Skip to content

Cookie policy

Cookie Policy

Last updated: September 10, 2026

This Cookie Policy explains which cookies and which local storage Custodio Legal uses on its public site and inside the product, what each one is for, how long it lasts and how you decide about the ones that are not necessary. It names every cookie exactly as the code writes it, so you can check it in your own browser. It is governed by Ley 1581 de 2012, Colombia's data protection statute, and Decreto 1377 de 2013 (compiled into Decreto 1074 de 2015), by Ecuador's Ley Orgánica de Protección de Datos Personales (LOPDP) and its Reglamento (Decreto Ejecutivo 904 de 2023), by the Dominican Republic's Ley núm. 172-13 and by Costa Rica's Ley N° 8968 and its Reglamento (Decreto Ejecutivo N° 37554-JP). The rules are named as their own official gazettes publish them, in Spanish, so you can check each one against the source.

1. What cookies and local storage are

Cookies are small text files that the site leaves on your device (computer, tablet or phone) and that the browser sends back with every request to the same site. They serve to recognise your session, remember a preference or protect a form. A "session" cookie disappears when you close the browser; a "persistent" one lasts until the date it declares or until you delete it.

Local storage (localStorage) is a similar space in the browser, with two differences: only the code of the page you are looking at writes and reads it, it does not travel to the server with requests, and it does not expire on its own — it stays until you or the browser delete it.

2. What we use cookies for

Custodio Legal uses cookies and local storage for three things only:

  • (a) Authentication and security: keeping you signed in, protecting forms against forged requests and securing sign-in with Google;
  • (b) Preferences: remembering your language, your theme (light or dark) and the decisions you already made, such as your answer to the cookie notice;
  • (c) Campaign measurement: knowing which link brought a firm to the site. It has two halves and they are not alike. Ours is a first-party cookie that stores the labels the link already carried and the name of the site you came from, with no identifier of you (section 3). The other is the Google Ads tag, which is the only third-party purpose, is limited to the public site and only switches on if you accept it (section 4).

We use no usage-analytics or performance cookies: there is no third-party tool measuring how you browse, neither on the site nor inside the product.

3. First-party cookies and local storage

These are all the cookies Custodio Legal writes. Seven are necessary for what they do and the eighth —our own campaign-measurement cookie— carries nothing that identifies you; none serves advertising or follows you outside the site.

Cookie What it is for Duration
law_flow_session Keeps you signed in. It carries a random identifier; the server does not store that identifier but a keyed fingerprint of it. Up to 7 days from sign-in, or until you sign out.
_csrf Protects every form and every submission against requests forged from another site. Up to 24 hours.
lang Remembers the language you want to read the site and the product in. 1 year.
flash_notice Carries a read-once notice between a redirect and the page that shows it, for example the result of linking your Google account. 1 minute; deleted once shown.
oauth_state Protects sign-in with Google: it checks that Google's reply matches the request that left your browser. 5 minutes.
oauth_consent During sign-up with Google, remembers that you ticked the acceptance of the terms and the data-processing authorisation before leaving for Google. 5 minutes.
oauth_link_state Protects linking your Google account from your account settings. 5 minutes.
law_flow_attribution Remembers which link you arrived through, so we can tell which of our own campaigns brings firms in. It stores only the labels the link itself carried in the address (utm_source, utm_medium, utm_campaign, utm_content) and the name of the site you came from —not the particular page you were reading—. It carries no identifier of you: two people arriving through the same link write exactly the same value, so it cannot count visitors, cannot recognise you if you return and cannot be joined to anything. It is only written if you arrived through a labelled link or from another site, never if you type the address; and only the first time. 30 days.

All eight share the same attributes: HttpOnly (no script on the page can read them), Secure (they travel only over HTTPS) and SameSite=Lax (the browser does not send them with requests that another site originates).

In addition, we keep in your browser's local storage:

  • theme: the light or dark theme you chose, on the site and in the product;
  • cookieConsent and cookieConsentDate: your answer to the public site's cookie notice ("all" or "essential only") and the date you answered. It is what keeps us from asking you again and what tells the Google tag whether it may switch its cookies on;
  • upgrade-banner-dismissed: inside the product, that you already closed the notice inviting you to change plan.

None of these values travels to the server. They stay until you delete them from the browser settings or, for cookieConsent, from the "Cookie preferences" link (section 6).

4. Third-party cookies: the Google Ads tag

On the pages of the public site — home, about, contact, security, pricing, judicial monitoring, guides and these legal documents — we load the Google Ads tag, which is what lets us know which campaign brought a firm to us. The tag is not loaded on the sign-in and sign-up screens nor on any screen of the product: advertising measures campaigns, not what a lawyer does with their matters.

The tag loads before you decide, but it arrives with consent denied by default (Google Consent Mode v2) for its four purposes — ad storage, ad user data, ad personalisation and analytics storage — and with ad data redaction turned on. Until you accept, the tag writes no cookies, does not personalise ads and does not associate you with an advertising profile. What it does do in that state is send Google cookieless pings with the date and time of the visit, the page address, the page you came from, the browser and system you use and the consent state; as in any web request, that transmission also carries your IP address. From those pings Google models aggregate conversion figures; they do not identify your device across visits.

Only if you choose "Accept all" does the tag start working with the four purposes granted, and only from that moment: it writes _gcl_au on our domain, to attribute the visit to the click on an ad, and may write IDE on Google's domain to measure and personalise ads. Their duration is set by Google and published in its cookie policy; as of this version, _gcl_au lasts 90 days and IDE 13 months. Google LLC (United States) is responsible for its own cookies and for the processing it carries out with them, under its own privacy policy. We do not sell your personal data to advertisers and we do not use the content of your matters for advertising.

5. Legal basis and scope

Custodio Legal is offered in Colombia, in Costa Rica, in Ecuador and in the Dominican Republic. The use of cookies is governed by Ley 1581 de 2012 and Decreto 1377 de 2013 in Colombia, by Ley N° 8968 and its Reglamento (Decreto Ejecutivo N° 37554-JP) in Costa Rica, by the LOPDP and its Regulation in Ecuador, and by Ley núm. 172-13 in the Dominican Republic.

The first seven first-party cookies of section 3 and the local storage do not require your consent: they are necessary to provide the service you yourself request — signing in, protecting your submissions, reading the site in your language — (LOPDP, article 7, number 5) and, for the session and your account, they are covered by the data-processing authorisation you grant when you register (Ley 1581 de 2012, article 9). On their own they do not say who you are: they carry a random identifier or a language code. You can delete them from the browser; without them sign-in and the forms stop working.

The eighth, law_flow_attribution, does not require it either, and for a different reason: it does not process personal data of yours. It stores the labels the link you arrived through already carried written in the address, and the name of the site you came from; it contains no identifier, does not tell your browser from anybody else's and does not allow recognising you inside or outside the site. We use it to know how many people our own posts bring in, which is a legitimate interest over information that does not point at you. You can delete it from the browser whenever you like and lose nothing: it takes part in no service.

The Google cookies of section 4 only switch on with your prior, express and informed consent, which you grant by choosing "Accept all" (Ley 1581 de 2012, article 9; LOPDP, articles 7, number 1, and 8). Choosing "Essential only" or closing the notice does not grant that consent, and in that state the tag stays denied. You can withdraw your consent at any time (section 6); the withdrawal does not affect what was processed while it was in force.

6. Managing your preferences and withdrawing consent

You have four ways to decide:

  • (1) The cookie notice shown the first time you visit the public site: "Accept all" switches the Google cookies on; "Essential only" and closing the notice leave them denied;
  • (2) The "Cookie preferences" link, in the footer of every page of the public site: it deletes the answer stored in your browser, shows the notice again so you can decide anew and tells the Google tag that its four purposes are denied from that instant. It is the way to withdraw the consent you gave. Cookies Google had already written stay in your browser until they expire or until you delete them from its settings, which is where they live;
  • (3) Your browser settings, which let you view, delete and block cookies site by site;
  • (4) A browser extension for managing cookies.

Blocking the first-party cookies of section 3 prevents signing in and using the forms.

7. Retention and security

Each cookie lasts what section 3 declares and not a day longer: the session cookie, up to 7 days or until you sign out; the form-protection cookie, up to 24 hours; the language cookie, 1 year; our own campaign-measurement cookie, 30 days; the Google sign-in cookies, 5 minutes; the read-once notice, 1 minute. Local storage does not expire on its own. The session cookie carries a random identifier the server does not keep in the clear, and every first-party cookie travels only over HTTPS and out of reach of the page's scripts.

8. Changes to this policy, version and contact

The version of this policy in force is 0.0.5, effective as of September 10, 2026; it replaces version 0.0.4, of September 8, 2026, version 0.0.3, of 4 September 2026, version 0.0.2, of 4 September 2026, and version 0.0.1, in force since April 2026. Version 0.0.5 adds Costa Rica to the legal basis and scope of section 5 —Ley N° 8968 and its Reglamento, Decreto Ejecutivo N° 37554-JP—, which the text already named without the version having moved with it, and names the four rules as their source publishes them in this translation too, where Colombia's and Ecuador's were translated. It changes not one cookie, one duration or one purpose. Version 0.0.4 declares the first-party cookie law_flow_attribution, which remembers which link you arrived through for 30 days without carrying any identifier of you, and makes purpose (c) of section 2 precise, which until now described only its third-party half. Version 0.0.3 removes the law_flow_impersonate_restore cookie and the one-hour support-session duration: the feature that created them —support access with the identity of a user of the firm— no longer exists, so neither is written in any browser any more. Version 0.0.2 named every first-party cookie with its purpose, duration and attributes, declares the local storage, removes the mention of analytics and performance cookies that do not exist, corrects the legal basis of the necessary cookies, describes what the Google tag sends before you decide and adds the "Cookie preferences" link as the means to withdraw consent. We may update this policy to reflect changes in our practices or in the law; each new version is published here with its date and number, and material changes are communicated through the platform.

This policy is written in Spanish; in case of any difference with its translation, the Spanish version prevails. For questions about it, or to exercise your rights of access, rectification, cancellation and opposition under the Personal Data Processing Policy, write to us at [email protected].