Cookie policy
Four cookies, all of them first-party and all of them necessary. Visits are counted without cookies. No advertising, no trackers.
Last updated 2026-09-14
Short version: Pinger sets no advertising cookies, no analytics cookies and no third-party trackers. Every cookie below exists to make the site work or to remember a preference you set yourself.
That is also why you are not asked to accept anything. A consent banner is required for cookies that are not strictly necessary, and we do not use any.
What is set, and when
| Cookie | Set when | What it does | How long |
|---|---|---|---|
pinger_session |
Your first visit to any page, including the public ones | Recognises a form you submit as coming from the page you loaded it on, and keeps you signed in once you sign in. | 2 hours after your last visit |
pinger_xsrf_token |
With the session cookie | Carries the token that proves a form submission came from a page we served, not from another site acting as you. | 2 hours after your last visit |
sidebar_state |
You collapse or expand the sidebar | Remembers which, so it is the same next time. | 1 year |
appearance |
You choose light, dark or system | Remembers which, and lets the server render the right one before the page paints — which is what stops a dark-mode visitor getting a white flash. | 1 year |
All four are first-party and SameSite=Lax. Over HTTPS the session and form-token cookies are
marked Secure, so a browser never sends them over an unencrypted connection.
The session cookie is HttpOnly, so no script can read it. The form-token cookie is not, on
purpose: our own script reads it and sends the token back with each form. On its own it grants
nothing.
Before you sign in, the session is not linked to any account. It holds the form token, the last page you opened and, for one page load, what you typed into a form that came back with an error, so you do not have to type it again — never a password. It is kept on our server and deleted two hours after your last visit.
Local storage
The application keeps nothing in local storage beyond what the interface needs to render, and nothing that identifies you.
Analytics
We count visits to the public pages ourselves, on our own server, without cookies, without a
script and without a third party. For each day we keep how many times each page was viewed and
where the visits came from — a campaign tag such as utm_source=newsletter, or the name of the
site that linked to us — and nothing about who you are.
To tell ten visits by one person from ten people, each visit is turned into a one-way code from a random value that exists for that day only and is then deleted. The code is never stored; it feeds a counter that can say how many different codes it has seen but cannot give any of them back. Your IP address is not part of what the count keeps. Signed-in visits and visits from automated tools are not counted.
When you follow a link from our pages to sign up, the campaign and referring site travel in the link itself, and are kept with the account you create, so we can tell which sources bring customers. You can see them in the address bar, and remove them.
Turning them off
You can block or delete cookies in your browser. Blocking the session and form-token cookies will stop you signing in — those two are what a sign-in is. Blocking the preference cookies costs you nothing except the preference.
Questions
Write to office@apostrof.ro.