# Cookie Policy

- Section: Imprint > Cookie Policy
- Canonical: https://covdbg.com/imprint/cookies/

---

Last updated: September 2026

## This website

The cookie banner lets you allow or reject optional analytics. We use Google Analytics and our own Matomo installation. Nothing is loaded from either service until you allow analytics. Advertising storage and personalization remain disabled. You can reopen Cookie settings in the footer and withdraw your choice.

Your choice is stored locally as `covdbg-consent-v1` for 180 days. If browser storage is unavailable, your choice applies to the current page and you may be asked again. With JavaScript off, analytics does not load.

The color theme follows your system until you choose light or dark mode. That choice is
saved in your browser's local storage as `covdbg-theme`, so it carries across pages and
visits. It contains only `light` or `dark` and is not sent to our server. Clearing this
site's browser storage restores the system default.

When Google Analytics is configured and you allow it, it uses `_ga` cookies to distinguish visits. We configure these cookies to expire after 180 days. Rejecting analytics removes these cookies for this site. Google receives usage information; see [Google’s privacy policy](https://policies.google.com/privacy).

Matomo runs on our own server at analytics.liasoft.de, so this usage data is not passed to another analytics company. When you allow analytics, it sets first-party cookies on this site: `_pk_id` to distinguish visits, which we configure to expire after 180 days to match `_ga`, `_pk_ses` for your current visit, which expires after about 30 minutes, and `_pk_ref` for how you reached the site. Matomo receives the page address without its query string, the origin of the page you came from, and technical details such as your browser and screen size. Rejecting analytics removes these cookies for this site.

The contact and quote forms temporarily store your details on our server and email you a verification link. We forward the request to our team only after you confirm. The `covdbg-form` session cookie protects form submissions against forgery and remembers the short challenge used to reveal our contact email addresses. It is restricted to `/api/` and expires with your browser session.

## The portal at app.covdbg.com

When you sign in at app.covdbg.com, your browser keeps a sign-in token in its local storage so that you stay signed in. It is not a cookie, it is not shared with any other site, and it is removed when you sign out. Every session signed in as you is listed on your profile, where you can end any of them.

Buying seats opens Paddle's checkout inside the page. Paddle is our merchant of record and may set cookies of its own during checkout; see [Paddle's privacy policy](https://www.paddle.com/legal/privacy).

## Changes

We update this page when the website or the portal changes. The date at the top says when.

## Questions

Write to [our team](/company/contact/#email-addresses).
