This Cookie Policy explains how noobtopro (noobto.pro) uses cookies and similar technologies — including browser localStorage, beacons, and device/network identifiers — and the choices you have. It supplements our Privacy Policy. The legal test is the act of storing or accessing information on your device, not the label "cookie", and it applies whether or not the information is personal data.
1. The categories we use
- Strictly necessary (always on). A small amount of browser storage we need to run the Service — keeping you signed in (Supabase authentication), remembering preferences such as your theme, and recording your own analytics choice (the consent record). These do not require consent, but we disclose them below.
- Analytics (off until you opt in). Privacy-friendly analytics that help us understand how the site is used and improve it. They load only after you accept(see "Your choices" below).
- Marketing / advertising. We do not use advertising or cross-site tracking cookies.
Importantly, the legal test is whether something is stored on or read from your device— not whether it sets a traditional “cookie”. A tool described as “cookieless” can still read or write localStorage or other device storage, so “cookieless” does not mean exempt from consent. We treat all three analytics tools below as consent-required for that reason.
2. Strictly-necessary storage (no consent needed)
We set the following before any consent because the Service cannot function without it. We disclose it here for transparency:
| Item | Provider | Purpose | Stored / accessed on device | Duration |
|---|---|---|---|---|
| Supabase authentication | Supabase, Inc. | Keeps you signed in and secures your session | Auth tokens in localStorage | Until you sign out or the session expires |
| Consent record | noobtopro (first-party) | Remembers your analytics choice so we don’t re-ask and don’t load analytics without consent | noobtopro:consent (“granted”/“denied”) in localStorage | Persistent until you change it or clear storage |
| Theme preference | noobtopro (first-party) | Remembers your light/dark theme | Theme value in localStorage | Persistent until you change it or clear storage |
3. Analytics technologies (consent-required)
These load only after you opt in, and never for visitors who decline. Each reads or writes information on your device, so each requires your consent:
| Tool | Provider | Purpose | Stored / accessed on device | Data collected | Retention | Transfer |
|---|---|---|---|---|---|---|
| Vercel Web Analytics | Vercel, Inc. (USA) | Aggregate, privacy-friendly page-view analytics; no cross-site tracking | Loads a script that reads/writes localStorage (e.g. the va-disable flag); no advertising cookies | Aggregated page views, referrer, approximate location, device/browser type | Aggregated; retained per Vercel’s analytics terms | United States — EU–US Data Privacy Framework (SCCs as a fallback) |
| Vercel Speed Insights | Vercel, Inc. (USA) | Anonymous performance measurement (load times, responsiveness) | Sends performance beacons; may read/write localStorage | Page-performance metrics and a transient device/route identifier | Aggregated; retained per Vercel’s analytics terms | United States — EU–US Data Privacy Framework (SCCs as a fallback) |
| Ahrefs Web Analytics | Ahrefs Pte. Ltd. (Singapore) | Privacy-friendly, “cookieless” traffic analytics | Loads a third-party script (analytics.ahrefs.com) that can read/write localStorage; “cookieless” ≠ no device access | Aggregated traffic metrics; a daily salted hash of IP + user-agent | Aggregated; retained per Ahrefs’ terms | United States (AWS) — Standard Contractual Clauses + Transfer Impact Assessment |
4. Your choices
For everything except strictly necessary technologies we ask for your prior, freely given, specific, informed consent before they run. Analytics is a single choice: when you first visit, a banner lets you Accept or Reject all analytics together. Rejecting is as easy as accepting, and refusing analytics does not reduce your access to the free or Pro tiers.
You can change or withdraw your choice at any time through "Cookie preferences"— available in the site footer and within the app — which reopens the banner so you can switch your choice; withdrawal is as easy as giving consent. We also honor the Global Privacy Control (GPC) browser signal as an opt-out — if your browser sends it, analytics stays off without you having to do anything.
You can additionally block or delete storage through your browser settings, though blocking strictly-necessary storage may prevent you from signing in.
5. International transfers
Our analytics providers process data outside the EU/EEA, in the United States. Where that happens we rely on appropriate safeguards: the EU–US Data Privacy Framework for Vercel, and the EU Standard Contractual Clauses (with a Transfer Impact Assessment) for Ahrefs. See our Sub-processors list and Privacy Policy for more.
6. Changes to this Policy
We may update this Policy as our technologies or the law change. We will revise the "Last updated" date and, for material changes, ask for your consent again.
7. Contact
Questions about this Policy: [email protected] — noobtopro, Cologne (Köln), Germany.