Legal · Last updated 3 July 2026
SvenskaCookie Policy
This page lists exactly what stockisto.com stores in your browser. We verified the list against the actual code, not a boilerplate template. There are no third-party trackers and no advertising cookies. Nothing is sold or shared with ad networks.
1. What we set, honestly
stockisto_consent
- Type
- Cookie
- Purpose
- Remembers your accept/reject choice below, so we don't ask on every page.
- Duration
- 365 days
- Needs consent?
- No (strictly necessary)
__cf_bm, cf_clearance (Cloudflare Turnstile)
- Type
- Third-party cookie (Cloudflare)
- Purpose
- Written by Cloudflare only when you meet the human check on a form (sign-up, contact, newsletter). It records that this browser passed the check, so the same form does not ask again. It carries no name, email or message, and no form without the check writes it.
- Duration
- 30 minutes (__cf_bm); up to 30 days (cf_clearance), both set by Cloudflare
- Needs consent?
- No (strictly necessary)
stockisto_utm
- Type
- Cookie
- Purpose
- Remembers the campaign labels (
utm_source,utm_medium, etc.) from the link you first arrived on. This shows us which campaigns bring visitors here. It stores no personal data, only the labels your own inbound link already carried. - Duration
- 30 days
- Needs consent?
- Yes (analytics & attribution)
stockisto_ref
- Type
- Cookie + localStorage
- Purpose
- If you arrived via a referral link (
?ref=CODE), remembers the code. This lets us credit a resulting signup to the referring company. - Duration
- 30 days (cookie); until cleared (localStorage)
- Needs consent?
- Yes (analytics & attribution)
stockisto_mktg_session
- Type
- sessionStorage
- Purpose
- Once you accept, a random id that groups the events sent from one browser tab, so we can tell one visit from two. It is not tied to your identity. The page count described in section 2 never uses it.
- Duration
- Until the tab closes
- Needs consent?
- Yes (analytics & attribution)
| Name | Type | Purpose | Duration | Needs consent? |
|---|---|---|---|---|
| stockisto_consent | Cookie | Remembers your accept/reject choice below, so we don't ask on every page. | 365 days | No (strictly necessary) |
| __cf_bm, cf_clearance (Cloudflare Turnstile) | Third-party cookie (Cloudflare) | Written by Cloudflare only when you meet the human check on a form (sign-up, contact, newsletter). It records that this browser passed the check, so the same form does not ask again. It carries no name, email or message, and no form without the check writes it. | 30 minutes (__cf_bm); up to 30 days (cf_clearance), both set by Cloudflare | No (strictly necessary) |
| stockisto_utm | Cookie | Remembers the campaign labels (utm_source, utm_medium, etc.) from the link you first arrived on. This shows us which campaigns bring visitors here. It stores no personal data, only the labels your own inbound link already carried. | 30 days | Yes (analytics & attribution) |
| stockisto_ref | Cookie + localStorage | If you arrived via a referral link (?ref=CODE), remembers the code. This lets us credit a resulting signup to the referring company. | 30 days (cookie); until cleared (localStorage) | Yes (analytics & attribution) |
| stockisto_mktg_session | sessionStorage | Once you accept, a random id that groups the events sent from one browser tab, so we can tell one visit from two. It is not tied to your identity. The page count described in section 2 never uses it. | Until the tab closes | Yes (analytics & attribution) |
2. Strictly necessary: no consent needed
The stockisto_consent cookie remembers your choice below. Under GDPR/ePrivacy it is exempt from consent. It is required to deliver the exact function you are using: not being asked again on every page. It stores nothing beyond that choice. We also count page views on this site, before you choose and whether or not you accept, because otherwise we cannot tell whether anyone reads these pages. That count stores nothing in your browser: each view sends our own servers the page address and nothing about you, no cookie, no reusable id, nothing that links one page to the next or one visit to another. It reaches no one outside Stockisto.
3. Analytics & attribution: one category, gated on your choice
The other three items answer one question: which campaigns bring people to Stockisto, and which referrals lead to a signup. They serve no advertising or cross-site tracking purpose. So we present them as a single accept/reject choice. Before you accept, or if you reject, we write none of the three, and every analytics event except the bare page count above is dropped before it leaves your browser. If you accepted earlier and then reject, we also clear what was already stored.
4. The embeddable Locator widget
A supplier can embed our Locator widget on their own site. The widget sets no cookies. It uses localStorage for a postcode and its coordinates, cached brand styling, and a saved embed's loading shape (type, view and settings). In sessionStorage, stockisto.result-intent.<brandSlugOrSupplierId>|<sku>|<retailerId> holds random result ids that prevent duplicate analytics events after a tab is restored. stockisto:gh-intent:<supplierId> holds the chosen installer id. stockisto:gh-intent:<supplierId>:<installerId> holds an idempotency key, a salted fingerprint of the submitted request body and the retailer id. This lets a retried installer request reuse its key without creating a duplicate lead. The fingerprint is derived from the submitted form; the record does not store the name or email address as text. The pending-request record is cleared after a successful submission, a replay or an intake conflict. The installer-selection key and remaining sessionStorage entries last for the tab session. It fires no analytics unless the embedding site explicitly turns analytics on. See our Security page for the full answer.