Legal
Cookie Policy
Effective 2026-05-28
We use the absolute minimum — exactly one cookie, and only on the admin dashboard.
What cookies are
A cookie is a small piece of text a site stores in your browser to remember something between page loads.
The cookie we use
admin_session — strictly necessary, set only when our team logs into the private admin dashboard at /admin. It’s an HMAC-signed session token, HTTP-only, Secure (in production), SameSite=Lax. It contains no personal information. It expires after 7 days.
That’s it. The public site (homepage, diagnostic, legal pages) sets no cookies.
What we don’t use
- No analytics cookies (Google Analytics, Plausible, Mixpanel, etc.).
- No advertising or marketing cookies.
- No third-party tracking pixels.
- No social media embeds that drop cookies.
- No fingerprinting.
First-party, cookieless analytics
We count aggregate page views and funnel steps using sessionStorage (not a cookie) for a per-session UUID that resets every time you close the tab. The UUID is anonymous, never tied to your identity, and never shared with anyone. No fingerprinting, no third-party trackers, no cross-site tracking.
Under CNILguidance, first-party analytics of this shape are exempt from cookie-consent requirements — but we’re telling you anyway, because it’s the right thing to do.
Questions
Reach us through our booking page.