Cookie Policy

Last updated 2026-09-29

This page lists everything Pelipact stores in your browser, what each item is for and how long it stays. Cookies are small files a site keeps in your browser. Local storage and the app's offline cache work much the same way, so this policy covers them too. There are two kinds: what Pelipact needs to work, and analytics, which is optional and off until you say yes.

1.Nothing analytical runs before you choose

On your first visit you may see a cookie banner from Cloudflare Zaraz, our consent manager. Until you choose, the only things stored are the strictly necessary items in the table below.

If you say no, or close the banner, no Google Analytics code loads, no analytics identifier is created and nothing is sent to Google. There is nothing to opt out of later, because nothing was set. If you never see the banner, analytics is not running at all. Pelipact works the same either way.

Strictly necessary storage needs no consent under Article 11.7a of the Dutch Telecommunications Act, because without it you cannot sign in or use the app. Everything else needs your consent, and we ask for it.

2.What we store, item by item

NameSet byCategoryPurposeHow long
__Secure-pelipact.session_tokenPelipactStrictly necessaryKeeps you signed in, with an account or on a guest seat. Set when you sign in, sign up or take a seat. It is HttpOnly, Secure and SameSite=Lax: scripts cannot read it, and it only travels over HTTPS.60 days, renewed while you use Pelipact. Deleted when you sign out.
__Secure-pelipact.two_factorPelipactStrictly necessaryHolds a sign-in that is waiting for your two-factor code. Only if you use two-factor authentication.10 minutes.
__Secure-pelipact.better-auth-passkeyPelipactStrictly necessaryTies a passkey sign-in or setup to the check your device answers. Only while you use a passkey.5 minutes.
__cf_bm, cf_clearanceCloudflareStrictly necessaryOnly if Cloudflare's bot protection checks your browser. They record that it passed, so you are not checked again straight away.__cf_bm: 30 minutes. cf_clearance: as long as the check stays valid, 30 minutes by default.
cf_consentCloudflare ZarazStrictly necessaryRemembers your cookie choice, so we do not ask on every page. It stores your choice, not who you are.12 months, or until you clear it.
pelipact.* and email_verify_cooldown_end (local storage)PelipactStrictly necessarySmall choices kept on this device: which sections you left open, whether you closed the install or notification hint, and a one-minute pause before we send a verification email again. Never sent to us.Until you clear your browser's storage.
better-auth.message (local storage)PelipactStrictly necessaryTells your other open Pelipact tabs that you signed in or out, so none of them keeps showing the wrong account. It holds a signal and a time, nothing about you.Until you clear your browser's storage.
pelipact-shell-v1, pelipact-assets (offline cache)PelipactStrictly necessaryKeeps the app's files and an offline page on this device, so Pelipact opens quickly and works without a connection. It also remembers the language you last used, so a notification opens in it. No personal data.Until a new version replaces it, or you clear this site's data.
Push subscriptionYour browserOnly with your permissionLets us send notifications to this device. Your browser asks you first, then keeps the subscription, and we keep its address so we can reach you.Until you turn notifications off here or block them in your browser.
cfz_google-analytics_v4, cfzs_google-analytics_v4Google Analytics, through Cloudflare ZarazAnalytics, needs your consentA random identifier for your browser and counters for your visit, so repeat visits count as one visitor. Only set after you say yes.cfz_: until you clear it. cfzs_: until you close the browser.

Providers rename their cookies from time to time, and we keep this table up to date. The Turnstile check on our sign-up and sign-in forms sets no cookie of its own. If you find something from Pelipact that is not listed here, tell us at info@pelipact.com and we will explain it or remove it.

3.The two kinds, explained

Strictly necessary. These make Pelipact work: they keep you signed in, protect the sign-in forms, remember your cookie choice, and keep small preferences and the offline app on your device. You cannot turn them off and still use an account, so we do not ask for consent for them, and we use them for nothing else.

Analytics. These show us how the site is used: which pages people reach, where they stop, and whether a change helped. They are optional, off until you say yes, and saying no costs you nothing.

There is no third kind. Pelipact has no ads, loads no advertising or social media tags, and shares nothing it learns from analytics with anyone for their own use.

4.What Google Analytics gets, if you say yes

  • A random identifier for your browser. It is not your name and not your account.
  • The pages you open, and in what order.
  • Your rough location, worked out from your IP address, at about city level.
  • Basic device and browser details, such as screen size, browser version and language.
  • The site or link that brought you here.

Google Analytics 4 does not store IP addresses, and we do not turn on Google signals or advertising features, so this data is never used for ad profiles. Google LLC may process it in the United States. Google LLC is certified under the EU-US Data Privacy Framework, and standard contractual clauses apply as well. Google keeps the data for 14 months. Our Privacy Policy explains more.

We never send your name, your email address or what you trade at your tables to Google Analytics.

5.Changing or withdrawing your choice

You can change your mind whenever you like, and it takes effect at once. Saying no later is as easy as saying yes.

  • Use “Cookie settings” in the site footer, or the button below. It opens the same panel you saw on your first visit, with your current choice.
  • Turn analytics off and save. The analytics code stops loading straight away.
  • To remove what analytics already stored on your device, clear this site's data in your browser. The next section explains how.

Your choice is kept in the cf_consent cookie, in this browser on this device. If you clear your cookies, use a private window or switch devices, we ask again.

6.Doing it in your browser instead

Every major browser lets you see, block and delete the cookies and stored data of one site, usually under the padlock in the address bar or in the privacy settings. If your browser sends a Global Privacy Control signal, we treat it as a no to analytics and do not ask.

Blocking everything is your right, but know what happens: without the strictly necessary items you cannot sign in or stay signed in. A guest seat lives in its cookie, so clearing your cookies before you save your seat loses it for good. Blocking only analytics changes nothing in the app.

7.Changes and contact

If we add or remove something that stores data in your browser, we update this table first. If something new needs your consent, we ask again rather than assume. Every version shows the date it took effect.

Questions about this page go to info@pelipact.com. Our Privacy Policy explains what we do with personal data, and our Terms of Service set the rules for using Pelipact.