Cookies and local storage

Published by Stampomat, operated by Daniel Ilievski, Ljubljana, Slovenia. Questions about this notice: hello@stampomat.com.

This notice lists every cookie and every other item we store on your device across the Stampomat products, what each one is for, how long it lasts, and how to remove it. It is the companion of the Privacy Policy, which explains what we do with personal data. Nothing here is legal advice.

1. What this notice covers

We run three products from one operator:

2. The short version

3. Why you do not see a cookie banner

The law requires your consent before anything is stored on your device or read from it, unless the storage is strictly necessary to provide a service you explicitly asked for. That rule is written into Slovenian law (ZEKom-2, Article 225), Macedonian law (the Law on Electronic Communications) and German law (TDDDG, section 25), and it is supervised in Slovenia by the Information Commissioner and in North Macedonia by the Agency for Personal Data Protection.

Everything in sections 4 to 10 falls under the exemption, apart from the two items in the next paragraph. A session cookie is needed to keep you signed in and to protect forms; a remember cookie exists because you asked to stay signed in; the stamp device cookie protects the shop's rewards from being farmed by one device; the cashier and till device cookies mark tablets the business itself registered at its counter; the language cookie stores a choice you made. None of them profiles you, none follows you to other websites, and no advertising network sees any of them. There is therefore nothing to ask consent for, and a banner would be noise.

Two items need consent, and each asks for it where it is used. The Google Map on some business sites is not loaded until you click a button that tells you what the click sends; that click is your consent, and you can undo it on the same page (section 8). Your checkout details are remembered on a business website only if you tick Remember my details on this device at its checkout, a box that starts unticked; that tick is your consent, and Not you? Clear at the same checkout removes them (section 9).

If we ever add storage that needs consent, we will ask first and update this notice before it goes live. You can always refuse or delete cookies in your browser (section 11); the sections below say what stops working when you do.

4. Cookies on stampomat.com

Every cookie in this table except the Cloudflare row is set by our own server on stampomat.com. Sign-in cookies are encrypted and signed, so their contents cannot be read or altered outside our server. The two device cookies (cashier_device, till_device) are not encrypted: each is a random token that the business can revoke at any time from its dashboard.

Three things the table does not contain, because they are not our cookies:

5. Browser storage on stampomat.com

Besides cookies, a browser can hold data in local storage, in caches and through a service worker. This is what we use, and none of it holds personal data:

No page on stampomat.com loads scripts, fonts, images or frames from any third party; the fonts are served from our own server.

6. Our website statistics work without cookies

When you view a page on the public site, your browser sends one small request to our own /track endpoint. Our server records the page, the domain of the site that referred you, the language, your country and an anonymous visitor hash. The hash is built from the current date, your IP address, your browser signature and a server secret, so it changes every day and cannot connect today's visit to tomorrow's. Your IP address is not stored: your country is looked up on our own server against a local copy of the DB-IP database (or read from the country header Cloudflare adds on proxied hostnames), and a hashed form of the address is cached on the server for one day so the lookup is not repeated. Requests from known crawlers are ignored.

Do Not Track. If your browser sends the Do Not Track signal (DNT: 1), our server records nothing at all for that request. It still answers with an empty success response so that the page is not affected. We do not currently read the Global Privacy Control signal; Do Not Track is the one we honour.

None of this sets or reads a cookie, and none of it involves a third party.

7. Cookies on business websites built with Stampomat Sites

A business website built with Sites (on something.stampomat.com or on the business's own domain), its ordering and order status pages, and the two portals all set the cookies below. Every business website domain is served through Cloudflare, so the Cloudflare row applies to all of them.

Three related points:

No script on a business website sets a cookie or writes to browser storage, with two exceptions, each only after you chose it: the map choice in section 8, and remembered checkout details in section 9. The one script library the pages use is served from our own server.

8. The Google Map on business websites

A business can show a map of its address on its Info page, or as a map section on any page. Google Maps is a service of Google, and loading it sends data to Google. So we do not load it by default.

Before you click, the page shows the business address as text, a link "Open in Google Maps" and a button "Load map". The link takes you to Google's own maps site in a new tab; following a link stores nothing on your device from our side. Nothing from Google is loaded at this point.

When you click "Load map", your browser loads the map frame from www.google.com. That request sends Google your IP address, your browser details and the address of the page you are on, and Google sets its own cookies inside the map frame (commonly NID, and the CONSENT and SOCS cookies for visitors in Europe; the names are Google's and can change). Google LLC uses this data for its own purposes as an independent controller; it is not our processor. Google Maps content is subject to the Google Maps Additional Terms of Service and the Google Privacy Policy. Google LLC is certified under the EU-US Data Privacy Framework for data it receives in the United States.

Your choice is remembered in your browser's local storage under the key stampomat_maps_consent, so the map opens directly on your later visits to that site. A "Hide map" control on the map removes the frame and clears the key; the next visit shows the placeholder again. The choice is stored per browser and per site, never on our server, and it never leaves your device. Google's attribution and links in the map are never covered or cropped.

If scripts are blocked in your browser, the placeholder stays as it is: the address and the plain link still work, and no map loads.

9. Browser storage on business websites and in the portals

Nothing else is written to local storage by a business website, its ordering pages or the portals.

10. Our internal tools

growth.stampomat.com is a tool for our own team, not a public service; apart from the team sign-in page and one technical endpoint that confirms an Instagram data deletion, our firewall keeps it closed. For team members it sets a session cookie named stampomat-growth-session and the XSRF-TOKEN cookie, both with the same purpose, lifetime and protection as in section 7, and no remember cookie: when the session ends, you sign in with Google again. Cloudflare's cookies apply as in section 4 where its protection is active. Its sign-in page loads its font from our own server. The team notice that every member receives describes these cookies and the tool's other processing.

11. How to clear or block cookies and storage

You can delete or block cookies and site data in your browser at any time. The path is similar everywhere: open the browser's settings, find "Privacy" or "Site settings", then "Cookies and site data", and either clear everything or search for the domain (stampomat.com, or the business website's domain). In most browsers you can also click the padlock or site icon next to the address bar and choose "Cookies and site data" for the site you are on. The same screen lets you remove a service worker and any push subscription for the site; on Android, clearing Chrome's stampomat.com entry does the same.

What happens when you do:

Deleting cookies removes data from your device only. To have your account or your data deleted on our side, use the account deletion page or write to hello@stampomat.com.

12. Changes to this notice

The version and effective date at the top identify the text you are reading. We change this notice when a cookie or storage item is added, removed or changed; the document versions page lists every published version with a summary. If a change would introduce storage that needs consent, we will ask for that consent in the product before the change takes effect, and account holders will be told by email as described in the Privacy Policy.

13. Contact and complaints

Write to hello@stampomat.com for anything about cookies or storage. For general support use hello@stampomat.com. If you believe we use cookies or device storage unlawfully, you can complain to the Information Commissioner of the Republic of Slovenia (ip-rs.si), which supervises the cookie rules in Slovenia, to the Agency for Personal Data Protection of North Macedonia (azlp.mk), or, if you live elsewhere in the EU, to the data protection authority of your country.

This notice is published in English, Macedonian, Slovenian and German. For consumers, the version in your language prevails; for businesses, the English version prevails. It is linked from the footer of every page of stampomat.com, from the wallet's account menu, from every dashboard and portal, and from the privacy page of every business website built with Sites.