Cookie Policy
The cookies the Parmo website sets, all of which are strictly necessary.
Version 1.2 · in effect since 28. Sept. 2026
Why there is no cookie banner
The law asks for your consent before a website stores anything on your device, unless the storage is strictly necessary to provide a service you explicitly asked for (Art. 5(3) of the ePrivacy Directive, and in Germany § 25 Abs. 2 Nr. 2 TDDDG). Every cookie Parmo sets falls under that exception: each one is written only in response to something you did, such as signing in, choosing a language, following an invite link or tapping Near me, and does only that job. Parmo sets no analytics cookies, no advertising cookies and no third-party tracking. Our product analytics runs without a cookie and without local storage, so it cannot recognise you from one visit to the next unless you sign in.
The mobile app sets no cookies at all. It keeps your session in the device keychain, which is cleared when you sign out or delete the app.
What the website sets
| Cookie | Purpose | Lifetime |
|---|---|---|
sb-*-auth-token | Your signed-in session, set by our authentication provider when you sign in. Without it every page would ask you to sign in again. A long session may be split across several cookies ending in .0, .1 and so on. | Until you sign out, or 400 days after your session was last refreshed |
sb-*-auth-token-code-verifier | A one-time secret that proves the sign-in you started is the one being finished, set when you sign up, reset your password or sign in with Apple or Google. | Deleted as soon as the sign-in completes; 400 days at most if it never does |
parmo_locale | The language you chose, so the site opens in it next time. | One year |
parmo_rail | Whether you folded the side menu down to its icons, so it stays the way you left it. | One year |
parmo_ref | The invite link you followed, so the person who invited you is credited when you sign up. Set only after you open an invite link. | 30 days |
parmo_next | The page you were on when you were asked to sign in, so you land back there afterwards. Set only when a link carries that destination. | One hour |
parmo_apply | The event you tapped "Sign up to promote this" on, so the application is made for you once your account is ready. | One hour |
parmo_geo | Your position, set only when you tap Near me, so the event feed can search around you. Kept in a cookie so it never appears in a web address you might share. | One hour |
parmo_impersonation | Only for Parmo admin staff: holds their own session while they view the app as another account for support, so they can switch back. | Eight hours |
All of them are first-party: they are set by the Parmo website and sent only back to it, and no other website can read them. Blocking them in your browser is possible; blocking the session cookie means you cannot stay signed in.
Requests to other companies
These services receive requests while you use the site. None of them sets a cookie.
- OpenFreeMap serves the map tiles when a map is shown, and sees your IP address.
- Meta’s CDN serves the Instagram images on profile and campaign pages, and sees your IP address.
- PostHog receives the usage events described in the Privacy Policy: page views from every visitor, and product events once you are signed in. It keeps them in memory only, sets no cookie, and discards the IP address on arrival.
- Vercel Web Analytics and Speed Insights, from our hosting provider, count page views and measure how fast pages load. They work without cookies and report only totals; your IP address is used to tell visits apart within a day and is not stored.
- Sentry receives a report when something breaks: the error, the page it happened on, and your browser and system version. No IP address, name or email is attached, and there is no recording of your screen.
- Google Maps Platform turns what you type into a city or venue field into place suggestions. The search goes through our server, so Google sees the text but not your IP address.
Questions: privacy@parmo.io.