Legal
Cookie policy
Synbuild currently uses only first-party cookies that are strictly necessary to operate and secure the service.
Last updated: 23 August 2026
Article 1 – Identity and scope
Synbuild is a product platform owned and operated by Goldflux Technologies OÜ, registry code 17479596, with its registered address at Harju maakond, Kesklinna linnaosa, Pärnu mnt 139b, 11317 Tallinn, Estonia. Goldflux Technologies OÜ is the legal entity that provides all Synbuild products and services and is responsible for cookies used through Synbuild. In this policy, “Synbuild”, “we”, “us” and “our” refer to Goldflux Technologies OÜ.
For more information about Synbuild's legal entity and its relationship with Goldflux, see Legal and ownership.
Cookies are small text files stored by a browser. They can support core functions such as maintaining a secure session, remembering an authenticated user and protecting forms and checkout flows.
Article 2 – Strictly necessary cookies
2.1 synbuild_session
The synbuild_session cookie is a first-party, strictly necessary cookie used to maintain a session, support CSRF protection, preserve login and checkout continuity, and secure interactions with Synbuild.
- Provider: Goldflux Technologies OÜ through the Synbuild product.
- Type: first-party and strictly necessary.
- Default lifetime: 120 minutes after the latest activity.
- Security: HttpOnly and SameSite=Lax; transmitted over HTTPS only in production.
- Consent: not requested because the cookie is necessary to provide and secure the requested service.
2.2 XSRF-TOKEN
The XSRF-TOKEN cookie is a first-party, strictly necessary security cookie used to help verify that form and checkout requests originate from the Synbuild site and to prevent cross-site request forgery.
- Provider: Goldflux Technologies OÜ through the Synbuild product.
- Type: first-party and strictly necessary.
- Default lifetime: 120 minutes after the latest activity.
- Security: SameSite=Lax and transmitted over HTTPS only in production; readable by the site's frontend where needed to submit the security token.
- Consent: not requested because the cookie protects requested forms, sessions and transactions.
2.3 Authentication cookies
Where account login and remember-me functionality are available and selected by the user, Synbuild may set an additional encrypted authentication cookie. It is used only to recognise the returning authenticated browser and is not used for advertising or cross-site tracking.
Article 3 – Server-side telemetry and no analytics cookies
Synbuild does not currently use cookies for advertising, remarketing, behavioural profiling or non-essential third-party analytics. A consent mechanism will be introduced before any non-essential cookie or comparable tracking technology is activated where consent is required.
Synbuild records first-party, server-side request telemetry to operate, secure and improve the reliability of the service. This may include the requested URL, route, method, response status, request duration, browser information and the existing synbuild_session identifier, which is used only to relate requests within that session. Request bodies, IP addresses and identifiers derived from IP addresses are not included. This processing does not place an additional browser cookie.
Article 4 – Stripe and external payment pages
Where online payment is available, Synbuild may redirect the customer to a payment page operated by Stripe. Cookies set by Stripe on Stripe's own environment are controlled by Stripe and are governed by Stripe's own privacy and cookie information; they are not presented here as cookies placed by Synbuild.
Synbuild will review and update this policy when live online payment is enabled or if payment functionality causes additional cookies to be set on a Synbuild-controlled page.
Article 5 – Browser controls
You can remove or block cookies through your browser settings. Blocking strictly necessary cookies may prevent sessions, forms, checkout or account features from working correctly.
Article 6 – Changes and contact
Synbuild performs a new cookie review before introducing analytics, embedded third-party content, tracking or materially different account or payment functionality. The current version and its last-updated date are published on this page.
Questions about cookies can be sent to hello@syn.build.