Legal

Cookie Policy

Last updated August 4, 2026

In short

We use a small number of cookies to keep you signed in, remember your language and currency, and — only if you agree — to understand how the site is used.

We run no advertising, no third-party tracking pixels and no data brokers. Nothing on this site is shared with an advertising network.

The complete list is below, with names, purposes and durations. If a cookie is not on this list, we are not setting it.

Why this list can be trusted

Cookie policies drift: the code gains a cookie, the document does not, and nobody notices for a year.

Ours is generated from a register that sits next to the code, and an automated test walks the entire source looking for anything written to your browser. If it finds something the register does not know about, the build fails. A new cookie cannot reach you before it appears here.

That is also how we found and fixed a problem in an earlier version of this site, described under Marketing below.

Cookies, and things that behave like cookies

A cookie is a small file a website stores in your browser. Two other mechanisms do the same job — local storage and session storage — and the law treats all three the same way, because what matters is that something is stored on your device.

So this page lists all three. Session storage disappears when you close the tab; local storage stays until you clear your browser data.

Necessary — always active

These make the site work. Without them you could not stay signed in or complete a purchase, so they do not require your permission. They are all set by us, not by anyone else.

sb-… — keeps you signed in. Split across a few cookies when the session is large. Lasts until you sign out: 6 months if you ticked "Remember me", otherwise until you close the browser.

dv_persist — records whether you ticked "Remember me". 6 months.

dv_consent — remembers your cookie choices, so we do not ask on every page. Contains only your choices, the policy version and a timestamp — never an identifier. 6 months.

dv_oauth_next — remembers where you were heading while you sign in with Google. 15 minutes.

dv_consent_pv, dv_ph_disabled (local storage) — small technical flags that stop the banner reappearing needlessly and record that analytics is switched off site-wide.

dv_auth_signed_in (session storage) — stops a sign-in being counted twice in one tab. Gone when you close the tab.

Administrators additionally get dv_td (skip the two-factor prompt on a trusted device, 30 days) and dv-staff (view the site while it is in maintenance mode, 30 days).

Functional — remembering what you chose

These remember a choice you made. Under Dutch rules they do not require separate permission, because they do nothing except give you back what you asked for.

dv_locale — your language. 1 year.

dv_locale_hint — records that we offered you the Spanish version once, so we stop suggesting it. 30 days.

dv_currency — whether you want prices in euros or dollars. 1 year.

dv_country_hint — a two-letter country code used only to pre-fill the country field at checkout. It never decides your tax — what you type does. 30 days.

dv-theme (local storage) — light or dark appearance.

Administrators additionally get dv_admin_nav and a legacy dv-admin-collapsed key, which remember how the admin sidebar was arranged.

Analytics — only if you agree

Nothing here is set unless you accept analytics. Until you do, the software is not even downloaded to your browser.

ph_… — set by PostHog, which we run on European infrastructure. Distinguishes one visitor from another so a page view is not counted twice. 1 year.

dv_replay_roll (session storage) — fixes whether this visit is part of the session-recording sample, so a session is consistently in or out. Gone when you close the tab.

What PostHog receives: your account identifier if you are signed in — never your name or email address — the pages you visit and the actions you take. Web addresses are stripped of sensitive parameters first.

Session recording captures a sample of visits on public pages. Everything you type is masked, and it never runs on account, checkout or payment pages.

Marketing — only if you agree

dv_ref — records that you arrived through a partner link, so that partner can be credited if you buy. 30 days.

This is the one we got wrong, and it is worth saying so. In an earlier version of this site this cookie was set the moment you arrived through a partner link, with no permission asked, while this very page said the marketing category was "currently not in use". Both of those were wrong. It is now set only if you accept marketing cookies, and if you do not, the attribution is simply lost.

We run no advertising cookies, no retargeting, and no third-party marketing pixels.

Traffic measurement that stores nothing

We use Vercel's aggregate traffic and performance measurement. It sets no cookie and stores nothing on your device, and it produces counts rather than profiles.

Because it stores nothing on your device, it falls outside the rule that requires permission for cookies. We mention it anyway rather than leaving you to discover it, and the Privacy Policy explains the legal basis.

We also count how often each article is read, using a one-way code that cannot be traced back to you and is deleted after 45 days. The Privacy Policy explains exactly how that works.

Changing your mind

Use Cookie settings at the bottom of any page. You can turn analytics or marketing off there, and it takes effect immediately — no reload, and anything already collected in this session stops being sent.

Withdrawing is exactly as easy as agreeing. Reject-all and Accept-all are the same size, in the same place, and neither is hidden behind an extra step.

Your browser can also block or delete cookies. Blocking the necessary ones will stop sign-in and checkout working.

Questions

Email info@dominicanvest.com.

Our Privacy Policy explains what we do with personal data generally, and the Subprocessors page lists every provider involved.