Cookie Policy
2026-08-16
Essential storage
Your cookie choice is stored locally in your browser (localStorage, key “qold-consent”), together with the time of the decision. This is required for the site to remember your decision and needs no consent. Both are removed when your choice expires — after 24 months at the latest, when we ask again.
Record of consents given
If you accept a category, we record that on our server — as far as the report reaches us: which categories, on which day, in which language, against which version of this policy, and whether you decided in the banner or in the settings. Nothing else — no IP address, no user agent, no identifier, and the date without a time.
We store nothing that would let us look you up. To be precise rather than reassuring: our hosting provider keeps access logs (IP, timestamp, URL) as described above, so during the retention period of those logs a connection would not be entirely impossible — that is why the record carries no time of day.
If you decline, nothing is sent to our server and nothing is stored there. The law requires us to demonstrate consent, not refusal. The same applies if you later withdraw: your withdrawal takes effect in your browser immediately, but it is not recorded on our server — so this record shows consents given, not the consents still in force.
Legal basis: our obligation to demonstrate consent (Art. 7(1), Art. 5(2), Art. 6(1)(c) GDPR). Stored by Supabase (eu-central-1) on our behalf, kept for 36 months, then deleted automatically.
Protecting the consent record (no consent required)
Every page carries a short-lived token in its head, signed by our server. Your browser returns it once when you accept in the banner — it proves the report came from a page we actually served and keeps foreign entries out of the record. It is not stored on your device, contains nothing about you, is never stored or analysed on our side, and does not track you. Strictly necessary for the accuracy of the record (Art. 22.2 LSSI-CE, § 25(2)(2) TDDDG).
Spam protection (no consent required)
When you open a page with a form, Cloudflare Turnstile is loaded from challenges.cloudflare.com to tell a person from a bot. It may store a short-lived token on your device for that check alone. This is strictly necessary to protect the form against abuse (Art. 22.2 LSSI-CE), it does not track you across sites, and it is not used for analytics or advertising. Provider: Cloudflare, Inc.
Analytics & marketing
Google Analytics 4 sets cookies (e.g. _ga, _ga_*) only after you accept “Analytics” in the cookie banner. Marketing signals (ad measurement) only after accepting “Marketing”. Both are off by default.
Managing cookies
Change or withdraw your choice anytime via “Cookie settings” in the footer, or delete cookies in your browser settings.