COOKIE POLICY

[DIRECTIVE] DISCLOSING STRICT NO-TRACKING STANDARDS, ESSENTIAL SESSION COOKIES, AND CONSENT-BASED ABUSE PREVENTION MECHANISMS.

GDPR & ePRIVACY COMPLIANT

1. ESSENTIAL SESSION COOKIES

+
ParseHook uses strictly necessary cookies to provide core authentication functionality. When you log into your ParseHook dashboard, our authentication provider (Supabase) issues a secure, encrypted JSON Web Token (JWT).
+
Purpose: This token is stored locally in your browser (via cookies or local storage) to keep you securely logged in and to authorize your requests to our backend. Without this token, accessing your secure dashboard would be impossible.
+
Legal Basis: Article six(one)(b) GDPR (Performance of a contract). This is a strictly necessary session cookie, which is exempt from requiring prior consent under the ePrivacy Directive.
+
Retention: This token remains active for the duration of your logged-in session and expires automatically, requiring you to log in again thereafter.

2. CONSENT-BASED ABUSE PREVENTION (FINGERPRINTING)

+
To protect our infrastructure and legitimate users from abuse, rate-limit evasion, and automated attacks on our Free tier, we may implement a privacy-preserving device fingerprinting mechanism.
+
Purpose: A cryptographic hash is generated based on non-identifying browser and device characteristics. This is used strictly for security, bot mitigation, and enforcing fair usage limits. It is not used to track you across third-party websites or build behavioral profiles.
+
Legal Basis: Article six(one)(a) GDPR (Consent). We only activate this fingerprinting mechanism if you explicitly grant consent via our cookie banner. If you decline, your access to the service remains unaffected, though you may be subject to stricter IP-based rate limits as an alternative abuse prevention measure.
+
Retention: The fingerprint hash is retained for a maximum of 30 days and then automatically deleted.
+
Withdrawal: You may withdraw your consent at any time via the cookie settings. Withdrawal does not affect the lawfulness of processing based on consent before withdrawal.

3. COOKIELESS WEB ANALYTICS (UMAMI)

+
We measure page performance and aggregate usage statistics using a self-hosted instance of Umami Analytics.
+
Privacy by Design: Umami does not use cross-site tracking cookies, does not store persistent identifiers in your browser, and does not track you across other websites. Your IP address is hashed and anonymized immediately upon connection to our servers.
+
Legal Basis: Because Umami operates without cookies and processes only anonymized, aggregated data, it falls outside the scope of the ePrivacy Directive's consent requirements. We process this data based on our legitimate interests in monitoring and improving system performance under Article six(one)(f) GDPR.

4. NO MARKETING OR ADVERTISING COOKIES

+
ParseHook does not use marketing, advertising, or social media tracking cookies. We do not sell your data to third parties, and we do not embed third-party tracking pixels (such as Facebook Pixel or Google Ads) on our website or dashboard.

5. MANAGING AND DELETING COOKIES

+
You have the right to decide whether to accept or reject cookies. You can exercise this right by setting your preferences in our cookie consent banner.
+
Additionally, you can manage or delete cookies directly through your browser settings at any time. If you delete all cookies on your device, you will be logged out of your ParseHook account and will need to sign in again. Links to manage cookies in popular browsers: