Local storage (localStorage and sessionStorage) are similar browser mechanisms for storing data on the client side. These technologies allow the site to remember certain preferences or states during a session or between visits.

Cookies may be session cookies (deleted when the browser is closed) or persistent cookies (retained for a defined period). They may be first-party (managed from the CoraSend domain) or third-party (managed from external provider domains).

2. Necessary Cookies and Storage

These are essential for the Platform to function. They cannot be disabled without preventing use of core features.

  • Consent preference cookie (cs_consent): a persistent, HMAC-SHA256-signed first-party cookie. Stores the user's choice regarding optional analytics measurement (accepted / declined). Set only when the user makes an active choice. Contains no identity data, payment session data, or transaction information. Does not authorise access to any protected function of the Platform.
  • Channel session storage: short-lived tokens used during authentication and page-management flows via WhatsApp or other enabled channels. Deleted when the session ends or the token expires.
  • Infrastructure technical storage: connection management, traffic routing, and security mechanisms operated by the underlying Cloudflare infrastructure. Not directly visible to the user.

3. Optional Analytics Cookies (Google Analytics 4)

These cookies are only activated if the user explicitly accepts optional analytics measurement via the consent panel. If the user declines optional consent or makes no choice, these cookies are not set and no request is sent to Google Analytics servers.

Google Analytics 4 (property G-D3KR7GGZ9K) measures aggregate site usage: pages visited, sessions, approximate traffic sources, and general interactions. Google consent mode is applied: analytics_storage defaults to denied and is changed to granted only if the user accepts. Google Analytics advertising features, Google Signals, and ad personalisation are disabled. Data is not used to build individual profiles or for advertising purposes.

  • _ga (persistent, ~13 months): an anonymous client identifier used by Google Analytics to distinguish sessions.
  • _ga_D3KR7GGZ9K (persistent, ~13 months): Google Analytics 4 session state for the CoraSend property.

Google Analytics is operated by Google Ireland Limited (Ireland) / Google LLC (USA) under their own privacy policy. CoraSend does not have access to raw visitor click histories or individual identifiers generated by Google.

The user may withdraw analytics consent at any time via the cookie preferences link in the page footer. On withdrawal, _ga and _ga_* cookies are deleted from the device, the ga-disable-* flag is set, and no further data is sent. The page reloads to apply the change immediately.

4. Community Page Engagement Measurement (Optional)

This measurement is only activated if the user accepts optional analytics and the feature is enabled on the Platform. When both conditions are met, public community pages send aggregate engagement counters (page views, support form opens, QR expansions, content shares) to the CoraSend backend.

These counters are exclusively aggregated: no individual click histories are stored, no visitor profile is created, and no engagement identifier is linked to the identity of a donor, sender, or payment recipient. Community page engagement data and Orangepill transaction data are held in separate systems and are not combined.

This measurement does not use additional cookies. Events are sent as server-side requests within CoraSend's own infrastructure.

5. HubSpot Forms (Aliados/Partners Pages Only)

The /aliados and /en/aliados pages (and their language equivalents) embed a HubSpot contact form via the js-eu1.hsforms.net script. HubSpot may set its own cookies from HubSpot domains when the user interacts with the form. These cookies are managed by HubSpot Inc. / HubSpot Ireland Limited under their own privacy policy; CoraSend does not control HubSpot's cookie behaviour.

HubSpot forms are not present on any other routes of the site. They are not extended to community pages, the editor, payment flows, or any other section of the Platform.

6. Typefaces

CoraSend serves the site's typefaces (Plus Jakarta Sans) directly from its own servers (corasend.com/fonts/), via the Cloudflare CDN. No request is made to Google Fonts or any other external font provider. Font loading does not involve sending user data to third parties.

7. No Advertising, Pixels, or Behavioural Tracking

CoraSend does not use advertising pixels, retargeting networks, browser fingerprinting, personalised rankings based on individual visitor behaviour, or third-party social network SDKs. The Platform does not share visitor data with advertising platforms.

8. How to Manage Your Preferences

The user may manage optional analytics cookies at any time:

  • Cookie preferences panel: accessible from the page footer at any time. Allows accepting or declining optional analytics measurement and confirming the current preference state.
  • Browser settings: most browsers allow deletion of existing cookies and blocking of new ones. Instructions vary by browser; consult your browser's help documentation.
  • Provider opt-out tools: Google offers the Google Analytics opt-out browser add-on as an additional mechanism independent of the CoraSend panel.

Declining optional analytics does not affect access to community pages, payment QR codes, WhatsApp support, page creation, or any other Platform feature. It only stops aggregate engagement measurement.

9. Updates to This Policy

Material changes become effective after reasonable prior notice. Non-material changes (typographical corrections, updated contact information) may take effect upon publication. The version and effective date at the top of this document always reflect the most recent revision.

10. Contact

For any queries relating to this Policy or the processing of data on the CoraSend Platform:

Orangepill Colombia SAS
CL 127 D 56 B 90, Colombia
Email: info@corasend.com

CoraSend logo

CoraSend is a technology platform operated by Orangepill Colombia SAS (NIT 901835670-7). Payments are executed by licensed financial partners. Availability may vary by country and corridor.

© 2026 Orangepill Colombia SAS · NIT 901835670-7