Cookies Policy
Last updated: 8 May 2026.
Short version: this site uses two strictly-necessary Laravel session cookies plus Google Analytics 4 for aggregate traffic measurement. We do not run advertising pixels, session-replay tools, heatmaps, or chat widgets.
Cookies we set
| Name |
Purpose |
Lifetime |
Category |
XSRF-TOKEN |
Anti-CSRF token issued by Laravel. Prevents cross-site request forgery on internal forms (currently only the contact form, future: any form). |
2 hours |
Strictly necessary |
acellemail-session |
Opaque session identifier. Carries the CSRF token and any temporary state across requests. |
2 hours |
Strictly necessary |
_ga, _ga_* |
Google Analytics 4 — distinguishes unique visitors and sessions for aggregate traffic measurement (page views, country, referrer, device class). IP address is automatically truncated by GA4 before storage; we do not enable Google Signals or Ads remarketing. |
Up to 2 years (auto-renewed on each visit) |
Analytics |
The two Laravel cookies are scoped to acellemail.com, marked Secure + HttpOnly + SameSite=Lax, and contain no personal data — they're random bytes used only as opaque identifiers. Under GDPR Article 6(1)(b) / Recital 30, strictly-necessary cookies do not require consent.
The Google Analytics cookies are set by gtag.js loaded from googletagmanager.com. Data flows to our Google Analytics property under data-processing terms; we receive aggregate reports only and never see individual visitor identities. If you are in the EU/UK and prefer to opt out, see "How to refuse / delete cookies" below.
Cookies we do NOT set
We have made an explicit decision NOT to deploy any of the following on this site:
- Facebook Pixel, TikTok Pixel, LinkedIn Insight Tag, or any advertising pixel
- Google Ads remarketing or Google Signals (disabled in our GA4 property)
- Hotjar, FullStory, Microsoft Clarity, or any session-replay tool
- Intercom, Drift, Crisp, or any embedded chat widget
- A/B testing tools that set additional cookies (Optimizely, VWO, etc.)
Third-party cookies via embedded content
The home page embeds three product walkthrough videos hosted on YouTube's privacy-enhanced no-cookie domain (youtube-nocookie.com). These embeds do not set cookies until you click play. If you do click play, YouTube may set its own cookies in your browser — those are governed by Google's privacy policy, not ours.
Self-hosted fonts: as of 6 May 2026 we ship our fonts directly from acellemail.com and no longer load Google Fonts. Earlier visits may have triggered a request to fonts.googleapis.com / fonts.gstatic.com — Google does not set cookies on these domains, but the request did include your IP. That is no longer the case.
How to refuse / delete cookies
Laravel session cookies: scoped to a single browsing session and self-expire after 2 hours. To refuse them entirely, configure your browser to block first-party cookies for acellemail.com. The site will still render fine — only future form submissions would fail (currently there are no required forms).
Google Analytics cookies: install Google's official Browser Add-on to opt out of Google Analytics, or block googletagmanager.com in your browser's content-blocker / privacy settings. Most modern browsers (Brave, Firefox with Strict mode, Safari) already block these automatically.
To delete cookies immediately: open your browser's site-data settings and clear acellemail.com + google-analytics.com cookies.
Updates
Material changes to this policy will be reflected in the "Last updated" date at the top. The full revision history is publicly viewable in the project's git repository.
Contact
Cookies questions: support@acellemail.com. See also our privacy policy.