Legal

Cookie policy

What this site stores in your browser, what it is for, and how to control it — including what we do not set.

Effective 15 January 2025 · Last revised 20 August 2026

What cookies are

Cookies are small text files stored on your device when you visit a website. They carry information our servers can read back on a later request — which is what keeps you signed in between pages, and what remembers a preference between visits.

Alongside cookies, a browser offers local storage and session storage — data kept in the browser itself, with session storage cleared when the tab closes. Where this site remembers something client-side, it uses these same mechanisms.

We do not use web beacons, tracking pixels or mobile advertising SDKs. There is no mobile app and no advertising.

What we set

There is no consent banner on this site, because there is nothing optional to consent to. No analytics, advertising or marketing cookies are set. If a non-essential cookie is ever introduced, consent will be asked for before it is written, and this page will describe it first.

CategoryWhat it doesLongest lifeCurrently set
EssentialSigning in and staying signed in; protecting requests against cross-site forgerySession, or 30 days for sign-inYes — cannot be disabled
FunctionalRemembering preferences and interface state1 yearNone
AnalyticsMeasuring how the site is used2 yearsNone
MarketingAdvertising and ad measurement90 daysNone — there is no advertising on this platform

Essential cookies

These are the cookies the service cannot work without: authentication cookies that keep you signed in to your account, for the session or up to 30 days, and security cookies that protect against forged requests, for the session only. Sign-in itself is delegated to an identity provider, as the privacy policy describes.

Everything else

The functional, analytics and marketing categories exist in this policy so their limits are on record before anything in them ships — the durations above are ceilings, not descriptions of cookies that exist. Usage measurement on this platform is server-side, per API key and per endpoint, and is covered by the privacy policy rather than by a cookie.

Third-party cookies

No third-party cookies are set. There is no third-party analytics script, no advertising network, no embedded support widget and no payment processor on this site — the terms of service state the last of those plainly.

An earlier version of this page listed Google Analytics, Hotjar, Stripe and Intercom cookies. None of those services was ever integrated — the list was carried over from the site template — and it has been removed rather than left to describe data sharing that does not happen. If a third-party service is ever added, it will be listed here, with its purpose and a link to its privacy policy, before it ships.

Managing cookies

Your browser can list, block and delete cookies for any site, including this one:

BrowserWhere to look
ChromeSettings → Privacy and security → Cookies and other site data
FirefoxSettings → Privacy & Security → Cookies and Site Data
SafariPreferences → Privacy → Manage Website Data
EdgeSettings → Cookies and site permissions → Cookies and site data

Blocking the essential cookies signs you out and breaks sign-in — they are the mechanism, not a preference. Because nothing non-essential is set, there is nothing else to turn off.

Retention

  • Session cookies — deleted when the browser closes. No persistent storage.
  • Security cookies — expire within 24 hours at most, and are deleted automatically.
  • Sign-in cookies — up to 30 days, and you can delete them manually at any time.
  • Anything longer-lived — nothing this site sets today outlives sign-in. The two-year ceiling in the table above exists only as the outer limit this policy would ever permit.

We follow data minimisation principles:

  • Collect only necessary cookie data.
  • Use the shortest retention period possible.
  • Review regularly and delete what is outdated.
  • Respect user preferences and consent.

Legal compliance

GDPR

Our cookie practices follow GDPR requirements:

  • Consent — clear consent before any non-essential cookie.
  • Information — transparent information about cookie use.
  • Control — easy management and withdrawal of consent.
  • Purpose limitation — cookies used only for stated purposes.

The wider data-protection position — lawful bases, your rights, and how to exercise them — is on the GDPR compliance page and in the privacy policy.

ePrivacy

  • Prior consent for non-essential cookies.
  • Clear and comprehensive information.
  • Respect for user choices.
  • Regular compliance review.

Elsewhere

We comply with privacy laws in the jurisdictions where we operate, including the CCPA (California), PIPEDA (Canada) and the Privacy Act (Australia), and with local requirements where they apply.

Changes

We will tell you when this policy changes, through:

  • Email notification to account holders for significant changes.
  • A website announcement.
  • The revised date at the top of this page.

The policy is reviewed at least annually, and whenever a new regulation, technology or service change touches it.

Contact

Questions about cookies, or any request about the data behind them, go to privacy@arapulse.com — expect a response within 5 business days — or through the contact page. Your rights over personal data, and how to exercise them, are set out in the privacy policy.

Questions about cookies?

The short answer is that this site sets almost none. For the long answer, ask.