Cookies and local storage
Version 2026-09-15. Effective 2026-09-15.
Published by Stampomat, operated by Daniel Ilievski, Ljubljana, Slovenia. Questions about this notice: hello@stampomat.com.
This notice lists every cookie and every other item we store on your device across the Stampomat products, what each one is for, how long it lasts, and how to remove it. It is the companion of the Privacy Policy, which explains what we do with personal data. Nothing here is legal advice.
1. What this notice covers
We run three products from one operator:
- stampomat.com (the loyalty product): the public website, the customer wallet at
/app, membership passes at/pass, the business and organisation dashboards, the cashier and monitor screens used at a counter, and the pages benefit providers use to answer an invitation and scan members. - Stampomat Sites: the websites and pickup ordering pages we build for businesses. They run on a
stampomat.comsubdomain or on the business's own domain. The business portal atmanage.stampomat.comand the owner console atadmin.stampomat.combelong to the same product. - Our internal tools at
growth.stampomat.com, which only our team can sign in to. Section 10 covers them for completeness.
2. The short version
- Every cookie we set is first-party (set by the site you are on, readable only by that site) and either strictly necessary for what you asked the site to do, or a preference you set yourself.
- We set no analytics cookies, no advertising cookies and no third-party tracking cookies. Our website statistics work without cookies (section 6).
- We use no third-party scripts, pixels or tags on any page. The only third-party content our pages fetch on their own is font files, from an EU host that sets no cookies, on business websites (section 7).
- There are two exceptions you control. Some business websites can show a Google Map, which does not load until you click "Load map", and clicking sends data to Google (section 8). And the checkout of a business website can remember your name, phone number and email address in your own browser, only if you tick the box that offers it (section 9).
- Because of the above, we do not show a cookie banner (section 3).
- Signing in with Google, saving a pass to Google Wallet and opening a map link all take you to Google's own pages, where Google's cookie rules apply, not ours.
3. Why you do not see a cookie banner
The law requires your consent before anything is stored on your device or read from it, unless the storage is strictly necessary to provide a service you explicitly asked for. That rule is written into Slovenian law (ZEKom-2, Article 225), Macedonian law (the Law on Electronic Communications) and German law (TDDDG, section 25), and it is supervised in Slovenia by the Information Commissioner and in North Macedonia by the Agency for Personal Data Protection.
Everything in sections 4 to 10 falls under the exemption, apart from the two items in the next paragraph. A session cookie is needed to keep you signed in and to protect forms; a remember cookie exists because you asked to stay signed in; the stamp device cookie protects the shop's rewards from being farmed by one device; the cashier and till device cookies mark tablets the business itself registered at its counter; the language cookie stores a choice you made. None of them profiles you, none follows you to other websites, and no advertising network sees any of them. There is therefore nothing to ask consent for, and a banner would be noise.
Two items need consent, and each asks for it where it is used. The Google Map on some business sites is not loaded until you click a button that tells you what the click sends; that click is your consent, and you can undo it on the same page (section 8). Your checkout details are remembered on a business website only if you tick Remember my details on this device at its checkout, a box that starts unticked; that tick is your consent, and Not you? Clear at the same checkout removes them (section 9).
If we ever add storage that needs consent, we will ask first and update this notice before it goes live. You can always refuse or delete cookies in your browser (section 11); the sections below say what stops working when you do.
4. Cookies on stampomat.com
Every cookie in this table except the Cloudflare row is set by our own server on stampomat.com. Sign-in cookies are encrypted and signed, so their contents cannot be read or altered outside our server. The two device cookies (cashier_device, till_device) are not encrypted: each is a random token that the business can revoke at any time from its dashboard.
| Cookie | Set when | What it does | Lifetime | Protection |
|---|---|---|---|---|
stampomat_session | Your first page view | Identifies your session on our server: who you are signed in as, the token that protects forms, and messages shown after an action | 120 minutes after your last request, then discarded; it does not end when you close the browser | HttpOnly (scripts cannot read it), Secure (HTTPS only), SameSite Lax, encrypted |
XSRF-TOKEN | Your first page view | Protects forms against cross-site request forgery | Same as the session cookie | Secure, SameSite Lax, encrypted; readable by our own scripts by design |
customer_remember | After you sign in to the wallet with Google | Keeps you signed in so you do not need Google on every scan; holds your account id and a random 64-character token that belongs to this device only | 400 days, the cap modern browsers put on cookie lifetime; removed when you sign out on this device, which does not sign you out on your other devices | HttpOnly, Secure, SameSite Lax, encrypted |
merchant_remember | After a business owner or team member signs in to the dashboard | Keeps the dashboard sign-in; team members' values are prefixed so one cookie serves both | 400 days; removed on sign-out, which signs that person out everywhere | HttpOnly, Secure, SameSite Lax, encrypted |
benefit_station_remember | After a benefit provider signs in with Google to the scanning page for benefits where the provider scans members | Keeps the scanning page sign-in on this device; holds the provider record's id and a random 60-character token | 90 days, renewed at each sign-in; removed on sign-out, which signs the provider out on every device | HttpOnly, Secure, SameSite Lax, encrypted |
owner_remember | After the platform administrator signs in | Keeps the administrator sign-in | 30 days | HttpOnly, Secure, SameSite Lax, encrypted |
stamp_device | The first time you collect a stamp in this browser | Fraud prevention: a random 40-character id for this browser, used to slow down one device that collects stamps on several accounts in quick succession. It is deliberately kept when you sign out, otherwise it would be pointless | 400 days | HttpOnly, Secure, SameSite Lax, encrypted |
cashier_device | When a business registers a counter tablet with its cashier password | Marks that tablet as a trusted stamp till so staff do not retype the password; holds a random 64-character token that the business can revoke from the dashboard | 365 days, or until revoked | HttpOnly, Secure (HTTPS only, on the live service), SameSite Lax; not encrypted (the token itself is the credential and is only compared, never decoded) |
till_device | When a business pairs a counter till tablet (points mode) with a one-time pairing code from its dashboard | Marks that tablet as a paired till so it can record sales and print slips; holds a random 48-character token. The business can retire or revoke the till from its dashboard, which stops the tablet on its next request | 365 days, or until revoked | HttpOnly, Secure (on the live service), SameSite Lax; not encrypted, for the same reason as the cashier cookie |
stampomat_locale | Every page view of the public site, and whenever you pick a language in the wallet | Remembers the language you chose, so the site opens in it next time | 400 days, restarted on every visit | Secure, SameSite Lax, encrypted; not HttpOnly |
__cf_bm, cf_clearance | Only on hostnames served through Cloudflare, and only when Cloudflare's bot protection or a challenge page is active | Cloudflare, Inc., our security and edge provider, uses them to tell browsers from bots and to remember that a challenge was passed; we do not read them | __cf_bm about 30 minutes; cf_clearance varies with the challenge settings | Set and controlled by Cloudflare; first-party to the hostname you are on |
Three things the table does not contain, because they are not our cookies:
- Google sign-in. When you sign in, your browser goes to Google's pages. Google sets cookies on its own domains under its own privacy policy. We receive only your name, email address and account id.
- Google Wallet. The "Save to Google Wallet" button on a membership pass is a link to Google's own page. No Google code runs on our pages before you click it.
- Accepting our terms. The
customer_remembercookie signs you in, but it never stands in for accepting our terms: if you have never accepted them, you see the acceptance screen before the wallet opens, whatever cookies your browser holds. A new version of the terms or the privacy policy does not bring that screen back.
5. Browser storage on stampomat.com
Besides cookies, a browser can hold data in local storage, in caches and through a service worker. This is what we use, and none of it holds personal data:
- Cashier screens keep the id of the last alert they showed (
lastMonitorAlertIdon the monitor,lastMultiAccountAlertIdon the stamp screen) so the same alert does not sound twice. These are numbers, nothing else. - The business dashboard keeps one small layout preference (which sidebar section was open) under a single key in local storage. Nothing about customers is stored there.
- The wallet and the pass page register a service worker so the app can be installed on your phone and can show an offline page. The worker caches only static files (scripts, styles, icons, fonts) and one fixed offline page that contains no data about you. Pages that show your stamps, points or passes are never written to any cache; every balance you see came from our server on that request.
- Push notifications in the wallet are off unless you switch them on inside the app; the browser then stores a push subscription that you can remove with the same switch or in your browser's site settings.
No page on stampomat.com loads scripts, fonts, images or frames from any third party; the fonts are served from our own server.
6. Our website statistics work without cookies
When you view a page on the public site, your browser sends one small request to our own /track endpoint. Our server records the page, the domain of the site that referred you, the language, your country and an anonymous visitor hash. The hash is built from the current date, your IP address, your browser signature and a server secret, so it changes every day and cannot connect today's visit to tomorrow's. Your IP address is not stored: your country is looked up on our own server against a local copy of the DB-IP database (or read from the country header Cloudflare adds on proxied hostnames), and a hashed form of the address is cached on the server for one day so the lookup is not repeated. Requests from known crawlers are ignored.
Do Not Track. If your browser sends the Do Not Track signal (DNT: 1), our server records nothing at all for that request. It still answers with an empty success response so that the page is not affected. We do not currently read the Global Privacy Control signal; Do Not Track is the one we honour.
None of this sets or reads a cookie, and none of it involves a third party.
7. Cookies on business websites built with Stampomat Sites
A business website built with Sites (on something.stampomat.com or on the business's own domain), its ordering and order status pages, and the two portals all set the cookies below. Every business website domain is served through Cloudflare, so the Cloudflare row applies to all of them.
| Cookie | Set when | What it does | Lifetime | Protection |
|---|---|---|---|---|
stampomat-sites-session | Your first page view on any page of the site | Identifies your session on our server. The session holds your cart and any item notes, the language you are viewing, the preview permission when a business owner previews a draft site, the opaque wallet reference if you linked your Stampomat wallet at checkout, and the portal sign-in | 120 minutes after your last request; it does not end when you close the browser | HttpOnly, Secure (HTTPS only), SameSite Lax, encrypted |
XSRF-TOKEN | Your first page view | Protects the checkout, contact and newsletter forms against cross-site request forgery | Same as the session cookie | Secure, SameSite Lax, encrypted; readable by our own scripts by design |
remember_web_ followed by a fixed hash | After a business user signs in to manage.stampomat.com, or the owner signs in to admin.stampomat.com, with Google | Keeps the portal sign-in | 30 days on the business portal; 400 days on the owner console. Removed on sign-out; a business user can also sign out of all devices at once | HttpOnly, Secure, SameSite Lax, encrypted |
__cf_bm, cf_clearance | Only when Cloudflare's bot protection or a challenge page is active for the domain | As in section 4: Cloudflare, Inc. tells browsers from bots; we do not read them | __cf_bm about 30 minutes; cf_clearance varies | Set and controlled by Cloudflare |
Three related points:
- The session record on our server (not on your device) holds your IP address and browser signature alongside the cart. It is deleted after about two hours of inactivity; a daily sweep removes anything the automatic cleanup missed.
- Fonts. The theme fonts of a business website are loaded from Bunny Fonts, run by BunnyWay d.o.o. in Slovenia. To deliver a font file, Bunny receives your IP address and browser details, states that it keeps no logs, and sets no cookie. Nothing is loaded from Google Fonts.
- Visit counting. Each site counts how many visitors reached the menu, the cart and the checkout. These are plain daily totals per site with no identifier; the counter stores nothing on your device and reads your browser signature only to skip crawlers, without keeping it.
No script on a business website sets a cookie or writes to browser storage, with two exceptions, each only after you chose it: the map choice in section 8, and remembered checkout details in section 9. The one script library the pages use is served from our own server.
8. The Google Map on business websites
A business can show a map of its address on its Info page, or as a map section on any page. Google Maps is a service of Google, and loading it sends data to Google. So we do not load it by default.
Before you click, the page shows the business address as text, a link "Open in Google Maps" and a button "Load map". The link takes you to Google's own maps site in a new tab; following a link stores nothing on your device from our side. Nothing from Google is loaded at this point.
When you click "Load map", your browser loads the map frame from www.google.com. That request sends Google your IP address, your browser details and the address of the page you are on, and Google sets its own cookies inside the map frame (commonly NID, and the CONSENT and SOCS cookies for visitors in Europe; the names are Google's and can change). Google LLC uses this data for its own purposes as an independent controller; it is not our processor. Google Maps content is subject to the Google Maps Additional Terms of Service and the Google Privacy Policy. Google LLC is certified under the EU-US Data Privacy Framework for data it receives in the United States.
Your choice is remembered in your browser's local storage under the key stampomat_maps_consent, so the map opens directly on your later visits to that site. A "Hide map" control on the map removes the frame and clears the key; the next visit shows the placeholder again. The choice is stored per browser and per site, never on our server, and it never leaves your device. Google's attribution and links in the map are never covered or cropped.
If scripts are blocked in your browser, the placeholder stays as it is: the address and the plain link still work, and no map loads.
9. Browser storage on business websites and in the portals
- Map choice (
stampomat_maps_consent): section 8. Only present if you clicked "Load map". - Remembered checkout details (
stampomat_checkout_details_followed by the site id, in local storage): only if you tick Remember my details on this device at the checkout of a business website. It holds your name, phone number and email address and the time they were saved, for that site's address only, so that your next checkout there is filled in. They are saved when your order status page opens after the order is placed; until then that browser tab's session storage holds them understampomat_checkout_pending_followed by the site id, and the site's next ordering page in that tab removes that copy if it is still there. An order placed with the box unticked and the same details leaves only a marker without your details there, so that the status page can remove the saved ones. Your notes and pickup time are never saved, and nothing reaches our server except as part of an order you place. The details are used for up to 365 days after they were last saved; after that the checkout deletes them. Not you? Clear at that checkout removes them at once. The business website's privacy notice describes this in full. - Order sound (
orderSoundEnabled): on the orders screen of the business portal, whether the new-order chime is on. A single true or false value chosen by the business user. - Open menu sections (
menu-open-followed by the site id): in the menu editor of the portals, which menu sections the user has opened; everything else starts folded. A list of category ids, nothing else. - Push notifications for new orders: on the orders screen, a business user can switch on push notifications. Only then does the page register a service worker (
/sw.js), whose sole job is to receive those notifications; it caches nothing. The same switch turns them off again, removes the subscription from the browser and tells our server to forget it. The page never asks for notification permission on its own.
Nothing else is written to local storage by a business website, its ordering pages or the portals.
10. Our internal tools
growth.stampomat.com is a tool for our own team, not a public service; apart from the team sign-in page and one technical endpoint that confirms an Instagram data deletion, our firewall keeps it closed. For team members it sets a session cookie named stampomat-growth-session and the XSRF-TOKEN cookie, both with the same purpose, lifetime and protection as in section 7, and no remember cookie: when the session ends, you sign in with Google again. Cloudflare's cookies apply as in section 4 where its protection is active. Its sign-in page loads its font from our own server. The team notice that every member receives describes these cookies and the tool's other processing.
11. How to clear or block cookies and storage
You can delete or block cookies and site data in your browser at any time. The path is similar everywhere: open the browser's settings, find "Privacy" or "Site settings", then "Cookies and site data", and either clear everything or search for the domain (stampomat.com, or the business website's domain). In most browsers you can also click the padlock or site icon next to the address bar and choose "Cookies and site data" for the site you are on. The same screen lets you remove a service worker and any push subscription for the site; on Android, clearing Chrome's stampomat.com entry does the same.
What happens when you do:
- Session and
XSRF-TOKENcookies: you are signed out, any cart on a business website is emptied, and the next form submission will ask you to try again. Both are set again on your next page view; the site cannot work without them. - Remember cookies: you sign in with Google again next time. Nothing else changes.
stamp_device: a new id is created the next time you collect a stamp. The cooldown rules still apply, so deleting it gains nothing.cashier_device: the tablet stops being trusted, and staff must register it again with the cashier password. The business can also revoke it from the dashboard without touching the tablet.till_device: the till stops working and must be paired again with a fresh code from the business dashboard.stampomat_locale: the site opens in the language of the address you visit until you choose again.- Map choice: the placeholder comes back and the map waits for your click.
- Remembered checkout details: the next checkout on that business website starts with empty fields and the box unticked.
- Blocking all cookies for a domain: you can read every public page and every legal page without cookies, but you cannot sign in, order or collect stamps there, because those actions need a session.
Deleting cookies removes data from your device only. To have your account or your data deleted on our side, use the account deletion page or write to hello@stampomat.com.
12. Changes to this notice
The version and effective date at the top identify the text you are reading. We change this notice when a cookie or storage item is added, removed or changed; the document versions page lists every published version with a summary. If a change would introduce storage that needs consent, we will ask for that consent in the product before the change takes effect, and account holders will be told by email as described in the Privacy Policy.
13. Contact and complaints
Write to hello@stampomat.com for anything about cookies or storage. For general support use hello@stampomat.com. If you believe we use cookies or device storage unlawfully, you can complain to the Information Commissioner of the Republic of Slovenia (ip-rs.si), which supervises the cookie rules in Slovenia, to the Agency for Personal Data Protection of North Macedonia (azlp.mk), or, if you live elsewhere in the EU, to the data protection authority of your country.
This notice is published in English, Macedonian, Slovenian and German. For consumers, the version in your language prevails; for businesses, the English version prevails. It is linked from the footer of every page of stampomat.com, from the wallet's account menu, from every dashboard and portal, and from the privacy page of every business website built with Sites.