What we do not do
primanza.com does not set cookies of any kind — not first-party, not third-party, not analytics, not advertising, not 'strictly necessary'. It does not write to local storage or session storage. It uses no pixels, web beacons, tracking scripts, session recording, heatmaps, device or browser fingerprinting, or any other technology that stores information on your device or reads information from it.
No third party is permitted to place such technology through this site, because no third-party script runs on it. The site's Content Security Policy enforces this at the browser level: it is a technical restriction, not just a promise in a document.
Why you are not seeing a banner
Article 5(3) of the ePrivacy Directive — the rule that actually governs cookies in Europe, as implemented in national law — requires consent before storing information on, or gaining access to information already stored in, a visitor's terminal equipment. This site does neither. There is nothing to consent to, so asking you to consent would be theatre.
The same reasoning covers the consent and opt-out requirements of the California Consumer Privacy Act and comparable US state laws: they attach to tracking, sale and sharing, none of which happens here.
How you can check
You do not have to take our word for it. Open your browser's developer tools, look at the Application or Storage panel, and browse this site. The cookie jar for primanza.com will be empty, local storage and session storage will be empty, and the Network panel will show requests to no origin but our own.
We would rather you verified this than trusted it. A privacy claim that cannot be checked is a marketing claim.
What still happens without cookies
Two things work without storing anything on your device, and it is worth being precise about them because they are the kind of detail a lazy policy omits:
- Language routing. When you arrive at a page without a language in the address, the site reads the Accept-Language header your browser already sends with every request and redirects you to the matching language. Nothing is stored, and no preference is remembered — the choice is recomputed from the request each time. Choosing a language from the switcher simply navigates you to that language's URL.
- Server logs. Our infrastructure records the request itself — address, page, timestamp, user-agent — as described in the Privacy Policy. This is a record on our server, not a file on your device, and cookie law does not govern it. Privacy law does, and the Privacy Policy sets out the basis and the retention.
Primanza products are different
A product with accounts needs, at minimum, a session cookie: that is how logging in works. Every Primanza product therefore sets the cookies its own function requires, publishes its own cookie policy inside the product, and obtains consent for any non-essential cookie where the law requires it.
That happens on the product's own subdomain, under the product's own policy. Because a Primanza product is addressed under primanza.com rather than at an unrelated domain, it is worth being exact about what that does and does not mean for cookies. Waving the question away would be describing a different architecture from the one we actually run.
- This site sets no cookie at all. So there is nothing set here for a product to read, whatever the domain relationship is. The one direction of leakage a shared parent domain could create does not exist, because the parent sets nothing.
- A product's cookies are scoped to the product's own host. They are issued for that subdomain and not for the parent domain, so they are not sent to primanza.com and not readable by another product's subdomain. Scoping a cookie to the parent domain would make it readable across every subdomain, which is precisely why no Primanza cookie is scoped that way.
- Sharing a parent domain does not share a session, an account or a database. Each product authenticates its own users against its own store. Being signed in to one product signs you in to nothing else.
- What a shared parent domain does mean, stated rather than hidden: subdomains of one registrable domain are same-site for the browser's purposes, so a cookie deliberately scoped to the parent would be visible across them. That is a design choice available to us, and this is us declining it and saying so, so that the claim can be checked rather than believed.
You can verify the first point on any page of this site in ten seconds — see the section above. The rest is verifiable on a product the moment one is published, in the same way: open the storage panel and read the domain each cookie is scoped to.
If this ever changes
We are not promising that this site will never need a cookie for the rest of time. We are committing to what happens if it does: a genuinely necessary cookie would be documented on this page, with its name, purpose, duration and provider, before it ships. A non-essential one would additionally require your prior consent, through a mechanism that makes refusing exactly as easy as accepting, and this page would say so.
Until this page says otherwise, the count is zero. Questions go to legal@primanza.com.