OMVA Cookie Policy

Last updated: 2 June 2026

1. Overview

This Cookie Policy explains how OMVA uses cookies, local storage, session storage, and similar technologies across omva.co.nz, OMVA-powered sites, dashboards, quote flows, support tools, careers pages, and related services.

2. What cookies and similar technologies are

Cookies are small files stored on your device. Local storage and session storage are browser storage technologies that can store preferences, session identifiers, draft content, referral information, and product state.

3. Categories we use

Strictly necessary

Used for login, authentication, security, account access, fraud prevention, routing, dashboard state, and core platform operation. These cannot usually be switched off without breaking the service.

Examples may include:

  • authentication/session state
  • security tokens
  • dashboard/sidebar state
  • tenant routing/session state
  • checkout/billing session state where applicable
  • legal acceptance state

Preferences and functionality

Used to remember preferences and improve usability.

Examples may include:

  • theme preferences
  • sidebar or UI preferences
  • recent colours
  • editor draft state
  • notification preferences
  • language/region settings
  • careers application draft state

Referral, attribution, and performance tracking

Used to track referrals, UTM links, marketing source attribution, first-touch data, campaign performance, site performance, and commission attribution.

Examples may include:

  • referral code storage
  • UTM source/medium/campaign/content/term
  • referrer and landing page data
  • first-touch attribution
  • traffic source classification
  • conversion journey identifiers

Analytics and product improvement

Used to understand usage, performance, quote flows, conversions, feature adoption, errors, and product quality.

Examples may include:

  • page views
  • product events
  • quote events
  • growth/session identifiers
  • device/browser/OS information
  • approximate country/location
  • conversion events

Error monitoring and security

Used to detect errors, diagnose issues, monitor abuse, and protect accounts.

Examples may include:

  • error/session reports
  • request and browser metadata
  • suspicious activity indicators
  • rate-limit/security logs

Chat/help/support storage

Used to remember chat/help state, support context, draft messages, or support session IDs.

Marketing cookies

If OMVA later uses advertising pixels, remarketing, or marketing analytics, those technologies should be disclosed and, where legally required, only run after consent.

4. Consent and controls

Where legally required, OMVA should request consent before setting optional analytics, marketing, or non-essential cookies/tracking. Strictly necessary cookies may be used without consent where required to provide the service.

Users should be able to:

  • accept all optional cookies
  • reject optional cookies
  • manage preferences by category
  • change choices later

Implementation note: optional analytics/product/quote event collection should be wired to consent choices before launch in jurisdictions where consent is required.

5. Third-party technologies

Third parties that may set or receive data through cookies or similar technologies include hosting, analytics, error monitoring, authentication, email, AI, payment, payout, security, and infrastructure providers. See the Subprocessor / Third-Party Services List.

6. Browser controls

Most browsers let you block or delete cookies. Blocking cookies may affect login, dashboard access, site editing, quote flows, and other functionality.

7. Contact

For cookie/privacy questions, contact support@omva.co.nz.