Cookie policy
Last updated: September 2026
1. What are cookies?
Cookies are small text files that websites store on your device (computer, tablet or smartphone). They serve to make using the website more convenient and efficient. In addition to cookies, this policy also covers similar storage technologies such as local storage and session storage, to which the same rules apply under Section 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG).
Cookies can be set by us (first-party cookies) or by third parties (third-party cookies). They have different storage periods: session cookies are deleted when the browser is closed, while persistent cookies remain on your device for a defined period.
We set technically necessary cookies on the basis of Section 25(2) TDDDG in conjunction with Art. 6(1)(b) and (f) GDPR. We set all other cookies and storage technologies only with your consent under Section 25(1) TDDDG and Art. 6(1)(a) GDPR.
2. Essential cookies (technically necessary)
These cookies are strictly necessary for the operation of the platform, in particular for signing in and session management. They cannot be disabled.
- __session
- Provider
- Clerk
- Purpose
- Authentication and management of your signed-in session
- Duration
- Session, or as determined by the provider
- Legal basis
- Section 25(2) TDDDG; Art. 6(1)(b) GDPR
- __client_uat
- Provider
- Clerk
- Purpose
- Indicates in the browser whether a signed-in session exists
- Duration
- As determined by the provider
- Legal basis
- Section 25(2) TDDDG; Art. 6(1)(b) GDPR
- uc_* (Local Storage)
- Provider
- Usercentrics
- Purpose
- Stores your cookie consent and serves as proof of it. Without this entry we would have to ask you again on every page view.
- Duration
- Until you delete your browser data
- Legal basis
- Section 25(2) TDDDG; Art. 6(1)(c) and (f) GDPR
- autosync.sessionId, autosync.provider
- Provider
- Investboard
- Purpose
- Matches your return from your bank or broker to the account link in progress. Contains the identifier of the linking process and the chosen provider, no credentials.
- Duration
- Until the link is completed or canceled
- Legal basis
- Section 25(2) TDDDG; Art. 6(1)(b) GDPR
- investboard.import.activeRun.v1
- Provider
- Investboard
- Purpose
- Stores the identifier of your ongoing file import so that you can safely resume the review after a reload or an interruption. The uploaded financial data itself is not stored in the browser.
- Duration
- Until the import is completed or canceled, or a new import is started
- Legal basis
- Section 25(2) TDDDG; Art. 6(1)(b) GDPR
- import-return:*
- Provider
- Investboard
- Purpose
- Remembers, for the broker import you started, whether you return to the dashboard or to portfolio management afterwards. Contains no financial data or credentials.
- Duration
- Until the browser tab is closed
- Legal basis
- Section 25(2) TDDDG; Art. 6(1)(b) GDPR
- investboard_gate_session_id
- Provider
- Investboard
- Purpose
- Limits how often notices about paid features are shown within a session
- Duration
- Session
- Legal basis
- Section 25(2) TDDDG; Art. 6(1)(b) GDPR
- from-splash
- Provider
- Investboard
- Purpose
- Remembers for the duration of the session that you arrived through the start sequence, so that it is not played again
- Duration
- Session
- Legal basis
- Section 25(2) TDDDG; Art. 6(1)(b) GDPR
The cookies marked Clerk are set by our sign-in service Clerk Inc., not by Investboard itself. Their names and lifetimes are determined by the provider and may change; depending on the configuration, further technically necessary cookies with the prefix __clerk may be added.
3. Analytics and marketing cookies
We use these storage technologies only with your express consent through our consent management platform. They help us understand how visitors use the platform, and attribute visits to our marketing campaigns.
- ph_* (Local Storage)
- Provider
- PostHog (EU)
- Purpose
- Usage analytics: page views, click paths and feature usage
- Duration
- Until withdrawal, or until you delete your browser data
- Legal basis
- Section 25(1) TDDDG; Art. 6(1)(a) GDPR
- ib_utm
- Provider
- Investboard
- Purpose
- Marketing attribution: stores the campaign origin (UTM parameters) of your visit; set only with your consent to marketing storage and deleted on withdrawal
- Duration
- 30 days
- Legal basis
- Section 25(1) TDDDG; Art. 6(1)(a) GDPR
- _gcl_au
- Provider
- Google Ireland Limited
- Purpose
- Measurement of advertising conversions: attributes a sign-up on this website to a preceding Google ad. Set only if you have consented to marketing storage in the cookie banner; without consent, storage remains disabled through Google Consent Mode. On withdrawal the cookie is deleted.
- Duration
- 90 days, immediately on withdrawal
- Legal basis
- Section 25(1) TDDDG; Art. 6(1)(a) GDPR
Privacy note: PostHog is activated only after your consent and stores data in your browser’s local storage, not in cookies. PostHog is hosted on EU servers; we do not identify individual users by name. The ib_utm cookie is set only with your consent to marketing storage, and only if you reach Investboard through a campaign link with UTM parameters.
Google Ads conversion measurement
We measure which of our Google ads lead to a registration. For this purpose, the Google tag (gtag.js) of Google Ireland Limited is embedded on every page. It is operated in Google Consent Mode v2: as long as you have not consented, all storage purposes (ad_storage, ad_user_data, ad_personalization, analytics_storage) are set to “denied”. In this state, Google places no identifier on your device and reads none; click identifiers are additionally suppressed (ads_data_redaction). Only when you consent to marketing storage in the cookie banner is the _gcl_au cookie set. Personalized advertising and the building of remarketing audiences do not take place.
Even in the “denied” state the tag is loaded, which means that your IP address is transmitted to Google for technical reasons. The legal basis, the recipients and the transfer to the USA are described in our Privacy policy. You can withdraw your consent at any time with effect for the future through the cookie settings. On withdrawal, we automatically delete a _gcl_au cookie that has already been set.
Cookieless reach and performance measurement
In addition, we use Vercel Analytics and Vercel Speed Insights from our hosting provider Vercel. These services work without cookies and place no identifiers on your device. They transmit aggregated page-view, interaction and load-time telemetry to Vercel (Web Vitals and counted events without personal reference, such as clicks on central buttons and the visibility of page sections) in order to measure the stability, speed and clarity of the platform. The legal basis for this processing is Art. 6(1)(f) GDPR; details can be found in our Privacy policy.
4. Functional cookies
Functional cookies store settings that you make yourself. They are set only when you choose the respective setting.
- investboard-lang
- Provider
- Investboard
- Purpose
- Stores your language choice (German/English)
- Duration
- 12 months
- Legal basis
- Section 25(2) TDDDG; Art. 6(1)(f) GDPR
- theme
- Provider
- Investboard
- Purpose
- Stores your display choice (light or dark design) so that the page appears correctly from the first paint
- Duration
- 12 months
- Legal basis
- Section 25(2) TDDDG; Art. 6(1)(f) GDPR
- investboard:theme-pref
- Provider
- Investboard
- Purpose
- Secondary store of the same display choice in local storage, so that the setting is kept even without a cookie
- Duration
- Until you delete your browser data
- Legal basis
- Section 25(2) TDDDG; Art. 6(1)(f) GDPR
- investboard.sidebar.rail
- Provider
- Investboard
- Purpose
- Remembers whether the sidebar is expanded or collapsed
- Duration
- Until you delete your browser data
- Legal basis
- Section 25(2) TDDDG; Art. 6(1)(f) GDPR
- investboard.dividends.gross-mode
- Provider
- Investboard
- Purpose
- Remembers whether dividends are shown gross or net
- Duration
- Until you delete your browser data
- Legal basis
- Section 25(2) TDDDG; Art. 6(1)(f) GDPR
- ib:cmdk:recents:v1
- Provider
- Investboard
- Purpose
- Shows your most recently used commands in the quick search
- Duration
- Until you delete your browser data
- Legal basis
- Section 25(2) TDDDG; Art. 6(1)(f) GDPR
- investboard_calculator_import_dismissed
- Provider
- Investboard
- Purpose
- Remembers that you dismissed the notice about carrying over a calculator result
- Duration
- Until you delete your browser data
- Legal basis
- Section 25(2) TDDDG; Art. 6(1)(f) GDPR
- investboard:goal_*
- Provider
- Investboard
- Purpose
- Remembers, per goal, that reaching it has already been acknowledged, so that the message does not appear again
- Duration
- Until you delete your browser data
- Legal basis
- Section 25(2) TDDDG; Art. 6(1)(f) GDPR
- demo.tour.*
- Provider
- Investboard
- Purpose
- Remembers that you have already seen a demo tour
- Duration
- Until you delete your browser data
- Legal basis
- Section 25(2) TDDDG; Art. 6(1)(f) GDPR
- investboard:access-notice:v1:*
- Provider
- Investboard
- Purpose
- Remembers that you have already seen the notice about the end of your Premium trial or a change to your subscription, so that it does not appear again
- Duration
- Until you delete your browser data
- Legal basis
- Section 25(2) TDDDG; Art. 6(1)(f) GDPR
- investboard.import.draft.file.v1
- Provider
- Investboard
- Purpose
- Preserves your unfinished input in the file import across view and app switches: the portfolio name entered, the chosen target, the name and size of the last chosen file, and, for each corrected position row, the values you re-entered. The uploaded file itself and the data read from it are not stored in the browser; the entry is bound to your account.
- Duration
- Deleted when the import is completed and on sign-out; after 7 days without changes the draft is no longer used and is removed on the next visit
- Legal basis
- Section 25(2) TDDDG; Art. 6(1)(f) GDPR
- investboard.import.draft.manual.v1
- Provider
- Investboard
- Purpose
- Preserves the manually entered positions and the portfolio name across view and app switches: for each row the chosen security with its basic data (such as identifier, name, exchange and currency) as well as your quantity, your purchase price and the purchase date. The entry is bound to your account.
- Duration
- Deleted when the portfolio is created, through “Discard entries” and on sign-out; after 7 days without changes the draft is no longer used and is removed on the next visit
- Legal basis
- Section 25(2) TDDDG; Art. 6(1)(f) GDPR
- nw-onboarding-state
- Provider
- Investboard
- Purpose
- Preserves your entries in the wealth-building assistant so that reloading the page does not discard them. Contains the values you entered.
- Duration
- Session
- Legal basis
- Section 25(2) TDDDG; Art. 6(1)(f) GDPR
- autopilot-wizard-step
- Provider
- Investboard
- Purpose
- Preserves the step reached in the investment plan assistant
- Duration
- Session
- Legal basis
- Section 25(2) TDDDG; Art. 6(1)(f) GDPR
- ib:mandat-starter:v2
- Provider
- Investboard
- Purpose
- Preserves your answers in the public mandate starter so that they are kept when switching between steps and after a reload. Contains the answers you gave, with no reference to a person.
- Duration
- Deleted through “Start over”, on transfer to your account and on sign-out; after 7 days without changes the answers are no longer used and are removed on the next visit
- Legal basis
- Section 25(2) TDDDG; Art. 6(1)(f) GDPR
- ib:mandat-starter:handoff:v3
- Provider
- Investboard
- Purpose
- Transfers your answers from the mandate starter to your account once, if you register afterwards; deleted in the process
- Duration
- Until transfer or sign-out; after 7 days the entry is no longer used and is removed on the next visit
- Legal basis
- Section 25(2) TDDDG; Art. 6(1)(f) GDPR
- ib_mandat_starter_handoff_v3
- Provider
- Investboard
- Purpose
- Transfers your answers from the mandate starter to your account once, if your browser's local storage is not available; deleted on transfer and contains no reference to a person
- Duration
- Until transfer or sign-out, at most one hour
- Legal basis
- Section 25(2) TDDDG; Art. 6(1)(f) GDPR
- ib:strategy-entry:handoff:v2
- Provider
- Investboard
- Purpose
- Transfers the base strategy chosen on the product page once into the onboarding after account creation; deleted on transfer, on sign-out or at the latest after seven days
- Duration
- Until transfer or sign-out, at most seven days
- Legal basis
- Section 25(2) TDDDG; Art. 6(1)(f) GDPR
- investboard_calculator_result
- Provider
- Investboard
- Purpose
- Preserves the result of a calculator so that you can carry it over on the following page. Contains the amounts you entered.
- Duration
- Session
- Legal basis
- Section 25(2) TDDDG; Art. 6(1)(f) GDPR
In addition, Investboard stores individual interface settings in your browser’s local storage or session storage, such as the state of the sidebar, dismissed notices or intermediate states of input assistants. These entries are stored exclusively locally in your browser and are required for the function you have requested (Section 25(2) TDDDG).
5. Third parties
The following service providers set their own cookies or similar technologies as part of their integration, or process data in doing so. We refer to their respective privacy policies:
- Clerk: authentication and session management: Clerk privacy policy
- Usercentrics: consent management: Usercentrics privacy policy
- PostHog: web analytics (EU-hosted): PostHog privacy policy
- Vercel: hosting as well as cookieless reach and performance measurement: Vercel privacy policy
- Sentry: error diagnostics. In our integration, Sentry sets no cookies; the optional session recording (Session Replay) starts only after your consent: Sentry privacy policy
6. Managing and deleting cookies
You can manage or delete cookies at any time through your browser settings: automatically delete all or certain cookies when the browser is closed, block cookies from certain websites, receive a notification before a cookie is set, or disable cookies altogether.
Please note: disabling essential cookies may cause certain functions of the platform to stop working properly, in particular signing in and session management.
Browser instructions
7. Consent and cookie banner
When you first visit our platform, our consent management platform (Usercentrics) shows you a cookie dialog. In this dialog you can consent to all services that require consent, allow only essential cookies, or make individual settings for each service.
You can withdraw or adjust your consent at any time with effect for the future: through the cookie settings in the footer or through our consent management platform. On withdrawal, we delete the affected marketing cookies (ib_utm and _gcl_au).
Essential cookies are set without consent in accordance with Section 25(2) TDDDG, since they are strictly necessary for the operation of the platform.
8. Contact
If you have questions about our Cookie policy, please contact:
Investboard GmbH · Data protection
Further information on data protection can be found in our Privacy policy.