Cookie Policy

Last updated: 24 July 2026

This policy explains how Velometry (velometry.cc) uses cookies. Cookies are small text files a website stores in your browser. We keep our use of them to the strict minimum needed to run the service.

The cookies we use

We use two strictly necessary cookies to run the service, and — only if you opt in — Google Analytics cookies to understand anonymous, aggregate usage. Nothing we set is used for advertising, profiling, or selling data.

Cookie Purpose Type Retention
Session cookie (PHP session, e.g. PHPSESSID) Keeps you signed in after you connect with Strava, and carries the anti-forgery (CSRF) token that protects form submissions. The CSRF token is held inside this session — there is no separate CSRF cookie. Strictly necessary · first-party Session — cleared when you close your browser or when the session expires
Consent cookie (velometry_consent, velometry_consent_v) Remembers whether you accepted or rejected analytics cookies, so we don't ask on every page and only load Google Analytics if you agreed. Strictly necessary · first-party 180 days
Google Analytics (_ga, _ga_<id>) Set by Google Analytics 4 only after you click "Accept all". Measures anonymous, aggregate usage (pages viewed, rough visitor counts) so we can improve the site. Until you opt in, Analytics runs in a cookieless consent-denied mode and sets no _ga cookies. Analytics · third-party (Google) Up to 2 years (managed by Google)

The strictly necessary cookies are SameSite=Lax and served as Secure over HTTPS; the session cookie is also HttpOnly (not readable by JavaScript).

What we do not use

Beyond the analytics cookies above, Velometry sets no advertising, marketing, or social-media cookies, and embeds no other third-party tracking scripts. We do not build advertising profiles, we do not use your data for targeted advertising, and we do not sell data. Google Analytics is configured with Google Consent Mode v2 and advertising signals disabled.

Do we need your consent?

For the two strictly necessary cookies — no. Under the EU ePrivacy Directive and the GDPR, cookies strictly necessary to provide a service you explicitly requested (keeping you logged in, securing forms, remembering your cookie choice) are exempt from the consent requirement.

For Google Analytics — yes. Those cookies are non-essential, so we ask for your opt-in consent through the cookie banner before loading them. Analytics stays denied by default; nothing analytics-related runs until you choose "Accept all". You can change or withdraw your choice at any time via Cookie settings (also in the footer of every page) — withdrawing is as easy as giving consent.

Strava and third parties

Signing in sends you to Strava's own authorization page. Strava may set its own cookies there, governed entirely by Strava's Privacy and Cookie Policy, not by this document. Velometry never receives or stores your Strava password.

Managing cookies

You can view, block, or delete cookies through your browser settings. Note that blocking the session cookie will prevent you from signing in and using the admin panel, since the service cannot maintain a logged-in session without it.

Changes to this policy

We may update this policy if our use of cookies changes. The "last updated" date above always reflects the current version.

Contact

Questions about cookies or your data? See our Privacy Policy or get in touch at privacy@velometry.cc.