Cookie Policy

The cookies the Parmo website sets, all of which are strictly necessary.

Version 1.2 · in effect since 28. Sept. 2026

Why there is no cookie banner

The law asks for your consent before a website stores anything on your device, unless the storage is strictly necessary to provide a service you explicitly asked for (Art. 5(3) of the ePrivacy Directive, and in Germany § 25 Abs. 2 Nr. 2 TDDDG). Every cookie Parmo sets falls under that exception: each one is written only in response to something you did, such as signing in, choosing a language, following an invite link or tapping Near me, and does only that job. Parmo sets no analytics cookies, no advertising cookies and no third-party tracking. Our product analytics runs without a cookie and without local storage, so it cannot recognise you from one visit to the next unless you sign in.

The mobile app sets no cookies at all. It keeps your session in the device keychain, which is cleared when you sign out or delete the app.

What the website sets

CookiePurposeLifetime
sb-*-auth-tokenYour signed-in session, set by our authentication provider when you sign in. Without it every page would ask you to sign in again. A long session may be split across several cookies ending in .0, .1 and so on.Until you sign out, or 400 days after your session was last refreshed
sb-*-auth-token-code-verifierA one-time secret that proves the sign-in you started is the one being finished, set when you sign up, reset your password or sign in with Apple or Google.Deleted as soon as the sign-in completes; 400 days at most if it never does
parmo_localeThe language you chose, so the site opens in it next time.One year
parmo_railWhether you folded the side menu down to its icons, so it stays the way you left it.One year
parmo_refThe invite link you followed, so the person who invited you is credited when you sign up. Set only after you open an invite link.30 days
parmo_nextThe page you were on when you were asked to sign in, so you land back there afterwards. Set only when a link carries that destination.One hour
parmo_applyThe event you tapped "Sign up to promote this" on, so the application is made for you once your account is ready.One hour
parmo_geoYour position, set only when you tap Near me, so the event feed can search around you. Kept in a cookie so it never appears in a web address you might share.One hour
parmo_impersonationOnly for Parmo admin staff: holds their own session while they view the app as another account for support, so they can switch back.Eight hours

All of them are first-party: they are set by the Parmo website and sent only back to it, and no other website can read them. Blocking them in your browser is possible; blocking the session cookie means you cannot stay signed in.

Requests to other companies

These services receive requests while you use the site. None of them sets a cookie.

  • OpenFreeMap serves the map tiles when a map is shown, and sees your IP address.
  • Meta’s CDN serves the Instagram images on profile and campaign pages, and sees your IP address.
  • PostHog receives the usage events described in the Privacy Policy: page views from every visitor, and product events once you are signed in. It keeps them in memory only, sets no cookie, and discards the IP address on arrival.
  • Vercel Web Analytics and Speed Insights, from our hosting provider, count page views and measure how fast pages load. They work without cookies and report only totals; your IP address is used to tell visits apart within a day and is not stored.
  • Sentry receives a report when something breaks: the error, the page it happened on, and your browser and system version. No IP address, name or email is attached, and there is no recording of your screen.
  • Google Maps Platform turns what you type into a city or venue field into place suggestions. The search goes through our server, so Google sees the text but not your IP address.

Questions: privacy@parmo.io.