Cookie declaration
Effective [not yet set]
These are all the cookies Corresso sets. Corresso sets each of them itself, and each is strictly necessary: without them you could not sign in, or submit a form safely. Cookies that are strictly necessary for a service you have asked for need no consent under Danish law (Cookiebekendtgørelsen, BEK nr. 1148 af 9. december 2011, § 4, stk. 1, nr. 2), so there is no cookie banner. We publish this declaration anyway, so you can see exactly what your browser keeps.
| Name | Set by | Purpose | Duration | Category |
|---|---|---|---|---|
| session_id | Corresso (first party) | Keeps you signed in. It holds only a signed number that points to your sign-in on our server, which ends when the cookie does. | 30 days from when you sign in, or until you sign out | Strictly necessary |
| _corresso_session | Corresso (first party) | Protects forms against cross-site request forgery, carries one-off messages such as “Password has been reset”, remembers the page to return to after signing in, and holds a random value our content security policy uses to tell our own scripts from injected ones. It is encrypted, so it cannot be read or changed in the browser. | Until you close your browser | Strictly necessary |
How they are protected
Each is sent only over HTTPS, cannot be read by scripts on a page (HttpOnly), and is not sent with requests that other websites make in the background (SameSite=Lax).
What we do not use
- No analytics, advertising, social-media or tracking cookies.
- No local storage, session storage or similar storage in your browser.
- No fonts or scripts from other companies’ servers.
- No images from other companies’ servers, with one exception: in an organisation that has connected its Shopify store, the pictures of the products a customer ordered load straight from Shopify’s servers (cdn.shopify.com). Our privacy notice explains what Shopify receives.
- No tracking in the email we send: open and link tracking is always off.
Removing them
Signing out deletes session_id, and closing your browser deletes _corresso_session.
You can delete both at any time in your browser’s settings; you will then simply be signed out.
The personal data involved
session_id holds only a signed number pointing to your sign-in on our server, which records
the IP address and browser you signed in from. Our privacy notice
explains how we handle that.