COOKIES

Cookie Policy

A short, transparent explanation of how we use cookies on this website. Spoiler: we don't use them for tracking.

Last updated: [DATE TO BE FILLED]

What Cookies We Use (and Don't)

✓ Strictly Necessary Cookies

Used only on administrative paths (/cp/) for the content management system. These cookies:

  • Enable user login for content editors
  • Maintain session security
  • Prevent cross-site request forgery (CSRF)

These are exempt from consent requirements under TTDSG §25(2) because they are technically necessary for the requested service.

CookiePurposeDurationPath
trackosteps_marketing_sessionCMS login sessionSession/cp/
XSRF-TOKENCSRF protectionSession/cp/

Regular site visitors browsing our public pages will not encounter these cookies.

✗ Cookies We Do NOT Use

We do not use cookies for:

  • Analytics — We use Plausible, which is cookieless and stores no data on your device
  • Advertising — No ads, no remarketing pixels, no third-party trackers
  • Social Media — No Facebook Pixel, no LinkedIn Insight Tag, no Twitter analytics
  • Cross-site Tracking — None whatsoever
  • Personalization — None

How We Track Site Performance Without Cookies

We use Plausible Analytics to understand aggregate site usage. Plausible:

  • Does not use cookies or any browser storage
  • Does not collect personal data
  • Does not generate persistent identifiers
  • Stores all data on EU servers (Falkenstein, Germany)
  • Provides only aggregated, anonymous statistics
  • Has independent legal assessment confirming GDPR/TTDSG compliance

Read more in Plausible's data policy.

Your Choice and Control

Because we don't use tracking cookies, there's nothing to opt out of on your side. However, if you'd still like additional control:

  • Browser settings: Most browsers let you block all cookies, accept only first-party cookies, or delete cookies
  • Privacy tools: Browser extensions like uBlock Origin can block third-party scripts (though there's nothing tracking you on our site)
  • DNT signal: We respect Do-Not-Track signals (though they don't affect anything since we don't track)

Third-Party Services on Specific Pages

Some pages may embed third-party content that could set cookies. As of the last update of this policy, we use:

  • Bunny Fonts — Self-hosted alternative to Google Fonts (no cookies, no tracking)
  • Plausible Analytics — Cookieless analytics

We do not use:

  • Google Fonts (uses Google's CDN — privacy issues per Munich court ruling)
  • Google Analytics
  • Google Tag Manager
  • YouTube embeds
  • Social media widgets

If we add new services in the future, this policy will be updated and you'll be informed where consent is required.

SaaS Application (app.trackosteps.com)

The SaaS application has its own cookie usage for authentication and session management. See its dedicated cookie policy for details.

Changes to This Policy

We may update this policy if our cookie practices change. The "Last Updated" date at the top reflects the most recent revision.