Cookies and trackers
Last updated: July 30, 2026
This page lists every tracker set or read by sestaro.com, whether it is a cookie, browser storage, or a technical read that stores nothing. For each one: its purpose, its actual nature, its actual lifetime, its publisher and its category.
Why strictly necessary trackers do not ask for your consent
Article 82 of the French Data Protection Act exempts from consent the trackers strictly necessary to deliver a service you explicitly asked for. The CNIL expressly places in that category authentication, security, protection against fraud and abuse, anti-bot devices such as CAPTCHAs, and the display preferences you set yourself. Those trackers therefore stay active whatever you choose, because without them the site either does not work or cannot defend itself. Everything else waits for your agreement, and does not fire until it is given.
The detail, tracker by tracker
| Name | Purpose | Nature | Lifetime | Publisher | Category |
|---|---|---|---|---|---|
sestaro-session |
Keeps your browsing session and your sign-in from one page to the next. | httpOnly, encrypted cookie | 2 hours | Sestaro | Necessary |
XSRF-TOKEN |
Protects forms against cross-site request forgery (CSRF). | Cookie | 2 hours | Sestaro | Necessary |
sestaro_consent |
Remembers the choice you make on this page, so it is not asked again on every visit. | Cookie, SameSite=Lax, sent to this site only | 6 months (183 days) | Sestaro | Necessary |
sestaro_dfp |
Technical device fingerprint, to prevent the bulk creation of free accounts aimed at harvesting the contact database. | httpOnly encrypted cookie, together with graphics rendering reads (canvas, WebGL) that store nothing on your device | 180 days after the device was last active, for the cookie as well as for the register kept on our servers. Any new activity restarts that period. | Sestaro | Necessary (security) |
challenges.cloudflare.com (Turnstile) |
Anti-bot CAPTCHA on the sign-up form, required before an account can be created. | Third-party script and frame, with the storage tied to running the challenge | For the duration of the challenge | Cloudflare | Necessary (security) |
sestaro-theme |
Remembers that you picked the light or the dark display. | Browser local storage (localStorage), not a cookie: nothing is sent to the server | Until you clear the site data | Sestaro | Necessary |
static.cloudflareinsights.com (Cloudflare Web Analytics) |
Aggregated audience measurement: page views, referrer, device type, with no individual profiling. | Third-party script posting a measurement to /cdn-cgi/rum. No cookie, no persistent identifier, nothing stored on your device | None: nothing is kept on your device | Cloudflare | Analytics |
Analytics: what we can do, and what we cannot do yet
Audience measurement runs on Cloudflare Web Analytics, which sets no cookie and uses no persistent identifier: it cannot recognise you from one visit to the next, nor follow you across other sites. That script is currently inserted by Cloudflare on the response path, before our application ever sees the page, so the application cannot yet make it conditional on your choice. We would rather say so than show a switch that commands nothing. The application-side slot that will make it conditional is already in place and waits on one thing: the automatic insertion being switched off on the Cloudflare side. Once that is done, refusing analytics will stop the script from loading.
Advertising and marketing: none, to this day
The site carries no advertising pixel, no retargeting tool, no embedded social button, no ad network and no third-party chat. The "Advertising and marketing" category still appears in the preference panel so that your refusal is already on record should such a tracker ever be added. Ticking that box today would switch on precisely nothing.
The device fingerprint case
The sestaro_dfp cookie and the graphics rendering reads that go with it exist for one purpose only: spotting that a single device is opening an abnormal number of free accounts. They belong to fraud prevention, not to analytics or marketing, so they are not subject to your consent and are never reused for anything else. One lifetime, on both sides: the cookie and the register kept on our servers are both erased 180 days after the device was last active, and any new activity restarts that period from zero. The technical detail attached to each event, including the IP address, is dropped after 4 days. Section 8 of the privacy policy gives the full detail.
The Global Privacy Control signal
Some browsers, Firefox, Brave, DuckDuckGo, or a privacy extension, send an automatic signal on every page that amounts to a refusal: Global Privacy Control. Twelve US states have made it a binding request that a site must honour without argument: California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon and Texas. We honour it everywhere, for everyone, without looking at where the visit comes from: it is simpler, it is more respectful, and nobody was ever blamed for obeying a refusal. When the signal is present, analytics and marketing stay off, and no banner comes back to ask you again for something you already refused. You stay in control: if you open the preference panel and switch a purpose on yourself, that later, deliberate choice takes precedence over the signal.
On this page, your browser is not sending that signal. Nothing is decided on your behalf: what applies is the choice you make yourself.
You are reading us from the United States
US privacy laws work on an opt-out model: collection is allowed by default, and it is up to you to say no. For trackers, saying no takes no effort here: this site carries no advertising pixel, no retargeting tool and no ad network, and your browser's Global Privacy Control signal is honoured automatically, with no request from you. For the business contact data our database may hold about you, you have the following rights, free of charge and with no need to justify yourself:
- Access: find out whether your business contact is in our database and what it says about you.
- Deletion: ask for that data to be erased.
- Opt-out: ask to be excluded for good, including from any future sale or unlock.
Exercise those rights on the data removal page
The proof of your choice
When you make a choice, we record on our side a random identifier, the date and time, the purposes kept, and the banner version. Neither your IP address, nor your browser, nor your account appears there: that record cannot identify you, it only demonstrates that a choice was collected, as the GDPR requires. It is deleted after 6 months, at the same time as your choice stops being valid.
Handling this from your browser
Independently of our settings, your browser lets you block or clear a site's cookies. Two consequences worth knowing: clearing the sestaro_consent cookie also clears your choice, so the banner will come back on your next visit; blocking strictly necessary cookies will break sign-in and sign-up.
Change your choice
You can change your mind at any time, in either direction. The "Manage cookies" link sits at the bottom of every page of the site.

