Three cookies. All strictly necessary. Zero tracking.
Last updated: April 27, 2026
Effective: April 27, 2026
At a glance
- We set exactly 3 cookies. All are strictly necessary.
- Zero tracking cookies. Zero advertising cookies. Zero third-party cookies.
- Under EU ePrivacy Directive Article 5(3), strictly necessary cookies do not require your consent.
- Full details below.
Cookies are small text files stored on your device by your web browser when you visit a website. They allow the site to remember things like your login state between page loads.
PrivacyFetch does not use local storage or session storage for tracking purposes.
We set exactly three cookies. All are first-party (set by privacyfetch.com) and strictly necessary for the Service to function.
| Name | Purpose | Duration | HttpOnly | Secure | SameSite |
|---|---|---|---|---|---|
privacyfetch-session | Maintains your authenticated session and carries the encrypted session payload. Without this cookie, you cannot remain logged in between page loads. | 2 hours (120 minutes) | Yes | Yes (HTTPS only) | Lax |
XSRF-TOKEN | Protects against cross-site request forgery (CSRF) attacks. This cookie is readable by JavaScript so it can be included in request headers — that is why HttpOnly is set to No. | 2 hours (120 minutes) | No | Yes (HTTPS only) | Lax |
cookie_consent | Remembers whether you have acknowledged this cookie notice, so we do not show it again. | 1 year | No | Yes (HTTPS only) | Lax |
Technical notes:
X-XSRF-TOKEN request header.We want to be explicit:
We have Google Tag Manager (GTM) configured on the site. However:
Currently, GTM is effectively inactive for all users because consent is never granted by default.
Some third-party services we use may process limited data through your browser:
We load web fonts from Bunny Fonts, a privacy-focused font CDN based in the EU. Bunny Fonts processes your IP address ephemerally to serve font files. It does not set cookies and does not store personal data.
When you interact with a payment form (e.g. during checkout or updating your payment method), Stripe's JavaScript SDK may set cookies for fraud prevention. These cookies are controlled by Stripe and are subject to Stripe's Cookie Policy. They are only active while the payment form is loaded.
You can block or delete cookies through your browser settings. Here are links to cookie management for common browsers:
Please note: If you block the privacyfetch-session cookie, you will not be able to log in. If you block the XSRF-TOKEN cookie, form submissions will fail. Other site features (browsing the directory, reading public company profiles) will continue to work without cookies.
We respect the Do Not Track browser signal. Since we do not track users across websites and do not engage in cross-site tracking, the DNT signal has no practical effect on our service — but we honor it as a matter of principle.
Under Article 5(3) of the ePrivacy Directive (2002/58/EC, as amended by 2009/136/EC), cookies that are strictly necessary for providing a service explicitly requested by the user are exempt from the consent requirement.
All three cookies we set qualify as strictly necessary:
If we ever add cookies that are not strictly necessary (e.g. analytics, marketing), we will:
If you have questions about our use of cookies, contact us:
See also: Privacy Policy · Terms of Service
Related legal documents