Cookie Policy

Last updated: September 2026

Overview

You won't see a cookie banner on droplana.com. That's not an oversight - it's because this site doesn't use cookies that require consent. This page explains, precisely, what that means for the marketing and blog pages you're reading now, and separately for the Droplana app itself, since the two work differently.

The Droplana website (marketing pages and blog)

The pages under droplana.com - the homepage, pricing, blog, and comparison pages - set no cookies at all. No visitor ID is created, and nothing is stored in your browser.

The only thing these pages do is send a single anonymous pageview beacon to our own server when you load a page. It's a first-party request, not a third-party script, and it doesn't set a cookie. Per page view, we log:

  • The page path you visited
  • The referring page, if any
  • Your browser's user agent string
  • A timestamp
  • Your IP address, with the last part removed (the last octet of an IPv4 address, or the last 80 bits of an IPv6 address) before anything is written down

That anonymized IP can't be reversed to your original address, and it isn't paired with a cookie or any other identifier, so we can't link separate page views back to the same visitor. The record goes into a server log, not a visitor database or a profile. Automated traffic - crawlers, bots, uptime monitors - is filtered out before it's logged at all.

We don't run Google Analytics, Meta Pixel, or any other third-party analytics or advertising script on these pages.

The Droplana app

Signing in and using the product - the business dashboard and the client portal - is different from browsing the marketing site, because a portal is a session-based product: it needs to know who's signed in from one request to the next. That requires a small number of cookies. All of them are first-party and strictly necessary to make the app work - none are used for advertising or cross-site tracking.

Cookie Purpose Duration
session_id Keeps a Business account signed in 31 days
csrf_token Protects signed-in requests from cross-site forgery Session-linked
portal_sid Keeps a Customer signed in to their portal 24 hours
portal_csrf_token Protects portal requests from cross-site forgery Session-linked
business_device Recognizes a returning device for one-click Business login 90 days
portal_device Recognizes a returning device for one-click portal login 90 days
lang Remembers your interface language 90 days
signer_name Prefills your typed name when signing a document About 1 year

None of these cookies are used to build advertising profiles, track you across other websites, or feed any analytics platform.

Under the ePrivacy Directive and GDPR, a consent banner is required for cookies that aren't strictly necessary for the service - typically analytics and advertising cookies. Droplana doesn't use either kind. The marketing site sets no cookies, and every cookie the app sets exists to keep you signed in, protect your session, or remember a preference you already set. All of them fall under the "necessary for the service you requested" exemption, so no consent prompt is required.

Third parties

No third-party cookies, scripts, or trackers run on droplana.com or in the app. The infrastructure and service providers that support the product - hosting, transactional email, payments - process account and billing data as sub-processors, not as trackers; see the sub-processor list in our DPA and Privacy Policy for details.

Managing cookies in your browser

You can view, block, or delete cookies through your browser's settings at any time. Since the app's cookies are what keep you signed in and remember your preferences, clearing them will sign you out of any active session and reset your saved language and device recognition.

Changes to this policy

We'll update this page if what we collect or how we collect it changes, and update the "Last updated" date above accordingly.

Contact

For questions about this policy, contact us at privacy@droplana.com.