Cookie Policy
Last updated: September 6, 2026
This Cookie Policy explains what cookies and similar browser storage mechanisms Pinkk ("Pinkk", "we", "us") uses, what each one does, and how you can control them. It supplements our Privacy Policy, which covers our broader data practices.
Contents
2. Strictly necessary cookies
These cookies are required for the platform to function. They do not require your consent and cannot be disabled without breaking core features. We do not use them to track you across other websites.
| Name | Purpose | Expires | Type |
|---|---|---|---|
| pinkk-session | Maintains your authenticated session while you use the platform. Without this cookie you cannot stay logged in. | ~120 minutes of inactivity | HTTP, session, HttpOnly, SameSite=Lax |
| remember_web_* | Set only if you choose "Remember me" at login. Keeps you signed in across browser restarts so you don't have to log in every time. | 90 days | HTTP, persistent, HttpOnly, SameSite=Lax |
| XSRF-TOKEN | Cross-site request forgery protection. Ensures form submissions and state-changing requests originate from Pinkk, not an external site. | Session | HTTP, session, SameSite=Lax |
3. Local storage
Local storage is a browser feature that lets websites save data on your device. Unlike cookies, data in local storage is never automatically sent to our servers — it is only read by JavaScript running on the page. It has no expiry date and persists until cleared.
| Key | Purpose | Category |
|---|---|---|
| cookie_consent | Stores your choice from the consent banner ("accepted" or "declined") so we know whether to load analytics tools on future visits. No tracking data is stored here. | Functional (consent management) |
4. Analytics and monitoring (consent-based)
The following tools are only loaded after you accept via the consent banner. If you decline, none of these tools load, no cookies are set by them, and no data is sent to any of these services. You can change your choice at any time — see section 7.
Page analytics
Tracks page views and general usage patterns to help us understand how the platform is being used. Configured with IP anonymisation enabled. Sets first-party cookies to distinguish unique visitors and sessions.
| Cookie | Purpose | Expires |
|---|---|---|
| _ga | Distinguishes unique visitors. Used to calculate session and user counts. | 2 years |
| _ga_* | Stores and counts page views for the current property. | 2 years |
Session replay and heatmaps
Records anonymised interaction sessions (mouse movements, clicks, scroll depth) to help us understand usability and identify friction points. Configured to mask sensitive input fields and displayed content. No keystrokes or form values are recorded.
| Cookie | Purpose | Expires |
|---|---|---|
| _clck | Persists a unique user ID and session data for Microsoft Clarity. | 1 year |
| _clsk | Connects multiple page views by a user into a single Clarity session recording. | 1 day |
| CLID | Identifies the first-time Clarity saw this user on any site using Clarity. | 1 year |
| MR, SM, MUID | Microsoft-level identifiers used for cross-site deduplication. Set by Microsoft's shared infrastructure. | Up to 1 year |
Error and performance monitoring
Captures application errors, performance traces, and (optionally) session replays to help us diagnose and fix issues. Session replay is configured to mask all text and media content. No personally identifiable information is included in error payloads by default.
Sentry does not set persistent first-party cookies. It may use session-scoped storage for replay identification. See Sentry's Privacy Policy for full details.
5. Bot protection
Our contact form uses Cloudflare Turnstile to distinguish humans from bots without requiring you to solve a visual puzzle. Turnstile may set cookies or use browser signals (such as screen properties and interaction patterns) to make this determination.
Turnstile is a strictly necessary protection against abuse — it does not require consent. No personal account data is shared with Cloudflare through this mechanism. See Cloudflare's Privacy Policy for details on how Turnstile handles data.
6. Third-party cookies
Pinkk does not use advertising cookies, tracking pixels, or affiliate tracking cookies. We do not place cookies that track you across other websites for marketing or retargeting purposes.
If you accept analytics, some third-party analytics cookies (detailed in section 4) may be set by Google and Microsoft on their own domains. These are governed by those companies' privacy policies, linked in section 4.
If you embed or share a Pinkk report on a third-party site, any cookies set by that site are outside our control and governed by that site's own cookie policy.
7. Managing your preferences
Your current preference
You can update your analytics consent at any time below. Changes take effect immediately — no need to clear your browser data.
Analytics tools were already loaded this session. They will not run again after you reload the page.
How it works
Your preference is stored in your browser's localStorage under the key cookie_consent. Analytics tools are never loaded if your preference is "declined" or if no choice has been made. Strictly necessary cookies (session and CSRF) are unaffected by this preference.
8. Changes to this policy
We may update this Cookie Policy when we add new tools, remove existing ones, or when laws or guidance change. When we make meaningful changes, we will update the "Last updated" date at the top of this page. If we add new consent-based cookies, the consent banner will resurface to give you the opportunity to review and accept or decline.
9. Contact us
If you have questions about this Cookie Policy or want to exercise any rights related to data we hold about you, please use our contact form.
Questions about our cookies?
If you want to know more about what we store and why, get in touch.