Last updated: July 9, 2026
This Cookie Policy explains how Visto n' Visa, LLC ("Visto n' Visa", "we") uses cookies, pixels, local storage, session storage, limited fingerprinting, and similar technologies (collectively, "Cookies") on the website vistonvisa.com and its versions in other languages, subdomains, and applications (the "Services"). This Policy is incorporated into our Privacy Policy.
1. What are Cookies
1.1. Cookies are small text files with a unique identifier, placed by a browser on your device (computer, phone, or tablet) when you visit a website. They allow the site to recognize your browser, remember your preferences, maintain authenticated sessions, measure audience, and personalize the experience.
1.2. Similar technologies include, among others: local storage and session storage (data stored within the browser itself), web beacons and tracking pixels (1×1 pixel images used to track email opens or page views), SDKs in mobile applications, and platform advertising identifiers (IDFA on iOS, AAID on Android).
2. Cookie classification
2.1. For purposes of this Policy, we classify Cookies into four categories, in accordance with the international standard adopted by European data protection authorities and the UK ICO:
- Strictly necessary (essential) — indispensable to the functioning of the Services (session management, authentication, security, load balancing, fraud prevention, cookie consent). No consent is required; disabling them impairs Service operation.
- Performance and analytics — measure audience, traffic, bottlenecks, and experience quality, generally on an aggregated and/or pseudonymized basis.
- Functional — remember preferences (language, currency, layout, theme) and enhance the experience without being essential.
- Marketing and advertising — campaign attribution, remarketing, conversion optimization, advertising ROI measurement, and ad personalization on third-party platforms.
2.2. By origin, cookies may be first-party (set directly by Visto n' Visa) or third-party (set by providers integrated into the Services and typically loaded through Google Tag Manager, such as Google, Meta, LinkedIn, TikTok, or Hotjar). By duration, they may be session cookies (deleted when the browser is closed) or persistent cookies (with a defined expiration date).
3. Cookies used in the Services
3.1. The table below describes the Cookies typically used in the Services. The Cookies actually active in your session may vary depending on the features you access, active integrations, and your consent preferences.
3.1. Strictly necessary
| Cookie | Provider | Purpose | Duration |
|---|---|---|---|
visto-n-visa-session | vistonvisa.com | Session and authentication identifier (server-side) | 7 days |
XSRF-TOKEN | vistonvisa.com | CSRF attack protection | 7 days |
__cf_bm | Cloudflare | Bot and automated-abuse mitigation | 30 minutes |
cf_clearance | Cloudflare | Security challenge validation (anti-DDoS) | up to 1 year |
__stripe_mid | Stripe | Payment fraud prevention | 1 year |
__stripe_sid | Stripe | Checkout session | 30 minutes |
3.2. Performance and analytics
Loaded through Google Tag Manager, subject to consent — may not be active at this time.
| Cookie | Provider | Purpose | Duration |
|---|---|---|---|
_ga | Google Analytics 4 | Anonymous visitor identification | 2 years |
_ga_* | Google Analytics 4 | Session state and measurement | 2 years |
_gid | Google Analytics | Daily visitor identifier | 24 hours |
_gat / _gat_* | Google Analytics | Request rate throttling | 1 minute |
_hjSessionUser_* | Hotjar | Anonymous visitor identifier | 1 year |
_hjSession_* | Hotjar | Recording session and heatmap | 30 minutes |
3.3. Functional
| Cookie | Provider | Purpose | Duration |
|---|---|---|---|
vnv_lang | vistonvisa.com | Language chosen by the user (PT/EN/ES) — keeps the site in the last selected language, even if the browser or country suggests another | 1 year |
theme | vistonvisa.com | Theme preference (light/dark) | ~10 years |
viston_ref | vistonvisa.com | Attribution of the referral that brought you (affiliate program) | 14 days |
vnv_chat_dock_state | vistonvisa.com | State of the messaging panel in the logged-in area (open or collapsed) — remembers your last choice between visits | 1 year |
vnv_sidebar | vistonvisa.com | State of the panel side menu (expanded or collapsed) | 1 year |
3.4. Marketing and advertising
Loaded through Google Tag Manager, subject to consent — may not be active at this time.
| Cookie / pixel | Provider | Purpose | Duration |
|---|---|---|---|
_gcl_au | Google Ads | Conversion attribution | 90 days |
_fbp | Meta Pixel (Meta Platforms, Inc.) | Conversion attribution and remarketing | 90 days |
fr | Meta | Ad personalization identifier | 90 days |
NID | Google preferences and personalization | 6 months | |
bcookie / lidc | LinkedIn Insight Tag | Attribution in LinkedIn campaigns | up to 1 year |
_ttp | TikTok Pixel | Attribution in TikTok campaigns | 13 months |
3.2. Do Not Track policy. Our ecosystem honors the Global Privacy Control (GPC) signal when emitted by a browser, treating it as a valid opt-out instruction for California residents under the CCPA/CPRA. The generic browser DNT signal is treated equivalently whenever technically feasible.
4. Legal basis
4.1. Strictly necessary Cookies are used on the basis of legitimate interest (LGPD art. 7, IX; GDPR Art. 6.1.f) or performance of a contract (Art. 6.1.b), as they are indispensable to providing the Services.
4.2. All other categories (performance, functional, marketing) are used on the basis of consent (LGPD art. 7, I; GDPR Art. 6.1.a), expressed by an affirmative action in the consent banner.
4.3. California "sharing"/"sale". For residents of California, loading the marketing/advertising cookies and pixels listed in Section 3.4 (such as Google, Meta, TikTok, and LinkedIn) may constitute "sharing" — and, under some interpretations, a "sale" — of personal information for cross-context behavioral advertising under the CCPA/CPRA. We do not engage in such sharing by default; it occurs only after you opt in through the consent banner, and we honor opt-out requests and the Global Privacy Control (GPC) signal.
5. How to manage your consent
5.1. Consent banner. Before any non-essential cookie (performance/analytics or marketing) is set, on your first access to the Services we display a banner where you may "Accept all," "Reject non-essential," or customize your preferences by category. Non-essential cookies are blocked until you give consent (prior opt-in), as required in the EU/UK. The banner is not shown only when, for that session, no non-essential cookies are available to be set.
5.2. Review and withdrawal. You may review and withdraw your consent at any time through the cookie preferences center (where available) or via the browser settings described in item 5.3. Withdrawal is not retroactive with respect to processing already carried out, but stops any new processing based on the withdrawn categories.
5.3. Browser settings. You may also block or delete cookies directly in your browser. Reference guides:
5.4. Impact of disabling cookies. Disabling essential cookies prevents login, cart, payment, security, and other authenticated features from functioning. Disabling performance/functional cookies reduces personalization and measurement. Disabling marketing cookies may result in less relevant ads on other platforms, but does not reduce the total volume of ads served by third parties.
6. Opt-out of behavioral advertising
6.1. To limit cross-context behavioral advertising on third-party platforms, you may use:
- Digital Advertising Alliance (USA): optout.aboutads.info;
- Network Advertising Initiative: optout.networkadvertising.org;
- European Interactive Digital Advertising Alliance: youronlinechoices.eu;
- Google Ads Settings: adssettings.google.com;
- Meta Ads Preferences: accountscenter.facebook.com/ads.
7. International transfers
7.1. Third-party providers listed in this Policy may process data in jurisdictions outside of Brazil and the EU/UK, particularly in the United States. The applicable safeguards are described in Section 7 of the Privacy Policy.
8. Updates to this Policy
8.1. This Policy may be updated to reflect changes in the technologies we use, integrations with third parties, or applicable rules. The date of the last update appears at the top of this page.
9. Contact
Data Protection Officer (DPO)
Visto n' Visa, LLC — 169 Madison Avenue, STE 75834, New York, NY 10016, USA
Email: [email protected]