Cookie policy
Drafted 19 August 2026 against what this application does. It has not yet been reviewed by a lawyer.
This policy covers the Crimptech application at app.crimptech.nl: the quote flow, the account area, the staff console and the shipment tracking pages.
The list below describes the browser storage used by the application.
1What this covers
Cookies, and the two other places a browser stores data for a site: local storage, which survives closing the browser, and session storage, which lasts as long as the tab. Dutch and European law treats all three the same way, so all three are listed here.
The privacy policy describes personal data processing. This policy covers browser storage.
2What is set, and why
The following entries support requested application functions.
The table lists each storage entry and its source. Active entries can be inspected in the browser developer tools.
| What is stored | Set by | What it is for | How long it lasts |
|---|---|---|---|
| Session cookies for signing in. Their names begin __client, __session or __clerk | Clerk, our sign-in provider, through this application | Authenticating the account, maintaining the session and identifying the account making a request | Until sign-out. The exact lifetime is configured by the sign-in provider |
| A challenge cookie | Cloudflare, through the abuse check on the upload step | Carrying the result of the check that the upload form is being used by a person. It is set on the quote page and on no other page | Set and expired by Cloudflare. This application never reads it |
| crimptech_quote_recovery: and crimptech_quote_claim: entries, in local storage | This application, on the quote page | Saved quote configurations and their individual claim credentials. Each quote can be restored or claimed independently | Until that quote is claimed, confirmed missing by the server, explicitly abandoned, or browser site data is cleared. Starting over clears its configuration while preserving an unresolved claim credential |
| crimptech_active_quote, in session storage | This application, when a saved quote is selected | Selecting the active quote for this tab while other tabs can work on different quotes | The life of the browser tab |
| crimptech_quote_draft and crimptech_claim_token, in local storage | Earlier versions of this application | Compatibility entries read during recovery of a quote saved before the per-quote registry | Until migrated, reconciled, explicitly abandoned, or browser site data is cleared |
| ct_viewed_ followed by a tracking token, in session storage | This application, on a tracking page | Recording that this tab has already counted one open of that tracking link, so a refresh does not count a second | The life of the browser tab |
3What is not here
The application does not include analytics, a tag manager, an advertising pixel or an error reporting service.
Two pieces of code do load from another company, and both are in the table above: the sign-in code from Clerk, and the abuse check on the upload step from Cloudflare.
The fonts are served from this application, so no page requests one from a third party while it loads.
4Why there is no consent banner
This application shows no cookie banner and asks for no consent.
Crimptech treats the listed storage as strictly necessary for requested functions: sign-in, file upload, draft configuration and counting one tracking-page open per tab. Article 11.7a of the Dutch Telecommunicatiewet exempts strictly necessary storage from the consent requirement.
That is a legal conclusion rather than a fact about the code. If it turns out to be wrong, this page and the application change with it.
5How to refuse them
The application has no optional storage controls. Browser settings can block cookies and site data for individual sites or all sites, and can delete existing entries.
With cookies and site data blocked for this site, signing in stops working, so the account area and the staff console are unreachable. The abuse check on the upload step cannot complete, so files cannot be uploaded. A configuration in progress is no longer carried across a page reload, so a quote has to be finished in one sitting.
A tracking link still opens with everything blocked. Each refresh is then counted as a new open.
