Oppermind Back

Cookie Policy

Last updated: 25 May 2026  |  Effective: 25 May 2026

This Cookie Policy explains how Oppermind Pty Ltd (ABN 89 689 605 918) ("Oppermind", "we", "us", or "our") uses cookies, browser local storage, session storage, and similar technologies (collectively, "Cookies and Similar Technologies") on the Oppermind platform and any related websites (the "Service"). It should be read together with our Privacy Policy, which forms part of, and is incorporated by reference into, this Cookie Policy.

Our identity: Oppermind Pty Ltd (ABN 89 689 605 918), operating from Perth, Western Australia, Australia. For all enquiries regarding this Cookie Policy or to exercise your rights, please contact us at enquiry@oppermind.com.

Contents

  1. Scope and definitions
  2. What we use and why
  3. Categories of Cookies and Similar Technologies
  4. Inventory of items we set
  5. Third-party technologies
  6. Consent, legal bases, and jurisdictional applicability
  7. How to withdraw or change your consent
  8. Managing items through your browser
  9. Do Not Track and Global Privacy Control
  10. Retention
  11. Changes to this Cookie Policy
  12. Contact and complaints
  13. Related documents

1. Scope and definitions

This Cookie Policy applies to all visitors and users of the Service, anywhere in the world. In this Cookie Policy:

  • "Cookie" means a small data file placed on your device by your browser, typically containing a name, value, expiry, domain, and path.
  • "Local storage" and "session storage" are browser Web Storage APIs that allow the Service to store data on your device until you (or the Service) clear it.
  • "Similar technologies" includes IndexedDB, the Cache Storage API, service worker caches, pixel tags, beacons, software development kits, fingerprinting techniques, and any other client-side mechanism that stores or accesses data on your device.

For the purposes of this Cookie Policy, all of the above are treated collectively as "Cookies and Similar Technologies" because applicable laws (for example, the UK Privacy and Electronic Communications Regulations and the EU ePrivacy Directive) generally regulate the placing or reading of information on a user's device irrespective of the technical mechanism used.

2. What we use and why

Cookies and Similar Technologies allow us to operate the Service securely, remember your preferences, measure how features perform, and (where you give us consent) measure the performance of our marketing. We use them only for the purposes set out in this Cookie Policy.

We use a combination of:

  • Essential items required to authenticate you, protect the Service from abuse, and deliver core functionality;
  • Functional items that remember your preferences (such as your theme and workspace layout);
  • Analytics and advertising items that, where you have provided consent in jurisdictions that require it, help us measure the effectiveness of our marketing.

3. Categories of Cookies and Similar Technologies

We classify the items we set into four categories. The categories below define which toggles are presented in our cookie consent interface (see Section 7).

3.1 Strictly necessary (always on)

These items are essential for the Service to function and cannot be switched off in our systems. They are usually only set in response to actions you take, such as logging in, submitting a form, or setting your privacy preferences. You can configure your browser to block these items, but parts of the Service will not work as a result. These items do not require your consent under Australian, EU, UK, US or Canadian law because they are strictly necessary to deliver the Service you have requested.

3.2 Functional (consent where required by law)

These items enable enhanced functionality and personalisation, such as remembering your theme and layout. If you do not allow these items, some or all of these features may not function correctly.

3.3 Analytics and advertising (off until you consent in regulated jurisdictions)

These items allow us and our advertising partners to measure visits and conversions, understand how users arrive at the Service, and improve the performance of our marketing campaigns. They are set only with your consent in jurisdictions where prior consent is required. They are not used to combine information that directly identifies you with your activity on third-party websites without your consent.

3.4 Security (always on)

These items help us detect and block automated abuse, brute-force attacks, and malicious actors. They are strictly necessary to protect the Service, our users, and our infrastructure. Disabling them would prevent us from delivering the Service safely.

4. Inventory of items we set

The following table lists the principal items we currently set or use. Item names, mechanisms, and retention periods may change as we improve the Service. We will update this list within a reasonable period of any material change.

Item Category Mechanism Purpose Typical lifetime
accessToken Strictly necessary HTTP-only cookie or local storage (depending on environment) Authentication; identifies your active login session so you do not have to re-enter your password on every request. Session, or until logout / token expiry
csrfToken Strictly necessary (security) Cookie / header Cross-Site Request Forgery protection; ensures requests originate from your authenticated session. Session
_ipBlockCache Security (always on) Local storage Caches abuse-prevention decisions on your device to reduce repeated checks against blocked IPs and to keep the Service responsive. Up to 24 hours, refreshed on use
theme / opp-theme Functional Local storage Remembers your light / dark mode preference across visits. Until you clear it
unified_tiles_settings Functional Local storage Stores your unified workspace layout, including pinned tiles, panel positions, and per-feature display preferences. Until you clear it
tiles_settings Functional Local storage Legacy storage key used as a fallback for layout preferences for users migrating from earlier versions of the Service. Until you clear it
Google Ads tag AW-18002530892 (gtag) Analytics and advertising (consent required where applicable) Third-party script (Google) setting cookies such as _gcl_au, _gcl_aw, _gac_* and similar Measurement of marketing campaign performance and conversion tracking. Loaded only after consent is granted in jurisdictions that require prior consent (EU/EEA, UK, Switzerland, and Canadian provinces with comparable rules). Up to 90 days, in accordance with Google's documentation

The list above is illustrative and is updated from time to time. Where we add a new item that is not strictly necessary, we will continue to seek your consent in jurisdictions that require it before it is set.

5. Third-party technologies

5.1 Google Ads conversion measurement

When you load a page that includes our Google Ads tag (AW-18002530892), Google may, subject to your consent where required, set cookies and process information about your device and visit. Google acts as an independent controller for some of this processing. For information about how Google uses this data, see Google's privacy policy at policies.google.com/privacy.

5.2 Payment processing

If you visit pages that include our payment processor, Stripe, Inc., Stripe may set cookies and use similar technologies to enable secure payment processing and fraud prevention. These are treated as strictly necessary when you are completing a transaction. See Stripe's Privacy Policy and Stripe's Cookies Policy.

5.3 Bot and abuse prevention

We may use third-party bot detection and abuse prevention services that set or read certain technical identifiers on your device. These items are strictly necessary to protect the integrity of the Service and our users.

5.4 No cross-site behavioural advertising

We do not participate in cross-site advertising networks, and we do not sell or share your personal information for cross-context behavioural advertising as those terms are defined under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), or under analogous laws in Colorado, Virginia, Connecticut, Utah, Quebec, or elsewhere.

6. Consent, legal bases, and jurisdictional applicability

How we obtain your permission to use Cookies and Similar Technologies depends on where you are located, and on whether a particular item is strictly necessary. The following summary is intended for general guidance only and does not replace specific legal advice.

6.1 European Economic Area, United Kingdom, and Switzerland

Where the EU ePrivacy Directive (as implemented in your country), the UK Privacy and Electronic Communications Regulations 2003 ("PECR"), the Swiss Federal Data Protection Act, the EU General Data Protection Regulation, or the UK GDPR applies to you, we will not set any non-essential Cookies or Similar Technologies on your device until you have given your prior, freely given, specific, informed, and unambiguous consent. Where consent is the legal basis, you may withdraw it at any time as set out in Section 7. Where we rely on a legal basis other than consent (for example, performance of a contract or legitimate interests for strictly necessary items), we will say so in our Privacy Policy.

6.2 Australia

Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, we are required to be transparent about the kinds of personal information we collect and how we collect it. Express prior consent is not generally required for non-essential cookies under Australian law, but we adopt prior consent where it is required by other applicable laws and we offer Australian users equivalent controls as a matter of good practice.

6.3 United States

In the United States, we comply with the California Consumer Privacy Act, as amended (CCPA/CPRA), and analogous state laws in Colorado, Virginia, Connecticut, Utah, Texas, Oregon, Montana, and other states with comparable laws. As stated in Section 5.4, we do not sell or share your personal information for cross-context behavioural advertising. Residents of California, Colorado, Virginia, Connecticut, Utah, and other states with comparable laws may exercise applicable rights as described in our Privacy Policy.

6.4 Canada

For users in Canada, we apply the standards required by the Personal Information Protection and Electronic Documents Act (PIPEDA) and, for residents of Quebec, the Act respecting the protection of personal information in the private sector (also known as Quebec Law 25), including its requirements concerning the use of technology that collects personal information.

6.5 Other jurisdictions

If you are accessing the Service from a jurisdiction not specifically named above, your local privacy laws may grant you additional or different rights, and we will honour those rights to the extent required by applicable law.

7. How to withdraw or change your consent

7.1 Cookie preferences centre

You can change your consent preferences for Cookies and Similar Technologies at any time, without affecting the lawfulness of processing carried out before your withdrawal, by using the "Cookie preferences" control. This control is accessible from the cookie banner shown to first-time visitors in jurisdictions where prior consent is required, and from a persistent "Cookie preferences" link in the footer of the Service or, where presented, an in-app preferences panel.

7.2 Effect of withdrawal

Withdrawing your consent will:

  • Stop new non-essential items being set on your device;
  • Where technically practicable, signal to third parties (such as Google) that they should not load or set advertising or analytics items;
  • Leave strictly necessary items in place, because they cannot be disabled without preventing the Service from functioning.

To completely remove items already stored on your device, please also follow the steps in Section 8.

7.3 Account closure

Closing your Oppermind account does not, by itself, delete Cookies and Similar Technologies stored in your browser. To clear them, use your browser's site data controls or follow the guidance in Section 8.

8. Managing items through your browser

You can also manage Cookies and Similar Technologies directly through your browser. Most browsers allow you to:

  • View the items stored for a particular website;
  • Block all or selected items from being set;
  • Delete items that are already stored;
  • Run in a private or incognito mode that automatically clears items at the end of the session.

Helpful guides are published by each major browser vendor (for example, Apple Safari, Google Chrome, Microsoft Edge, Mozilla Firefox, and Brave). Please note that blocking strictly necessary items, including accessToken and csrfToken, will prevent you from logging in or using the Service.

9. Do Not Track and Global Privacy Control

The Service does not track users across third-party websites for advertising purposes, and we therefore do not respond to legacy "Do Not Track" (DNT) signals. Because we do not sell or share personal information for cross-context behavioural advertising, the Global Privacy Control (GPC) signal does not change how non-essential Cookies and Similar Technologies are loaded; we nonetheless treat GPC as a general expression of preference and honour it where applicable law requires.

10. Retention

Retention periods for each item are set out in the inventory in Section 4. Where an item has a session lifetime, it is removed when you close your browser or when your session ends. Where an item has a fixed lifetime, it is removed when the lifetime expires, when you clear browser storage, or when you withdraw the consent on which it was based. We do not extend the lifetime of consent-based items without obtaining renewed consent in line with applicable law.

11. Changes to this Cookie Policy

We may update this Cookie Policy from time to time to reflect changes in our practices, technologies, or legal obligations. The "Last updated" date at the top of this Cookie Policy indicates the date of the most recent revision. Where the changes are material, we will take reasonable steps to bring the update to your attention, including (where required) by re-displaying the cookie consent interface so that you can review your preferences. Your continued use of the Service after any update to this Cookie Policy constitutes your acceptance of the updated Cookie Policy, subject to your right to withdraw any consent at any time.

12. Contact and complaints

If you have questions, concerns, or complaints regarding this Cookie Policy or our use of Cookies and Similar Technologies, please contact us:

  • Email: enquiry@oppermind.com
  • Location: Perth, Western Australia, Australia

If you are not satisfied with our response, you may lodge a complaint with the relevant regulatory authority listed in Section 17 of our Privacy Policy, including the Office of the Australian Information Commissioner (OAIC), the UK Information Commissioner's Office (ICO), your EU/EEA supervisory authority, the Office of the Privacy Commissioner of Canada (OPC), the Commission d'accès à l'information du Québec (CAI), or the California Privacy Protection Agency (CPPA), as applicable.

13. Related documents

  • Privacy Policy
  • Terms & Conditions
  • Data Processing Addendum
  • Acceptable Use Policy
  • Accessibility Statement
  • Children's Privacy Policy
  • Refund Policy

© 2026 Oppermind Pty Ltd. All rights reserved.
Terms Privacy AUP DPA Cookies Refunds Accessibility Children's Privacy Withdraw consent