Legal

Cookie policy

Every cookie we set and what it does.

Last updated 5 September 2026

In short

There is no consent banner on this site because there is nothing to consent to. We set no advertising cookies, no analytics cookies and no third-party trackers. The FlowFinds application sets one first-party cookie, ff_session, which identifies your session so that the product can tell one visitor from another, keep you signed in, and attribute a referral to the person who invited you.

Everything we set is listed below in full. If you find a cookie on one of our surfaces that is not on this list, tell us at [email protected] — that is a defect, not an omission from the policy.

The summary is not the agreement. Where it and a numbered clause differ, the clause governs.

Contents

  1. Scope
  2. Every cookie we set
  3. Cookies set by others
  4. Consent
  5. Controlling cookies

1. Scope

1.1 This policy covers the FlowFinds company site, the application and the documentation. It uses “cookie” to include local storage and any other means of storing or reading information on your device, which is how Hungarian Act C of 2003 and the ePrivacy Directive treat the question.

1.2 Storefronts generated for FlowFinds customers are operated by those customers. What a shop sets on its own domain is that shop’s responsibility and is covered by its own notice.

2. Every cookie we set

NameTypePurposeLifetime
ff_sessionFirst-party, strictly necessaryIdentifies the browser session. It is what holds a product you are looking at against you before you have an account, keeps you signed in after you follow a sign-in link, and records which referral link you arrived through so the person who invited you can be credited.Up to 1 year, or until you clear it

3. Cookies set by others

3.1 When you pay, you are taken to the payment provider’s own hosted page. That page is operated by the provider and may set cookies necessary to complete the payment and to prevent fraud, under the provider’s own policy. We cannot read them.

3.2 Requests to our surfaces pass through a network provider that may set a cookie for security and traffic management. Its role is described on sub-processors.

3.3 We embed no social widgets, no advertising pixels and no third-party fonts or scripts that would let another party observe your visit.

4. Consent

4.1 Strictly necessary cookies — those without which a service you asked for cannot be delivered — do not require consent under Article 5(3) of the ePrivacy Directive. Everything in clause 2 falls into that category.

4.2 If we ever introduce an analytics or advertising cookie, we will ask for consent before setting it, with refusal as easy as acceptance, and this page will say so before the change takes effect.

5. Controlling cookies

5.1 Every browser can block or delete cookies for a site. Blocking ff_session does not stop you reading these pages, but the application will not be able to sign you in or hold a product for you.

5.2 Clearing it also removes referral attribution, as clause 3 of the referral programme terms explains.

5.3 What the session identifier is used for as personal data, and how long the records behind it are kept, is set out in the privacy policy.

Questions about this document

Write to [email protected]. For a privacy request specifically, use [email protected], which reaches the same people faster. Every other document in this set is listed on the legal index, and the plain-English explanations of how we operate are under trust.