Cookie notice

AOV currently uses first-party cookies and related browser state only for necessary workspace operation. Login is not blocked behind a cookie consent gate because these cookies are required to provide the authenticated service.

Cookie or statePurposeCategoryRetentionConsent or opt-out
Auth session cookieKeeps the signed-in session active and binds requests to the authenticated person.Strictly necessarySession or configured auth-session lifetimeRequired for sign-in; not optional while using the app
CSRF cookie/tokenProtects sign-in and cookie-authenticated writes from cross-site request forgery.Strictly necessaryShort-lived/sessionRequired for secure form and API writes
Callback/redirect handlingReturns the user to the intended same-origin workspace page after authentication.Strictly necessaryShort-lived/sessionRequired for login flow continuity
aov_active_contextStores the selected organization, agreement, vendor, IV, org-admin, or AOV context.Strictly necessarySession-oriented workspace preferenceRequired for correct authorization context

Non-essential scripts

AOV does not currently load analytics, marketing, advertising, session replay, or cross-site tracking scripts. Any future non-essential script category must be held until the user has a real preference control.