Legal

Cookies

1. Introduction

This Cookie Policy explains how Native AS ("Native", "we", "us" or "our") uses cookies and similar tracking technologies on our website (https://native.no) and platform (https://app.native.no), collectively referred to as the "Services".

Native AS is the data controller for personal data collected through cookies on the Services. Contact details are provided in section 9.

The use of cookies on the Services is governed by the General Data Protection Regulation (GDPR), the Norwegian Personal Data Act, and Section 2-7b of the Norwegian Electronic Communications Act (which implements the EU ePrivacy Directive).

2. What are cookies?

Cookies are small text files stored on your device (computer, tablet or mobile) when you visit a website. They are used, among other things, to remember your settings, keep you logged in, measure usage and deliver relevant advertising.

We also use similar technologies such as local storage, tracking pixels and SDKs. In this Policy, "cookies" covers all such technologies.

3. Legal basis and consent

Under Section 2-7b of the Norwegian Electronic Communications Act, your active consent is required before we may place cookies on your device, with the exception of cookies that are strictly necessary to deliver the service you have requested.

When you visit the Services for the first time, a consent banner is displayed where you can:

  • accept all cookies,

  • reject all non-essential cookies, or

  • make individual choices per category.

Strictly necessary cookies are placed without consent, as they are required for the Services to function. For all other categories, we rely on your consent under Article 6(1)(a) of the GDPR.

You can withdraw your consent or change your choices at any time by clicking "Cookie settings" at the bottom of native.no.

4. Cookies we use

4.1 Strictly necessary cookies

These are required for the Services to function and cannot be rejected.

Cookie / purpose

Provider

Duration

Login session and authentication

Native (app.native.no)

Session / up to 30 days

CSRF token (cross-site request forgery protection)

Native

Session

Storage of cookie consent

Native / Framer

12 months

Load balancing and infrastructure

Framer (native.no)

Session

Payment session (during checkout)

Stripe

Session

Fraud prevention for payments

Stripe (__stripe_mid, __stripe_sid)

30 minutes / 1 year

4.2 Analytics cookies (consent required)

Help us understand how the Services are used so we can improve them.

Cookie / purpose

Provider

Duration

Product analytics and user behaviour

PostHog

Up to 12 months

Traffic measurement and source analysis

Google Analytics 4 (_ga, _ga_*)

Up to 14 months

PostHog is hosted in the EU (PostHog EU Cloud). Google Analytics involves transfers to the United States based on the EU–U.S. Data Privacy Framework and Standard Contractual Clauses (SCCs). IP addresses are anonymised before storage.

4.3 Marketing and advertising cookies (consent required)

Used to measure the effectiveness of marketing and deliver relevant advertising.

Cookie / purpose

Provider

Duration

Conversion tracking and audience building

Meta Pixel (_fbp, fr)

Up to 90 days

Conversion tracking and audience building

TikTok Pixel (_ttp)

Up to 13 months

Meta and TikTok transfer data to the United States and other third countries. Transfers take place on the basis of Standard Contractual Clauses (SCCs) and, where applicable, the EU–U.S. Data Privacy Framework. Meta and TikTok act as joint controllers for parts of this processing.

5. Third-party cookies

Some cookies are set by third parties when you use the Services. These providers have their own privacy policies governing their processing:

  • PostHog: posthog.com/privacy

  • Google Analytics: policies.google.com/privacy

  • Meta: facebook.com/privacy/policy

  • TikTok: tiktok.com/legal/privacy-policy

  • Stripe: stripe.com/privacy

  • Framer: framer.com/legal/privacy-policy

We recommend you read these if you want to know more about how each provider processes your data.

6. How to manage cookies

On the Services: You can change your consent at any time via the "Cookie settings" link at the bottom of native.no.

In your browser: Most browsers allow you to block or delete cookies through their settings. Please note that blocking strictly necessary cookies may cause parts of the Services to malfunction.

Opt-out for specific providers:

  • Google Analytics: tools.google.com/dlpage/gaoptout

  • Meta: facebook.com/settings?tab=ads

  • TikTok: tiktok.com/legal/page/row/personalized-ads-and-data/

  • General personalised advertising settings: youronlinechoices.eu

7. Your rights

Under the GDPR, you have the right to:

  • access the personal data we process about you,

  • request correction or deletion,

  • request restriction of processing,

  • object to processing,

  • request data portability (receive your data in a structured format), and

  • withdraw consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.

To exercise your rights, contact us at benjamin@native.no.

You also have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet) if you believe the processing is in breach of data protection law. Datatilsynet can be contacted at datatilsynet.no, by phone at +47 22 39 69 00, or by post at Postboks 458 Sentrum, 0105 Oslo, Norway.

8. Changes to this Policy

We may update this Cookie Policy when our use of cookies changes or in response to changes in law. The date of last update is shown at the top of this document. Material changes will be announced on native.no.

9. Contact

For questions about this Policy or our use of cookies, contact:

Privacy contact: Benjamin Bekken Email: benjamin@native.no

Native AS Org. no. 930 324 787 Behrens' gate 5, 0257 Oslo, Norway

This Policy is also available in Norwegian at native.no/cookies. In the event of any discrepancy, the Norwegian version prevails.