Cookie Policy
Cookie Policy
- Controller
- Martin Nikiforov, trading as Norppa
- Version
- 2.0
- Effective
- 11 August 2026
- Applies to
- norppa.co and its regional versions
- Companion document
- Privacy Policy
In one sentence
This website sets no cookies at all. It stores four small values in your own browser so that it remembers your language, and nothing else. There is no advertising, no cross-site tracking, and no third-party cookie of any kind.
We do now measure how many people visit, using a cookieless analytics tool that stores nothing whatsoever on your device. Section 3 names it, says exactly what it collects, and explains why that does not change anything about the cookies on this site — because there still are none.
You do not have to take our word for it. Section 10 shows you how to check it yourself in thirty seconds.
1. Why this document is not only about cookies
The law here is not actually about cookies. Section 205 of the Finnish Act on Electronic Communications Services (laki sähköisen viestinnän palveluista 917/2014), which implements Article 5(3) of the ePrivacy Directive 2002/58/EC, regulates storing information on, or gaining access to information already stored on, a user's terminal equipment — whatever the technology.
That covers cookies, but equally:
localStorageandsessionStorage- IndexedDB and Cache Storage
- service workers
- device fingerprinting
- pixels, beacons and tracking scripts
So this document covers everything the site puts on your device, not just the one technology people usually name. Where consent is required, GDPR Article 4(11) and Article 7 set the standard for what counts as consent.
2. Cookies we set
None.
| Cookie name | Purpose | Duration |
|---|---|---|
| — | We set no cookies | — |
That is not a simplification for readability. There is no Set-Cookie header on any response from
our server or our content delivery network, and no line of code in the site writes to
document.cookie. Section 10 explains how to confirm this.
3. Cookies set by third parties on our site
None. One third party runs code here, and it sets no cookie.
Since 15 August 2026 the site loads a visitor counter from SiteSights. It is 897 bytes of JavaScript. We read all of it before installing it, and this is what it does:
| Cookies set | None. |
localStorage / sessionStorage written |
None. Nothing at all is stored on your device. |
| What it sends | The page address, the page that referred you, and your screen width. |
| What it does not send | No user agent string, no canvas or font fingerprint, no timezone, no device identifier, no cross-site identifier. |
| Where it goes | app.sitesights.de, in Germany. Inside the EU, so no third-country transfer. |
| Your IP address | Reaches the collector as part of any HTTP request, and is processed there. This is the only personal data involved. |
Because nothing is stored on or read from your device, Article 5(3) of the ePrivacy Directive — the rule that makes cookie banners necessary — does not apply to it, and no consent is required for that storage. The processing of your IP address rests on our legitimate interest in knowing whether anyone reads this site (Article 6(1)(f) GDPR). You can object to it at any time under Article 21; Section 12 says how.
Apart from that: there is no Google Analytics, no Google Tag Manager, no Meta Pixel, no LinkedIn Insight Tag, no Hotjar, no chat widget, no embedded YouTube or Vimeo player, no social media plugin, no A/B testing tool, no consent management platform, and no advertising network.
Our social media links in the footer are ordinary links. They set nothing until you click them, and then you are on that company's website under their rules, not ours.
4. What we do store on your device
Four values in localStorage, and one in sessionStorage. All are first-party, none contains an
identifier, and none is transmitted to us — they exist only in your browser and are readable only
by norppa.co.
| Key | Where | What it holds | Set when | Lifetime |
|---|---|---|---|---|
norppa.locale |
localStorage | The language and region you chose, e.g. fi-fi |
When you pick a region, or confirm the one we suggest | Until you clear it |
norppa.locale.asked |
localStorage | The single character 1, recording that we already asked you about your region |
Only after you answer the region prompt — never merely on page load | Until you clear it |
norppa.cookie.consent |
localStorage | accepted or declined, recording your answer to the storage notice |
When you answer the notice | Until you clear it |
norppa.festive |
localStorage | A flag for a seasonal variant of the front page heading | Seasonally | Until you clear it |
tsr-scroll-restoration-v1_3 |
sessionStorage | Your scroll position per page, so the browser Back button returns you to where you were | On navigation | Deleted when you close the tab |
Is consent needed for these? No. Under section 205(2) of Act 917/2014, storage is exempt from the consent requirement when it is strictly necessary to provide a service the user has expressly requested. Remembering the language version you selected, not asking you the same question twice, and returning you to your place on the page when you press Back are all in that category. None of them tracks you, builds a profile, or leaves the browser.
We rely on legitimate interests under GDPR Article 6(1)(f) for the corresponding processing, and the balancing assessment is in section 6 of the Privacy Policy.
One additional item, for us only. When the site administrator signs in to the private admin
console, Supabase Authentication stores a session token in localStorage under a key beginning
sb-. This appears only after a successful administrator login. It never appears for a visitor,
and there is no login form on any public page.
5. What we do not do, stated precisely
| Analytics or visitor measurement | Cookieless only. We count page views through SiteSights, which stores nothing on your device. We do not build profiles, do not track you between visits, and cannot tell one returning visitor from two new ones. See Section 3. |
| Advertising and remarketing | None. No ad networks, no audience lists, no conversion pixels. |
| Cross-site tracking | None. Nothing on this site can follow you to another site. |
| Fingerprinting | None. We do not read canvas, fonts, audio or WebGL. Screen width is sent as a number, so we know how many visitors are on phones; it is not combined with anything else and cannot identify you. |
| Profiling | None. See Article 22 and section 11 of the Privacy Policy. |
| Selling or sharing data | Never. |
| Service workers, Cache Storage, IndexedDB | None used. Verified empty. |
6. Third parties your browser does contact
No cookies, but a complete account of every network request the site makes, because "we set no cookies" would be an incomplete answer on its own. Loading a file from another server always discloses your IP address and browser type to that server, cookie or not.
| Host | Who operates it | Where | What it is for | Sets a cookie? |
|---|---|---|---|---|
norppa.co |
Hetzner Online GmbH, for us | Frankfurt, Germany | The site itself | No |
cdn1.norppa.co |
Bunny.net (Bunny.net d.o.o., Slovenia), for us | Edge in Finland, storage in Sweden | Our logo, favicon and social preview image | No — verified in the response headers |
…supabase.co |
Supabase, for us | Frankfurt, Germany | Loading news and page content, and the country lookup in section 7 | No |
…b-cdn.net / …vxdgroup-cloud.xyz |
Bunny.net, for us, over our own storage | Edge in Finland, storage in Germany | Images attached to news articles. vxdgroup is our former name; the domain has not been migrated yet |
No — verified |
images.unsplash.com |
Unsplash Inc., independently | United States (served via imgix) | Four decorative photographs | No — verified. Your IP address is disclosed, nothing is stored on your device |
Our CDN keeps no logs of you. Request logging is switched off on our Bunny.net zones, with IP anonymisation enabled, so there is no per-visitor record of what you loaded from the CDN.
Fonts are ours. The Montserrat typeface is served from our own server. We deliberately do not
load it from fonts.googleapis.com, because doing so would disclose every visitor's IP address to
Google LLC in the United States before you could have any say in it.
Avoiding Unsplash entirely. The four photographs are decorative. Blocking
images.unsplash.com in your browser or an extension removes that request with no effect on
anything you came here to read.
7. Country detection, without storing anything
To suggest the right language version, and to keep the Russian regional version limited to visitors
in Russia, we read a two-letter country code that our CDN attaches to the request
(cdn-requestcountrycode). Your IP address passes through the function that reads that header. It
is never logged, never written down and never stored, by us or by the function. The country code
itself is used to produce one response and then discarded.
This involves no storage on your device and therefore no consent requirement under section 205.
8. If you pay an invoice
Card payments happen on Stripe's own hosted checkout page. We do not embed Stripe.js, so no
Stripe cookie is ever set on norppa.co. When you follow the payment link you leave our site: you are
then on checkout.stripe.com, where Stripe sets its own cookies as the controller for that page,
under Stripe's cookie policy and not ours.
We never see or store your card number. What comes back to us is the outcome and a payment reference. See section 5.7 of the Privacy Policy.
9. The notice you may have seen, and what it actually does
On your first visit you may see a small panel telling you that the site sets no cookies, with Accept and Decline.
We want to be straight with you about this, because a choice that quietly does nothing is exactly the kind of design the European Data Protection Board criticises in its Guidelines 03/2022 on deceptive design patterns:
- Neither button changes what is stored. Whichever you press, the site continues to behave identically, because everything it stores is exempt from consent under section 205(2) as described in section 4. There is no non-essential storage to switch off.
- Your answer is itself recorded in
norppa.cookie.consent, so we do not ask again. - Declining costs you nothing. No feature is withheld, no content is hidden, nothing is degraded.
In other words: it is a notice, not a gate. We would rather tell you that plainly than let the two buttons imply a control that does not exist. If we ever introduce storage that genuinely does require consent, the panel will become a real, granular choice with opt-in defaulting to off, and Accept and Decline will be equally prominent, as Article 7(4) and Recital 32 require.
10. Verify all of this yourself
Do not trust a cookie policy that cannot be checked. In your browser:
Chrome or Edge: press F12 → Application tab → Storage in the sidebar.
Firefox: press F12 → Storage tab.
Safari: enable Develop in Settings → Advanced, then Develop → Show Web Inspector → Storage.
You should see:
- Cookies →
norppa.co— empty. - Local Storage →
norppa.co— thenorppa.*keys from section 4, and nothing else. - Session Storage → one
tsr-scroll-restorationentry. - IndexedDB, Cache Storage, Service Workers — all empty.
Or paste this into the browser console on any page of the site:
console.log({ cookies: document.cookie || "(none)", localStorage: {...localStorage} });
If what you see does not match this document, that is a bug in our honesty and we want to hear about it: hello@norppa.co.
11. Controlling and deleting what is stored
Delete it now, from the console:
localStorage.clear(); sessionStorage.clear(); location.reload();
Or through your browser: clearing site data for norppa.co removes everything in section 4. The only consequence is that the site will ask about your region again and will have forgotten your language choice.
Block it in advance: browser settings that block site data for norppa.co are fine. The site handles unavailable storage without breaking — every read and write is wrapped so that a refusal is simply ignored. Your language will just not be remembered between visits.
Private or incognito windows: everything in section 4 disappears when you close the window.
12. Do Not Track and Global Privacy Control
We have nothing to switch off in response to a Do Not Track header or a Global Privacy Control signal, because we do not track anyone and we sell no data. Both signals are therefore honoured by default and permanently, rather than by exception.
We do honour prefers-reduced-motion, which is a different kind of signal but the same principle:
if your device tells us what you want, we listen.
13. What would have to happen before this page changes
If we ever add anything that stores non-essential data on your device or discloses your behaviour to a third party, then before it goes live we will:
- update this document and raise its version number;
- replace the notice in section 9 with a genuine consent mechanism — separate opt-in per purpose, all toggles off by default, Accept and Decline equally prominent, and withdrawal as easy as giving consent (Article 7(3));
- store nothing beyond the strictly necessary until you have actively opted in.
We said in version 2.0 that we would not quietly add analytics and update this page afterwards. We have kept that: the analytics described in Section 3 and this page changed in the same release, on the same day, and the version history below records it. Nothing was live before it was written down.
14. Version history
| Version | Date | Change |
|---|---|---|
| 1.0 | 25 July 2026 | First publication |
| 2.1 | 15 August 2026 | Cookieless visitor measurement (SiteSights) added, and this page updated in the same release. Documented what the script collects, what it does not, where the data goes and why no consent gate is required for it. Still zero cookies. |
| 2.0 | 11 August 2026 | Rewritten after a full technical audit of the site. Confirmed zero cookies by three independent methods; documented every browser-storage key and every network recipient by name and location; recorded that third-party font loading has been removed; disclosed plainly that the Accept/Decline notice does not change what is stored. |
15. Contact
Questions about anything on this page, including a challenge to any statement in it:
Martin Nikiforov, trading as Norppa Leksankuja 3, 01700 Vantaa, Finland hello@norppa.co
You may also complain to the Finnish supervisory authority at any time:
Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto) Lintulahdenkuja 4, 00530 Helsinki · PL 800, 00531 Helsinki, Finland +358 29 566 6700 · tietosuoja@om.fi
Legal basis for this document
- Directive 2002/58/EC (ePrivacy), Article 5(3)
- Finnish Act on Electronic Communications Services (917/2014), section 205
- Regulation (EU) 2016/679 (GDPR), Articles 4(11), 6, 7, 12–13
- Finnish Data Protection Act (1050/2018)
- CJEU, Planet49, C-673/17 — pre-ticked boxes are not consent
- EDPB Guidelines 03/2022 on deceptive design patterns in social media platform interfaces
- EDPB Guidelines 05/2020 on consent under Regulation 2016/679
This document states how Norppa handles storage on your device. It is a statement of our own practice, not legal advice to you.