Last updated: [DATE] Who this is from: [LEGAL ENTITY NAME] — [PRIVACY CONTACT EMAIL]
The short version
This site sets two cookies. Both are strictly necessary to make it work. There is no advertising, no analytics, no tracking, and nothing is shared with anybody else.
That is also why there is no cookie banner. Under the UK's PECR and the EU ePrivacy Directive, cookies that are strictly necessary to deliver a service the visitor asked for do not require consent — and asking for consent we do not need, for cookies you cannot refuse without breaking the site, would be a box to click rather than a choice.
If we ever add analytics, that changes, and a banner appears with it.
1. What we actually set
| Cookie | What it does | How long |
|---|---|---|
ticketmodules-session |
Keeps you signed in and remembers your session between pages. Without it you would be logged out on every click. | 2 hours of inactivity |
XSRF-TOKEN |
Proves a form submission came from this site. It is what stops another site making your browser perform actions in your account. | 2 hours |
Both are first-party — set by this site, readable only by this site. The
session cookie is HttpOnly, so scripts cannot read it, and both are
SameSite=Lax, which is what makes the cross-site attack above impossible.
One more, only if you ask for it: ticking Remember me when you sign in
sets a remember_web_* cookie so you are not asked again on that device. You
chose it, you can clear it by signing out, and it is not set otherwise.
2. What we do not set
No advertising cookies. No analytics — no Google Analytics, no Facebook Pixel, no Hotjar, nothing of that kind. No third-party embeds that set cookies of their own. We do not track you across other websites, because we have no way to and no interest in doing so.
This is checked automatically, not just asserted. An automated test fails the build if a tracking cookie or an analytics script is ever added to the marketing site — so if this section stops being true, somebody has to deliberately change the test, and update this page while they are at it.
3. Cookies inside a support desk
If you reached a support portal run by somebody using TicketModules — you opened a ticket about a product you bought — the same two cookies apply, set by that portal's address rather than ours.
The company running that desk decides what else, if anything, happens there. See our Privacy Policy for the split between what we decide and what they do.
4. Payments
Paying goes through Stripe, and Stripe sets its own cookies on its own checkout pages for fraud prevention. Those are Stripe's, governed by Stripe's policy, and they are set when you are on Stripe's page rather than ours.
5. Turning them off
You can block or delete cookies in your browser settings. Do that here and you will not be able to sign in — the session cookie is what being signed in consists of. That is the sense in which these are strictly necessary rather than a claim we are making about our own convenience.
6. Changes
If we add any cookie that is not strictly necessary, we will update this page and ask for your consent before setting it. Adding tracking quietly and mentioning it in a policy nobody re-reads is exactly the practice this section exists to rule out.
[LEGAL ENTITY NAME], [REGISTERED ADDRESS] — [PRIVACY CONTACT EMAIL]