Theori Cookie Policy
Effective Date: August 4, 2026
Theori ("Company") uses cookies and similar tracking technologies to provide services and improve user experience. This Cookie Policy explains how cookies are used on the Company's websites and services, and how you can manage them.
This Cookie Policy forms part of the Theori Privacy Policy. Terms not defined in this policy follow the definitions in the Privacy Policy.
1. What Are Cookies
A cookie is a small text file that a website sends to your browser and stores on your device. Cookies help websites remember your preferences, maintain authentication sessions, and analyze usage patterns.
In addition to cookies, similar technologies perform comparable functions:
| Technology | Description |
|---|---|
| Web Beacon | A transparent image embedded in a web page or email, used to confirm whether a page was visited or an email was opened |
| Pixel | Similar to web beacons, a code snippet used for advertising conversion tracking and remarketing |
| Local Storage | A browser-based data storage method that can store larger amounts of data than cookies with no expiration date |
In this policy, "cookies" includes these similar technologies.
2. Cookie Classification
2.1. By Whom They Are Set
| Type | Description |
|---|---|
| First-Party Cookies | Set directly by the website you are visiting (e.g., theori.io) |
| Third-Party Cookies | Cookies set by a domain other than the website being visited (e.g., google.com, meta.com) |
2.2. By Duration
| Type | Description |
|---|---|
| Session Cookies | Automatically deleted when you close your browser |
| Persistent Cookies | Remain on your device until their expiration date or until you manually delete them |
3. Cookie Categories We Use
We classify the cookies we use into the following four categories.
3.1. Strictly Necessary Cookies
These cookies are essential for core service functionality. Without them, features such as login, session management, and security would not function properly.
- Login session management and authentication
- CSRF (Cross-Site Request Forgery) protection
- Bot prevention and traffic protection (reCAPTCHA, Cloudflare)
- Cookie consent state storage
- Security verification
- Session identification on our blog and careers platforms
- Payment processing (Dreamhack paid services)
Strictly necessary cookies are installed without separate consent as they are essential for service delivery (EU ePrivacy Directive Art. 5(3) exemption). Among these, reCAPTCHA is used solely for security purposes such as preventing automated attacks, spam, and fraudulent use, and is not used for advertising or analytics.
3.2. Functional Cookies
These cookies remember your preferences to provide an enhanced experience.
- Language preference retention
- Theme/dark mode preference storage
- Layout and UI settings persistence
3.3. Analytics Cookies
These cookies analyze service usage patterns to improve our services. The collected data is, as a rule, used in aggregated form for statistical purposes.
| Provider | Purpose | Applicable Services |
|---|---|---|
| Google Analytics | Web usage statistical analysis | Theori website, blog and careers site, Xint, aprism, Dreamhack |
| PostHog | Product analytics and UX improvement | Xint Web, Dreamhack |
| HubSpot | CRM, lead attribution and web analytics | Xint Landing |
| Microsoft Clarity | Usage pattern analysis, heatmaps and session replay | Dreamhack |
| Sentry | Error tracking and session replay | Dreamhack, Xint Web, aprism |
| RudderStack | Event collection and data integration | Theori careers site |
| Datadog | Real-user (RUM) performance and error monitoring | Dreamhack, aprism, Theori careers site |
| Inblog | Blog usage statistics and referral analysis | Theori blog |
3.4. Marketing Cookies
These cookies enable targeted advertising, conversion tracking, and advertising effectiveness measurement.
| Provider | Purpose | Applicable Services |
|---|---|---|
| Google Ads and Google AdSense | Targeted advertising, conversion tracking and ad delivery | Theori website and blog, Xint Landing, Dreamhack |
| LinkedIn Insight | Advertising and lead tracking | Xint Landing |
| YouTube (embedded video) | Video playback and viewing-based recommendations or advertising | Theori blog |
The tables above list our principal providers. The complete list of cookies used by each service, along with individual cookie names and expiration periods, is available in the "Show details" section of our consent management platform (CMP). We may use additional analytics, error-tracking, and security tools as needed to operate our services, and any changes will be reflected in this policy and in the CMP list.
4. Third-Party Cookies and Tracking Technologies
Our websites may include cookies set by third-party service providers. These third-party cookies are governed by the respective provider's privacy policy.
| Third-Party Service | Privacy Policy |
|---|---|
| Google Privacy Policy | |
| PostHog | PostHog Privacy Policy |
| HubSpot | HubSpot Privacy Policy |
| LinkedIn Privacy Policy | |
| Cookiebot (Usercentrics) | Cookiebot Privacy Policy |
| Microsoft (Clarity) | Microsoft Privacy Statement |
| Sentry (Functional Software) | Sentry Privacy Policy |
| RudderStack | RudderStack Privacy Policy |
| Datadog | Datadog Privacy Policy |
| Cloudflare | Cloudflare Privacy Policy |
| Inblog | Inblog Privacy Policy |
5. Consent Management
5.1. Consent Management Platform (CMP)
We use Cookiebot (Usercentrics A/S) as our cookie consent management platform (CMP), deployed across all of our websites that use advertising or analytics cookies. You can also manage cookies through your browser settings (Section 6.1).
- A cookie consent banner is automatically displayed upon your first visit
- You can accept or reject non-essential cookies by category (Analytics, Marketing, Functional)
- Deleting cookies in your browser causes the consent banner to reappear on your next visit, allowing you to change your choices
Individual cookie names, expiration periods, and detailed descriptions are available in the "Show details" section of the Cookiebot consent banner.
5.2. Consent Principles
- Opt-in: We install cookies other than strictly necessary cookies only after obtaining your prior consent
- Opt-out: You can withdraw your cookie consent at any time; after withdrawal, the relevant cookies will no longer be installed
- Consent records: Cookiebot records your consent choices to support regulatory compliance
6. How to Manage Cookies
6.1. Browser Settings
You can refuse or delete cookies through your web browser settings.
| Browser | Cookie Settings Path |
|---|---|
| Chrome | Settings → Privacy and Security → Third-party Cookies |
| Safari | Preferences → Privacy → Manage Website Data |
| Firefox | Settings → Privacy & Security → Cookies and Site Data |
| Edge | Settings → Cookies and Site Permissions → Manage and Delete Cookies and Site Data |
Note: Disabling cookies may prevent some service features, such as login, from functioning properly.
6.2. Advertising Opt-Out
| Tool | Opt-Out Method |
|---|---|
| Google Analytics | Google Analytics Opt-out Browser Add-on |
| Google Ads | Google Ad Settings |
| LinkedIn Ad Settings | |
| Microsoft | Microsoft Ad and Privacy Settings |
| General Opt-Out | Digital Advertising Alliance (DAA) |
6.3. Mobile Advertising Identifier
- Android: Settings → Google → Ads → Delete Advertising ID
- iOS: Settings → Privacy & Security → Tracking → Toggle off "Allow Apps to Request to Track"
7. Changes to This Policy
We may update this Cookie Policy from time to time due to changes in applicable laws, services, or the cookies and tracking technologies we use. When changes are made, we will post the updated policy on this page and revise the effective date.
8. Contact Us
If you have any questions about our use of cookies, please contact us:
| Item | Details |
|---|---|
| Chief Privacy Officer | Kenny Kwansoon Park (박관순) · Chief Information Security Officer (CISO / CPO / DPO) |
| privacy@theori.io | |
| Phone | +82-70-8864-1337 |
| Address | 9F, 14 Teheran-ro 4-gil, Gangnam-gu, Seoul 06232, Republic of Korea |
Language
This policy is published in Korean and English. The Korean version is the authoritative text for disclosures required by the Korean Personal Information Protection Act and for data subjects in the Republic of Korea; the English version is the authoritative text for data subjects in the EEA, the United Kingdom and other jurisdictions. We maintain both versions in substantive alignment. If you identify any discrepancy, please contact privacy@theori.io and we will correct it without delay. Neither version limits any right guaranteed to you by applicable law, and where the versions differ, the version more favorable to the data subject applies.
This Cookie Policy takes effect on the date shown at the top of this document.
All previous privacy policies and addendums can be found on our consolidated Previous Versions page: