Cookie Policy

Effective date: July 30, 2026

This policy explains how Nestview International, Inc. ("we," "us," or "our") uses cookies and similar technologies on nestview.com and its subdomains, including ir.nestview.com (together, the "Sites"), and how you control them. It also covers the related technologies, described in Section 4, that do the same work in our applications. Our Privacy Notice explains how we handle personal information generally.

1. What cookies are

Cookies are small text files that a website stores on your device to remember something about your visit: a language, a session, a consent choice. Each cookie has a name, a provider, a purpose, and an expiry, and your browser keeps cookies separated by the domain that set them. In this policy, "cookies" is shorthand for the whole family of technologies described in Sections 1 through 4; the same category rules apply to all of them.

2. First-party and third-party cookies

First-party cookies are set by the site you are visiting. On the Sites, that means cookies set from nestview.com or its subdomains, such as the cookie that remembers your language selection. Only our pages can read them.

Third-party cookies are set from another provider's domain through our pages, typically when a page includes content or code that the provider serves, for example an embedded video player. Because the provider can read its cookie on any site that carries its content, third-party cookies are the building block of cross-site measurement and advertising. The Sites load third-party content sparingly, and nothing outside the Necessary category loads before you have made a choice, as Section 5 describes.

Cookies on the Sites may be set or read by us, by other members of our corporate group (together with us, the "Nestview Group"), and by service partners acting on our behalf, always under the category rules and consent choices described in this policy.

3. Session and persistent cookies

A session cookie lasts only as long as your browser session: close the browser and it is gone. Session cookies hold short-lived state, such as a secure connection while you are signed in to a portal.

A persistent cookie remains on your device after the browser closes, until it expires or you delete it. Typical lifetimes run from a few hours for security tokens, through 6 to 12 months for consent records, to about two years at the long end for some analytics identifiers. The actual lifetime of every cookie on the Sites appears in the declaration in Section 8; we do not set cookies with indefinite lifetimes.

4. Similar technologies: pixels, local storage, SDKs, and device identifiers

  • Pixels (web beacons). Tiny images or code snippets embedded in a page or an email that report back to their provider when the content is viewed. On the Sites, marketing pixels belong to the Marketing category and can only ever run under your choices; our newsletters may include a standard open-rate pixel, and the Privacy Notice covers the related data.
  • Local storage. A store in your browser that a site can write values to. Unlike cookies, local storage is not sent with every request, but it can hold the same kinds of values, so our consent tool treats consent-relevant local storage entries like cookies, and the declaration in Section 8 lists them by type.
  • SDKs in applications. Mobile applications do not use browser cookies; they use software development kits (SDKs), code libraries that can perform the same measurement and preference work inside an app. When our applications, including NVaccess, offer analytics or marketing features through SDKs, they will present their own consent choices under the same category logic, and Section 13 describes the device-level controls.
  • Device identifiers. Mobile operating systems expose resettable identifiers, such as an advertising identifier, that apps may use the way websites use cookies. We treat them under the same category rules.

5. Consent: how choices work on the Sites

The Sites use a consent management tool with automatic blocking: cookies outside the Necessary category do not load until you have made a choice in the banner shown on your first visit. Choices are made per category, not all or nothing. The accept and decline controls carry equal weight, there are no pre-ticked boxes, and continuing to browse is never treated as consent.

The banner applies the rule of your region:

  • European Union, European Economic Area, United Kingdom, and Quebec: non-necessary cookies stay off unless you opt in.
  • United States: you may opt out of non-necessary cookies at any time, and we honor the Global Privacy Control signal described in Section 11.
  • Everywhere else: we apply the consent-first model.

Your choice is stored in a consent preference cookie (Section 6) so the banner does not reappear on every page. You can reopen the preferences center and change or withdraw your choices at any time, as described in Section 11, and our consent tool keeps a record of the choices you have made.

6. The categories we use

Our consent management tool groups cookies into four categories, and the banner toggles mirror them one to one. The Necessary category cannot be switched off; it is what makes the Sites and the consent choice itself work. Everything else loads only according to your choices.

For each category, this section describes what it does, what happens if you decline it, and the consent rule that applies. The representative tables show cookies that are in use now ("In use") or that could appear if we adopt a capability of that kind ("Possible"). The live declaration in Section 8 is the authoritative list at any moment: a cookie marked Possible here is not in use unless it appears there.

Necessary

What it is: cookies required to operate the Sites, including storing your consent state, keeping sessions secure, and providing core functions you request. What it enables: the banner remembers your decision, forms submit safely, and signed-in areas stay signed in. If you decline: this category cannot be declined from the banner, because the Sites cannot work without it; you can still block these cookies in your browser (Section 12), at the cost of parts of the Sites failing, including the memory of your consent choice. Consent rule: every region allows these to run without consent, under the strictly-necessary exceptions of the applicable rules.

CookieProviderPurposeDurationStatus
Consent preference cookieOur consent management toolStores the cookie consent choices you make for the Sites.12 monthsIn use
Session and security cookiesnestview.com (first party)May be set to hold a signed-in session on our owner and broker portals and to protect forms against abuse.SessionPossible

Preferences

What it is: cookies that remember choices you make, above all your language, so the Sites appear the way you chose. What it enables: pages open in your language without asking again on every visit. If you decline: the Sites still work; they simply forget your choices between visits. Consent rule: European Union, European Economic Area, United Kingdom, and Quebec, opt-in; United States, on unless you opt out. United Kingdom law also recognizes a lighter objection basis for appearance and functionality storage, noted in Section 11; we apply the stricter consent-first model in any event.

CookieProviderPurposeDurationStatus
NEXT_LOCALEnestview.com (first party)Remembers your language selection.Up to 12 monthsIn use

Statistics

What it is: cookies that measure how the Sites are used, in aggregate: which pages are read, how visitors arrive, where journeys stop. What it enables: we see what to improve. Today: our measurement is cookieless (Section 7), so the live declaration may show this category as empty. If you decline: nothing visible changes; we lose aggregate signal only where a future setup uses cookies. Consent rule: European Union, European Economic Area, United Kingdom, and Quebec, opt-in; United States, on unless you opt out.

If we ever adopt cookie-based analytics, cookies such as these may appear, and only under your choices:

CookieProviderPurposeDurationStatus
_gaGoogle AnalyticsMay be used to distinguish visitors in aggregate statistics.Up to 2 yearsPossible
_gidGoogle AnalyticsMay be used to distinguish visitors within a single day.24 hoursPossible

Marketing

What it is: cookies used to show relevant messages, cap how often you see them, and measure whether campaigns worked, together with the cookies that embedded content sets when you interact with it (Section 9). What it enables: campaign measurement and working embeds. If you decline: the Sites work exactly the same; embedded content may wait behind a placeholder until you allow it, and any advertising you encounter elsewhere is simply less connected to us. Consent rule: European Union, European Economic Area, United Kingdom, and Quebec, opt-in; United States, opt-out, with the Global Privacy Control signal honored (Section 11). Quebec's requirement that identification, location, and profiling functions stay off until activated is met by the same off-by-default toggle.

Representative cookies that may appear if we run campaigns or you activate embedded content, and only under your choices:

CookieProviderPurposeDurationStatus
_fbpMetaMay be used to measure advertising campaigns.Up to 3 monthsPossible
bcookieLinkedInMay be used as a browser identifier for campaign measurement.Up to 12 monthsPossible
VISITOR_INFO1_LIVEYouTubeMay be set by an embedded video player to estimate bandwidth and remember playback settings.Up to 6 monthsPossible
vuidVimeoMay be set by an embedded video player to measure playback.Up to 2 yearsPossible

Naming a provider in the tables above does not mean it is in use. The declaration in Section 8 is the authoritative, always-current list of what actually runs on the Sites.

7. Our setup as of the effective date

As of the effective date of this policy:

  • The only cookies the Sites set are the two marked In use in Section 6: the consent preference cookie and NEXT_LOCALE.
  • Website measurement runs in cookieless mode, using Ahrefs Analytics: visits are counted in aggregate, no analytics cookies are set, and no individual profiles are built.
  • The Sites load typefaces from Adobe Fonts (Typekit), a third-party font delivery service. Adobe receives the technical request needed to serve the font for licensing purposes; we do not use this service for advertising.
  • No advertising pixel or social media plugin is in use on the Sites.

8. The live cookie declaration

The always-current list of cookies in use on the Sites appears below. It is generated by our consent tool's regular scans, grouped by category, and shows each cookie's name, provider, purpose, expiry, and type, together with your current consent state.

If the embedded declaration ever differs from the tables in Section 6 or the summary in Section 7, the embedded declaration reflects the most recent scan and controls.

9. Cookies in embedded content

Pages on the Sites may embed content hosted by third parties: video players, maps, or social posts. An embed behaves like a small window onto the provider's own service. When it loads, or when you interact with it, the provider can set and read its own cookies and receives technical data such as your IP address.

On the Sites, embedded content that sets non-necessary cookies is tied to the categories in Section 6 and does not activate until you have opted in to the relevant category; until then, you may see a placeholder instead of the content. For example, an embedded YouTube video may set advertising cookies from associated domains, including DoubleClick, once you play it, and an embedded Vimeo player may set its own playback cookies. The declaration in Section 8 lists what each embed in use actually sets.

10. How third parties use information collected through the Sites

Providers that set third-party cookies through the Sites process the information those cookies collect under their own privacy policies, which may differ from ours and may include combining that information with data the provider gathers on other sites and services. We choose providers deliberately and limit them by category, but we do not control their processing. The declaration in Section 8 names each provider in use, so you can read its policy before opting in, and our Privacy Notice describes how we ourselves share personal information.

11. Managing your preferences

  • Change or withdraw consent. You can reopen the cookie preferences center at any time and change or withdraw your choices, with effect for the future: open your cookie preferences in your browser settings. Withdrawing consent is as easy as giving it.
  • United Kingdom visitors. United Kingdom law permits limited first-party statistics and appearance or functionality storage without prior consent where clear information and a simple, free means of objecting are provided. This policy is that information, and the preferences center linked above is the means of objecting; we currently apply the stricter consent-first model in any event.
  • Opt-out preference signals. The Global Privacy Control (GPC) is a signal your browser or a browser extension can send with every request. We honor GPC as a valid opt-out of any sale or sharing of personal information, as described in our Privacy Notice, and we process it without charging a fee, without degrading your experience, and without displaying interruptions. To use it, enable GPC in a participating browser or extension.
  • Other signals. We do not respond to other "do not track" signals, for which no settled standard exists.

12. Managing cookies in your browser

Current browsers let you block or delete cookies directly, alongside the banner on the Sites:

  • Chrome. Cookie controls sit under Settings, then Privacy and security: you can block third-party cookies, clear browsing data for a period or a site, and set per-site permissions.
  • Safari. On a Mac, open the Safari menu, then Settings, then Privacy; on iPhone and iPad, use the Safari section of the device Settings app. Safari limits most third-party cookies by default and can remove stored website data site by site.
  • Firefox. Under Settings, then Privacy & Security, the Enhanced Tracking Protection controls and the Cookies and Site Data panel set the blocking level and clear stored data.
  • Edge. Under Settings, then Cookies and site permissions, you can manage and delete cookies and site data and set per-site rules.

Your browser's help pages describe the exact steps for the version you run. In private or incognito windows, cookies are deleted when the window closes. Blocking all cookies, including Necessary ones, may stop parts of the Sites from working, as Section 14 explains.

13. Choices in our applications

Where our applications, including NVaccess, offer analytics or marketing features through SDKs (Section 4), the app will ask for the relevant choices itself, under the same category logic as the Sites. Your device adds a layer of its own: on iOS, an app must ask permission before tracking you across other companies' apps and websites, and you can change that permission under Settings, then Privacy & Security, then Tracking; on Android, you can delete or reset the advertising identifier under Settings, then Privacy, then Ads. App store listings also summarize each application's data practices.

14. If you decline or delete cookies

What changes depends on the category. Without Necessary cookies, the Sites cannot remember your consent choice, hold a secure session, or keep forms working; blocking them is possible at browser level, at the cost of parts of the Sites failing. Without Preferences cookies, your language and similar choices reset between visits. Without Statistics cookies, nothing visible changes; our aggregate picture of the Sites simply gets thinner. Without Marketing cookies, embedded content may wait behind a placeholder until you allow it, and campaigns go unmeasured. Declining a category never blocks your access to the Sites, and we do not use cookie walls.

15. Glossary

  • Consent management tool. The software that shows the banner, records your choices, blocks non-necessary cookies until you decide, and generates the declaration in Section 8.
  • Device identifier. A resettable identifier a mobile operating system exposes to apps, used the way websites use cookies.
  • First-party cookie. A cookie set by the site you are visiting; on the Sites, one set from nestview.com or its subdomains.
  • Global Privacy Control (GPC). A browser-level signal that tells websites you opt out of the sale or sharing of your personal information.
  • Local storage. A store in your browser that a site can write values to; unlike cookies, it is not sent with every request.
  • Pixel (web beacon). A tiny image or code snippet that reports back to its provider when content is viewed.
  • SDK (software development kit). A code library inside a mobile application that can do the measurement and preference work that cookies do on websites.
  • Third-party cookie. A cookie set from another provider's domain through the page you are visiting.

16. Updates to this policy

We maintain this policy as the Sites evolve. If our use of cookies changes in a way that matters, for example a new category or a new provider, the declaration in Section 8 updates with the next scan, the effective date of this policy changes, and, where the law requires, we will ask for fresh consent before the change applies to you. The effective date at the top shows the current version; earlier versions are available from legal@nestview.com on request.

17. Contact

Questions about this policy or about cookies on the Sites: legal@nestview.com. Our Privacy Notice explains how we handle personal information generally, including the rights available to you.