Loading ChongCheck
Preparing the next page and checking session context.
Preparing the next page and checking session context.
This Cookie Policy explains how ChongCheck OÜ ("ChongCheck", "we") uses cookies and similar technologies ("Cookies") on our websites and applications.
It supplements our Privacy Policy and Terms of Service.
A cookie is a small text file placed on your device by a website you visit. Cookies have many uses: keeping you signed in, remembering your preferences, measuring how the site is used, and (sometimes) tracking you across sites.
Similar technologies include local storage, session storage, IndexedDB, pixels, and SDK identifiers in our mobile apps. We treat them under the same rules as cookies for the purposes of this Policy.
We group cookies into four categories:
Required for the Service to function. You cannot opt out of these — without them, the site won't work.
| Cookie / Storage | Purpose | Duration |
|---|---|---|
cc_session | Authenticated session token | Session |
cc_csrf | Cross-site request forgery protection | Session |
cc_consent | Stores your cookie preferences | 12 months |
cc_locale | Remembers your language choice | 12 months |
Local storage cc_draft_* | Draft case data not yet submitted | Until submission or 30 days |
Cloudflare __cf_bm | Bot detection on infrastructure layer | 30 minutes |
Enhance usability, but the Service works without them.
| Cookie / Storage | Purpose | Duration |
|---|---|---|
cc_theme | Light/dark mode preference | 12 months |
cc_dismissed_banners | Tracks which in-app banners you've dismissed | 6 months |
cc_a11y_motion | Stores reduced-motion preference if set in-app | 12 months |
Help us understand how the Service is used so we can improve it.
| Cookie / Storage | Purpose | Duration | Provider |
|---|---|---|---|
ph_* (PostHog) | Anonymous usage analytics (events, funnels) | 12 months | PostHog |
| Sentry session-replay (sampled) | Reproduce errors so we can fix them; replay is PII-scrubbed | 90 days | Sentry |
PostHog is configured with no IP collection in EU mode and with PII scrubbing. We do not use Google Analytics or any cross-site advertising trackers.
Used only if you opt in. We currently do not run paid retargeting campaigns, so this category is empty in production. If we add any in the future, we will re-prompt for consent.
The first time you visit, you see a banner with four options:
You can change your choice at any time via the Cookie Preferences link in the website footer or via Settings → Privacy → Cookies in your account.
Most browsers let you block or delete cookies directly. Useful links:
chrome://settings/cookiesabout:preferences#privacyedge://settings/content/cookiesDisabling Strictly Necessary cookies may prevent the Service from working.
We honour the Global Privacy Control (GPC) signal where required by law. When we detect GPC, we treat it as a refusal of non-essential cookies (Analytics + Marketing).
We do not currently honour the legacy "Do Not Track" header because it is ambiguous and has been deprecated in modern browsers.
Some pages embed third-party content (e.g., support widget). Those providers may set their own cookies under their own policies. We disclose the third parties below. We do not allow them to read our authentication cookies.
| Provider | Purpose | When loaded | More info |
|---|---|---|---|
| Cloudflare | DDoS protection, bot detection | All pages | cloudflare.com/privacypolicy |
| PostHog | Analytics (with consent) | Pages where analytics is enabled | posthog.com/privacy |
| Sentry | Error monitoring | All pages | sentry.io/privacy |
| Postmark | Email link tracking (transactional only) | Email link clicks | postmarkapp.com/privacy-policy |
| Heleket | Payment processing | Checkout pages only | heleket.com/privacy |
| Stripe (if enabled in your region) | Payment processing | Checkout pages only | stripe.com/privacy |
Our mobile apps do not use cookies but use functionally equivalent local storage and (with permission) push-notification tokens. Tokens identify your device to the push provider so we can deliver outcome wizard nudges, security alerts, and other notifications. You can revoke push consent in your device settings at any time.
We do not knowingly use cookies to track children under 16. The Service is not directed at children.
We update this Policy when we change our cookie practices. Material changes are announced via in-app banner. If new categories of cookies are added, we re-prompt for consent.
Version history: chongcheck.app/legal/cookie-policy/versions.
privacy@chongcheck.app
This document is a draft pending review by qualified counsel.