Last updated:
Cookie Policy
1. Introduction
This Cookie Policy explains the cookies and similar technologies (local storage, SDK identifiers) used by the Cookrange website (cookrangeapp.com) and mobile app. For how personal data is processed generally, see our Privacy Policy.
analytics_storage signal stays "denied" and Google Analytics places no cookie and collects no data — see §5 below. Meta Pixel isnot yet integrated; it appears in the table below, labelled "not yet active", to document in advance and transparently what cookies would appear once it is added.2. What Are Cookies?
Cookies are small text files placed in your browser when you visit a website; they let the site remember you, store your preferences, or gather usage statistics. In the mobile app, the equivalent role is played by local storage and device/install identifiers used by SDKs; in this policy, "cookie" is used to cover both.
3. Cookie Categories
- Strictly necessary: required for core functions like logging in, security, and form submission; these do not require consent and cannot be turned off.
- Analytics: help us understand how the site/app is used (e.g. which pages are visited); these activate only with your explicit consent.
- Marketing: used to measure ad performance and deliver personalized advertising; these activate only with your explicit consent.
4. Cookie Inventory
| Name | Provider | Purpose | Duration | Party | Category |
|---|---|---|---|---|---|
cr_consent | Cookrange | Remembers your cookie/consent choice (Consent Mode v2 state) | 12 months | First-party | Strictly necessary |
cr_lang_pref | Cookrange | Remembers your language preference (Türkçe/English) | 12 months | First-party | Strictly necessary |
cf_turnstile / cf_clearance | Cloudflare Turnstile — not yet integrated, not active | Verifies the waitlist form against bots/abuse | Session (minutes) | Third-party (challenges.cloudflare.com) | Strictly necessary |
_clck | Microsoft Clarity — active (only after consent) | Recognises the same visitor across page views and sessions via an anonymous ID | 12 months | First party | Analytics (only after consent) |
_clsk | Microsoft Clarity — active (only after consent) | Joins page views from the same session into a single session recording | 1 day | First party | Analytics (only after consent) |
_ga | Google Analytics 4 — active (Consent Mode v2, only set post-consent) | Distinguishes visitors for statistical purposes | 2 years (GA4 default) | Third-party | Analytics (post-consent only) |
_ga_<container-id> | Google Analytics 4 — active (Consent Mode v2, only set post-consent) | Measures session state and engagement | 2 years (GA4 default) | Third-party | Analytics (post-consent only) |
_gcl_au | Google Ads / GTM — planned, not yet active | Conversion-linking cookie | 90 days | Third-party | Marketing (post-consent only) |
_fbp | Meta Pixel — if used, not yet active | Browser identification, ad performance measurement | 90 days | Third-party | Marketing (post-consent only) |
_fbc | Meta Pixel — if used, not yet active | Stores ad click identifier | 90 days | Third-party | Marketing (post-consent only) |
Durations above are the providers' published general defaults. The GA4 rows now reflect real Consent Mode v2 behaviour; the remaining marketing rows (Google Ads/GTM conversion linking, Meta Pixel) will be updated with real IDs and confirmed durations once those integrations are added.
5. Consent Management (Google Consent Mode v2)
Cookrange manages Google Analytics/Google Tag Manager through Google Consent Mode v2: until you explicitly consent, the analytics_storage signal stays "denied," and Google Analytics places no cookie and collects no data. Once you consent, this signal switches to "granted"; withdrawing your choice returns it to "denied" immediately. Thead_storage, ad_user_data, and ad_personalization signals stay permanently "denied" — Cookrange runs no advertising and the consent banner has no marketing/ads category at all; these signals only become updatable once a real advertising integration (e.g. Google Ads, Meta Pixel) is added alongside a separate consent category for it. See src/scripts/consent.ts and public/analytics-boot.js for the implementation.
6. How to Manage Cookies
You can change your analytics-cookie preference at any time — withdrawing consent is as easy as giving it:
When you withdraw consent, Clarity's cookies (_clck, _clsk) are deleted and tracking stops; on the Google Analytics side, the analytics_storage signal returns to "denied" at the same moment, and no further data is collected or cookie placed from that point on (any _ga cookie already set while you had consented may remain in your browser until removed through your own browser settings, but Google no longer reads or updates it). You can also manage cookies through your browser settings (blocking/deleting cookies). Blocking strictly-necessary cookies may break some core functionality of the Service (e.g. remembering your language preference, submitting forms).
7. Third-Party Cookies
Some cookies are placed by providers other than Cookrange (Google, Meta, Cloudflare) and are subject to those providers' own privacy policies. See our current list of providers on theSub-Processors page.
8. Changes
This policy will be updated to reflect the real cookie inventory once the planned analytics integration is complete. The current version is always published with the date shown at the top of this page.
9. Contact
Questions about cookies can be sent to contact@cookrangeapp.com.