Cookie Policy
Last updated: 10 October 2026
What cookies are
Cookies and similar technologies (localStorage, sessionStorage, pixels) store or read information on your device. EU ePrivacy rules require prior consent for any that are not strictly necessary to provide the service you asked for. This notice describes how staff sign-in, X-Lab CRM 2.0 WEB, and X-Lab LIMS 2.0 WEB use them.
Who is responsible
X-Lab Team operates staff sign-in and these web applications. Cookies listed here are used to run sign-in and the applications, keep them secure, and — only with your consent — measure usage or advertising. Records processed inside CRM and LIMS are handled on the laboratory’s instructions and are not governed by this cookie notice. The service keeps a copy of each choice: the time, the policy version, and whether analytics and marketing are on. A copy saved after sign-in names the staff member who made the choice. It does not include the policy text or what you do in the application.
Legal basis
Strictly necessary storage and fault reports (security, session, consent record, language, theme, workplace layout, and error reports sent to Sentry) rely on ePrivacy Article 5(3) and GDPR Article 6(1)(f) or 6(1)(b). Analytics and marketing, including Sentry performance traces and masked session recording, are used only after GDPR Article 6(1)(a) consent. You can refuse or withdraw as easily as you accept. A choice is stored for 12 months, then asked again.
Google Consent Mode
Staff sign-in and the applications use Google Consent Mode v2. Analytics and ads storage stay denied until you opt in. Google tags then wait or run cookieless pings. This meets Google’s EU user-consent requirements for measurement and ads tags. reCAPTCHA on the sign-in page is a security control and is treated as essential.
Cookie categories
Essential — always on: sign-in session, reCAPTCHA, consent record, language, theme, grid and workplace layout, and fault reports to Sentry (error message, stack, page address, and browser). Session recording stays off. Analytics — optional: Google Tag Manager / Google Analytics audience and usage measurement, plus Sentry performance traces and a masked session recording. Text, inputs, and media in the recording are masked. HTTP message bodies are not sent. Marketing — optional: Google advertising storage, ad user data, and ad personalization.
Cookies and storage we use
| Name | Purpose | Duration | Provider |
|---|---|---|---|
| xl-cookie-consent | Stores your cookie choice (analytics / marketing) and the time you made it. | 12 months | X-Lab (this site) |
| xl-consent-analytics | Tells the sign-in server whether performance traces are allowed. It repeats the analytics choice and is set only after you choose. | 12 months | X-Lab (this site) |
| xl-locale, xl-auth-locale | Remembers the UI language (English or Russian) in the application and on the sign-in page. | Until you change it or clear site data | X-Lab (this site) |
| xl-theme, xl-auth-theme | Remembers light or dark theme in the application and on the sign-in page. | Until you change it or clear site data | X-Lab (this site) |
| xl-workplace-settings, xl-grid-cols:*, view keys | Workplace idle timeout, label sizes, and table / board layout in this browser. | Until you change it or clear site data | X-Lab (this app) |
| xl.auth.tokens | Keeps the signed-in session for this browser tab. | Until you sign out or close the tab | X-Lab (this app) |
| _GRECAPTCHA | Google reCAPTCHA v3 on the sign-in page (fraud protection). | Up to 6 months | |
| Sentry fault reports | Sends the error message, stack, page address, and browser so faults can be fixed. No session recording. Always on. The IP address is not attached. | Kept by Sentry for the project retention period | Functional Software, Inc. (Sentry), United States |
| _ga, _gid, _gat, _ga_* | Audience and usage measurement through Google Tag Manager / Analytics. Set only if you accept analytics. | Up to 24 months (product-dependent) | |
| Sentry session recording and traces | Masked session recording and performance traces. Used only if you accept analytics. | Kept by Sentry for the project retention period | Functional Software, Inc. (Sentry), United States |
| _gcl_*, IDE and other ads cookies | Advertising measurement and personalization. Set only if you accept marketing. | Up to 24 months (product-dependent) |
How to change or withdraw consent
Use Cookie settings on this page, on the sign-in screen, or under Settings → Workplace. Rejecting analytics and marketing does not block sign-in. You can also delete site data in the browser. Blocking essential storage may prevent sign-in or layout restore.
Updates
If cookie purposes change, the stored consent version is invalidated and the banner is shown again. The date at the top of this page is the last editorial update.