Cookie policy
Last updated: 9 August 2026
Strictly necessary cookies
Passmatch uses only session cookies, essential to your authentication. No analytics, advertising or tracking cookies. The service measures product usage with no cookie and no local storage: see “Measuring how the service is used” in the privacy policy.
Details
“access” cookie: session token (short-lived, about 15 minutes). “refresh” cookie: silent session renewal (about 30 days). httpOnly, Secure and SameSite=Lax. “pm_session” cookie: a plain flag holding “1”, which lets the page know a session exists without asking the server — this is what spares two pointless requests on every anonymous visit. It contains no identifier, authenticates nothing on its own, and is cleared on sign-out. Readable by the page (so not httpOnly), Secure and SameSite=Lax, same lifetime as the “refresh” cookie.
No consent banner
Cookies strictly necessary for a service you request are exempt from consent (CNIL guidelines); no banner is therefore required. Any introduction of a non-essential cookie would be announced here.