Cookie Policy
Version 2.0
1. What Are Cookies?
Cookies are small text files that are stored on your device (computer, tablet, or smartphone) when you visit a website. They enable the website to recognise your device and store certain information about your session or preferences. Similar technologies serve comparable purposes: local storage and session storage, which hold values in your browser, and IndexedDB, a small database in your browser. This policy is called a Cookie Policy because that is the familiar name, but it covers all of them — German law treats them alike, and so do we.
2. How We Use Cookies
Eigentum² uses technically necessary cookies to operate the platform. With your prior consent, we additionally use marketing cookies from Meta Platforms Ireland Ltd. to measure the effectiveness of our advertising on Facebook and Instagram and to show relevant ads.
Technically necessary cookies are set without consent in accordance with § 25(2) No. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG) and Article 5(3) of the ePrivacy Directive (2002/58/EC). All marketing cookies are set only after you have given your prior, express consent under § 25(1) TDDDG in conjunction with Article 6(1)(a) GDPR. You can withdraw that consent at any time with effect for the future via "Cookie settings" in the footer of this website.
We do not use analytics cookies. Marketing cookies are set exclusively on our public marketing pages and on the checkout page. They are never set inside the authenticated application in which you manage your properties, and no data you store in the platform is transmitted to any advertising partner.
3. Cookies and Similar Technologies We Use
The following tables list every cookie, local storage entry, session storage entry and database that the Eigentum² platform creates in your browser. Section 25 TDDDG is written in technology-neutral terms: it covers not only cookies but any storage on, or reading from, your device — including local storage, session storage and IndexedDB — and it applies whether or not the stored information is personal data. We therefore list all of them, not only the cookies.
3.1 Authentication and Session Cookies
These are created by our authentication system when you sign in. On dein-eigentum.de they all carry the __Secure- prefix, which instructs your browser to transmit them only over an encrypted connection. If a value is too large for a single cookie, your browser will show it split across several numbered entries (.0, .1, and so on); these are parts of one cookie, not additional ones.
| Name | Provider | Purpose | Type | Duration |
|---|---|---|---|---|
__Secure-eigentum.session_token | dein-eigentum.de | The session token that identifies your active session after login. | HTTP cookie (HttpOnly, Secure, SameSite=Lax) | 7 days |
__Secure-eigentum.session_data | dein-eigentum.de | A short-lived cached copy of your session, so that most page loads do not need to query our database. | HTTP cookie (HttpOnly, Secure, SameSite=Lax) | 30 seconds |
__Secure-eigentum.account_data | dein-eigentum.de | A short-lived cached copy of your account record, serving the same purpose. | HTTP cookie (HttpOnly, Secure, SameSite=Lax) | 30 seconds |
__Secure-eigentum.dont_remember | dein-eigentum.de | Records that you chose not to stay signed in, so that your session ends when you close the browser. | HTTP cookie (HttpOnly, Secure, SameSite=Lax) | Session |
__Secure-eigentum.two_factor | dein-eigentum.de | Carries the pending two-factor step between entering your password and entering your confirmation code. | HTTP cookie (HttpOnly, Secure, SameSite=Lax) | Session |
__Secure-eigentum.trust_device | dein-eigentum.de | Records that you marked this device as trusted, so that two-factor confirmation is not requested again on it. | HTTP cookie (HttpOnly, Secure, SameSite=Lax) | 30 days |
3.2 Application State Cookies
| Name | Provider | Purpose | Type | Duration |
|---|---|---|---|---|
NEXT_LOCALE | dein-eigentum.de | Stores the language you selected, so that the site is not returned to the language guessed from your connection. | HTTP cookie (SameSite=Lax) | 1 year |
sidebar_state | dein-eigentum.de | Remembers whether the dashboard sidebar is expanded or collapsed, so the layout matches your preference on each visit. | HTTP cookie | 7 days |
3.3 User Interface Preferences
These entries store only the setting you have selected yourself. They are strictly necessary within the meaning of Section 4.1, are never used for analysis or advertising, and are therefore not part of your cookie decision — our cookie banner offers no separate "preferences" category. You can change the setting itself at any time in the interface, and you can delete these entries through your browser at any time.
| Name | Provider | Purpose | Type | Duration |
|---|---|---|---|---|
theme | dein-eigentum.de | Stores your selected colour theme (light, dark, or system) so the interface renders correctly without a flash of the wrong theme. | Local storage | Until you delete it |
languagePreferences | dein-eigentum.de | Stores your selected language in the browser as well, so the interface does not change language while a page is loading. | Local storage | Until you delete it |
3.4 Consent Storage (Strictly Necessary)
These entries record the cookie decision you have made. They are strictly necessary because without them we could not honour your decision and would have to ask you again on every page. We record a decision for every visitor — whether you accept or refuse, and whether or not you have an account with us. We store refusals for exactly as long as we store consents, so that refusing does not mean being asked again on every visit.
| Name | Provider | Purpose | Type | Duration |
|---|---|---|---|---|
eigentum_cookie_consent | dein-eigentum.de | Records which cookie categories you have accepted or refused and the version of this policy your decision relates to. | Local storage | 6 months |
eig_consent | dein-eigentum.de | Records your cookie choices so they can be honoured on the server as well as in your browser. Contains no identifier and no advertising data. | HTTP cookie (SameSite=Lax, Secure) | 6 months |
eigentum_consent_id | dein-eigentum.de | A randomly generated identifier stored on your device alongside your decision. It allows us to link a later withdrawal to the consent originally given. It is not derived from any data about you, carries no meaning outside our consent records, and does not identify you. It is never transmitted to Meta or to any other third party. It is not permanent: it expires with your decision after six months, and a new identifier is issued when you decide again. | Local storage | 6 months |
Your decision remains valid for six months; after that we ask you again, so that your consent is always current rather than assumed. Six months is our own choice, not a period prescribed by law: neither the GDPR nor the German supervisory authorities set a maximum, and we have taken the shorter of the intervals in circulation — the six months recommended as best practice by the French supervisory authority (CNIL) — rather than the longer ones. It is at the same time deliberately longer than the 90-day lifetime of the Meta marketing cookies in Section 3.5, so that those cookies can never outlive the consent that permits them.
Independently of that interval, we ask you again whenever what you consented to changes. Under the guidance of the German supervisory authorities, a bundled consent no longer covers a purpose or a recipient that was not part of it, so introducing a new advertising partner or a new purpose invalidates the earlier decision. Section 7 sets out how we have applied that rule.
We additionally record your decision on our own servers so that we can demonstrate it, as Article 7(1) GDPR requires of us. The IP address contained in that record is shortened before it is stored, so that it can no longer be assigned to an individual connection. Section 5.5 of our Privacy Policy describes that record in full, and Section 8 sets out how long we keep it.
3.5 Marketing Cookies (Only With Your Consent)
The following cookies are set only after you have consented to the "Marketing" category. If you refuse, or later withdraw your consent, they are not set, and any that already exist are deleted from your device.
| Name | Provider | Purpose | Type | Duration |
|---|---|---|---|---|
_fbp | Meta Platforms Ireland Ltd. | Browser identifier. Allows Meta to recognise the same browser across visits — the basis for measuring our advertising campaigns and for building advertising audiences. | First-party HTTP cookie, set on dein-eigentum.de | 90 days |
_fbc | Meta Platforms Ireland Ltd. | Stores the Facebook click ID (fbclid) when you reach our website from a Meta advertisement, linking your visit to that specific ad click. | First-party HTTP cookie, set on dein-eigentum.de | 90 days |
Provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, D02 AX86, Ireland.
These cookies belong to the Meta Pixel, which we load only after your consent and only on our public marketing pages and on the checkout page. For the collection of this data and its transmission to Meta, we and Meta Platforms Ireland Limited are joint controllers within the meaning of Article 26 GDPR; the details are set out in Section 6.6 of our Privacy Policy. Data is transferred to the United States — see Section 7.5 of the Privacy Policy, including the note on the residual risk of such transfers.
3.6 Payment Cookies (Strictly Necessary)
When you open a page on which you can enter or manage payment details, we load Stripe's payment library so that your card details go directly to Stripe and never pass through our servers. That library sets the following two cookies on our domain. They are used by Stripe to detect fraudulent payment attempts, they are not used for advertising, and they are strictly necessary for a payment service you have explicitly requested.
| Name | Provider | Purpose | Type | Duration |
|---|---|---|---|---|
__stripe_mid | Stripe, Inc. | Fraud prevention: allows Stripe to recognise the device across payment attempts. | First-party HTTP cookie, set on dein-eigentum.de | 1 year |
__stripe_sid | Stripe, Inc. | Fraud prevention: identifies the current payment session. | First-party HTTP cookie, set on dein-eigentum.de | 30 minutes |
These cookies are set only on pages that offer payment functions — the checkout page and the billing pages inside your organisation. They are not set on our marketing pages.
3.7 Working Data in Your Browser (Strictly Necessary)
The following entries hold work in progress and interface state. They stay in your browser, are never used for analysis or advertising, and are never transmitted to any advertising partner. You can delete them at any time through your browser.
| Name | Storage | Purpose | Duration |
|---|---|---|---|
eigentum-onboarding | Local storage | Holds the details you have entered in the property wizard — including the property address and the valuation result — so that closing the tab does not lose your progress. | 7 days |
eigentum-onboarding-stepper | Local storage | Holds which step of the property wizard you had reached. | Until you delete it |
eigentum-loan-wizard:<property> | Session storage | Holds the figures you have entered in the loan wizard, so that they survive a page reload. | 24 hours, or until the tab closes |
eigentum-loan-wizard-stepper:<property> | Session storage | Holds which step of the loan wizard you had reached. | Until the tab closes |
eig_checkout_conversion | Session storage | Carries the details of a completed purchase across the redirect back from your bank's payment confirmation, so the confirmation page can be shown correctly. | Until the tab closes |
eigentum.banner.<name>.dismissedAt | Local storage | Records that you dismissed an information banner, so it is not shown to you again. | Until you delete it |
firebaseLocalStorageDb | IndexedDB | Holds the short-lived access credential that lets your browser upload and download your documents directly to our file storage. | Until you sign out or delete it |
firebase-heartbeat-database | IndexedDB | A technical record kept by our file storage library noting the days on which it was used. | Approximately 30 days |
4. Legal Basis
4.1 Technically Necessary Cookies and Storage (Sections 3.1 to 3.4, 3.6 and 3.7)
The entries listed in Sections 3.1 to 3.4, 3.6 and 3.7 are strictly necessary for the provision of the service you have explicitly requested, within the meaning of:
- § 25(2) No. 2 TDDDG (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz): Storage on the end user's device is permitted without consent when it is strictly necessary for the provider to deliver the service the user has explicitly requested.
- Article 6(1)(f) GDPR (Legitimate interests): The processing of data stored in these cookies is necessary for the purposes of our legitimate interest in providing a secure, functional, and user-friendly service.
4.2 Marketing Cookies (Section 3.5)
The cookies listed in Section 3.5 are not technically necessary. They are stored on, and read from, your device solely on the basis of your consent:
- § 25(1) TDDDG: Storing information on your terminal equipment, and accessing information already stored there, is permitted only with your consent, granted on the basis of clear and comprehensive information.
- Article 6(1)(a) GDPR: The subsequent processing of the data read from your device is based on your consent.
We do not rely on legitimate interests (Article 6(1)(f) GDPR) for marketing cookies. You may withdraw your consent at any time with effect for the future via "Cookie settings" in the footer of this website. Withdrawal is as easy as giving consent (Article 7(3) GDPR) and does not affect the lawfulness of the processing carried out before the withdrawal.
5. Third Parties and Their Cookies
5.1 Cookies Set on Our Domain by Third-Party Code
Two third parties place cookies on our own domain dein-eigentum.de through code we embed:
- Meta — the
_fbpand_fbccookies described in Section 3.5. They are first-party cookies on our domain, written by the Meta Pixel that we load. Their content is nevertheless transmitted to and evaluated by Meta Platforms Ireland Limited, which is why we treat them as marketing cookies requiring consent and do not present them as harmless first-party cookies. They are set only after your prior consent, and only on our public marketing pages and on the checkout page. Because they are set on our own domain, we can and do delete them ourselves as soon as you withdraw your consent. - Stripe — the
__stripe_midand__stripe_sidcookies described in Section 3.6. These are set on our domain by Stripe's payment library on pages that offer payment functions. They serve fraud prevention for a payment service you have explicitly requested and are not used for advertising.
5.2 Third Parties Your Browser Contacts
The following services are contacted directly by your browser when you use certain parts of the platform. Where a service is contacted, your IP address and your browser's user agent necessarily become known to it, because they are part of every internet request. Except for the Meta Pixel, none of these services is used for advertising or analysis, and none of them is used to build a profile of you.
| Service | When your browser contacts it | What it receives |
|---|---|---|
Meta Platforms Ireland Ltd. (connect.facebook.net) | Only on our public marketing pages and the checkout page, and only after you consent to marketing cookies. | See Section 3.16 of our Privacy Policy. |
Stripe, Inc. (js.stripe.com) | On the checkout page and the billing pages, so that your card details reach Stripe without passing through our servers. | Your IP address, user agent, and the payment details you enter. |
Google Ireland Ltd. / Google LLC (firebasestorage.googleapis.com, storage.googleapis.com) | Whenever you upload or open a document or image in the platform. | Your IP address, user agent, and the file being transferred. |
Google Ireland Ltd. / Google LLC (www.google.com/maps) | Only where a map of a property is displayed on a shared-property page. | Your IP address, user agent, and the coordinates of the property shown. |
unpkg (unpkg.com) and jsDelivr (cdn.jsdelivr.net) | When a PDF is previewed in the platform, and on our internal administration screens, to fetch the program code that renders it. | Your IP address and user agent. No document content is sent to them. |
These services are not loaded on our public marketing pages, with the single exception of the Meta Pixel. They are functional components of the platform, are necessary to provide features you have explicitly requested, and set no cookies on dein-eigentum.de. Where they are operated from outside the European Economic Area, Section 7 of our Privacy Policy sets out the safeguards that apply.
5.3 Sign-In With Google
When you use "Sign in with Google," you are redirected to Google's own domain, where Google may set its own cookies. These are not set on dein-eigentum.de and are governed by Google's privacy policy.
5.4 Consent Management Services
We do not use a recognised consent management service within the meaning of § 26 TDDDG and the German Consent Management Regulation (Einwilligungsverwaltungsverordnung, in force since 1 April 2025). Participation in that scheme is voluntary. Your decision is recorded by us directly, as described in Section 3.4.
6. How to Manage Cookies
6.1 Cookie Settings on This Website
You can change your decision at any time via the "Cookie settings" link in the footer of our website. Our consent banner offers exactly two categories: strictly necessary cookies, which are always active because the platform cannot be operated without them, and marketing cookies, which you can accept or refuse. There are no further categories — we use no analytics cookies and no other optional cookies. Refusing is offered with the same prominence as accepting.
Withdrawing your consent to marketing cookies takes effect immediately: the Meta Pixel is no longer executed, the _fbp and _fbc cookies are deleted from your device, and no further data is transmitted to Meta.
Refusing marketing cookies has no effect whatsoever on your access to our platform or on its functionality. We do not operate a cookie wall: no page, no feature and no part of our offering is withheld, restricted, delayed or degraded because you have refused your consent, later withdrawn it, or simply not responded to the banner at all. Consent to marketing cookies is never a condition of registering, of concluding a contract with us, or of using any function of the platform.
6.2 Browser Settings
Technically necessary cookies cannot be switched off through our cookie settings, because the platform cannot be operated without them. Disabling them in your browser may impair or prevent the use of our platform (e.g., you would not be able to stay logged in). This applies solely to strictly necessary cookies blocked at browser level; refusing marketing cookies has no such consequence and leaves every function available to you.
You can manage cookies through your browser settings:
- Google Chrome: Settings > Privacy and Security > Cookies and Other Site Data
- Mozilla Firefox: Settings > Privacy & Security > Cookies and Site Data
- Safari: Preferences > Privacy > Manage Website Data
- Microsoft Edge: Settings > Cookies and Site Permissions > Manage and Delete Cookies
Please note that blocking strictly necessary cookies will likely prevent you from using the Eigentum² platform, as authentication and session management depend on them.
7. Changes to This Cookie Policy
With version 2.0 of this Cookie Policy we have introduced the first non-essential cookies on our platform — the marketing cookies described in Section 3.5. In doing so, we have kept the commitments we made in version 1.0 of this policy:
- This Cookie Policy has been updated to list the new cookies with their provider, purpose, type and duration before they are set;
- A consent mechanism obtains your prior consent before any marketing cookie is set, and the Meta Pixel is not loaded at all until you have consented;
- "Reject All" is presented with the same prominence and accessibility as "Accept All," in compliance with CNIL guidelines and TDDDG requirements.
Because this version introduces a new purpose and a new recipient, any cookie decision recorded under version 1.0 is no longer treated as valid; you will be asked for your decision again.
If we introduce further non-essential cookies or a new advertising partner in the future, we will apply the same standard: update this policy, obtain your prior consent before setting the cookies, and ask you for your decision again.
8. Contact
If you have any questions about our use of cookies, please contact us at:
Email: support@dein-eigentum.de
For comprehensive information about how we process your personal data, please refer to our Privacy Policy.
The effective date of this version is displayed above this document.