Cookie Policy
Last updated:
The short version
We set seven things on your device, and every one of them is needed for the portal to work: signing you in, keeping you signed in, protecting the sign-in and the site search from abuse, and letting our own editors preview drafts. We do not run advertising cookies, we do not send anything about your visit to an analytics company, and we do not embed anything that tracks you. There is nothing here to opt out of — which is why you have not seen a cookie banner.
If that changes, we will ask you first, and you will be able to say no.
What we store, and why
| What | Type | When it is set | How long it lasts | What it does |
|---|---|---|---|---|
| What__Host-cms_portal_session | TypeCookie | When it is setWhen you sign in | How long it lasts1 hour | What it doesKeeps you signed in. It holds a random reference to your session — never your name, email, or password. |
| What__Host-cms_portal_sso_state | TypeCookie | When it is setFor a few seconds during sign-in | How long it lasts1 minute | What it doesA one-time security check that stops someone from hijacking your sign-in. Deleted as soon as sign-in finishes. |
| Whatcms_portal_avatar | TypeLocal storage | When it is setAfter you sign in | How long it lastsUntil you sign out | What it doesRemembers that you are signed in and your initials, so your avatar appears instantly instead of flickering in. It holds only {signed in: yes, initials} — no name, email, account id, or token. Removed the next time you load a page here after signing out. |
| What__prerender_bypass | TypeCookie | When it is setOnly for our staff, previewing unpublished content | How long it lastsThe preview session | What it doesLets an editor see a draft page instead of the published one. |
| What__theme_draft | TypeCookie | When it is setOnly for our staff, previewing unpublished content | How long it lasts5 minutes | What it doesA signed, expiring pass authorising one specific draft preview. |
| Whatdisc_sid | TypeCookie | When it is setWhen you open the site search | How long it lastsUntil you close your browser | What it doesA random identifier for your search session. It protects the search service from abuse: each session gets its own request allowance. Only if you agree to analytics does the same identifier let us see which searches belonged to one visit; until then it is not used for that. It holds no name, email, account id or token. |
| Whatdisc_rl | TypeCookie | When it is setWhen you open the site search | How long it lastsUntil you close your browser (the pass inside expires after 24 hours) | What it doesA signed, expiring pass that proves your search requests belong to your session, so one abusive client cannot use up everyone’s allowance. Security only. |
All seven are set by us, on this site only. None of them are shared with anyone else, and none of them follow you to other websites.
What we do not do
- No advertising or marketing cookies. We do not run ad networks and we do not build advertising profiles.
- No third-party analytics. No Google Analytics, no Tag Manager, no product-analytics service — nothing about your browsing is sent to an analytics company. We do keep our own record of site searches — the search terms, the filters used, how many results came back, which results were shown and which one was clicked — so we can improve search. Those records are not tied to your search session unless you agree to analytics.
- No third-party embeds. No embedded YouTube or Vimeo players, no chat widgets, no social buttons — the usual sources of cookies set by other companies.
- No cross-site tracking, and no selling or sharing of personal information for advertising.
Our fonts are served from our own servers, so loading a page on this site does not tell any font provider that you were here.
Why there is no cookie banner
Under the EU ePrivacy rules, consent is needed to store things on your device unless they are strictly necessary for a service you asked for. Everything in the table above falls into that exception: signing in, keeping you signed in, protecting the sign-in and the search service from abuse, and letting our own editors preview drafts.
Asking for consent we do not need would mean showing you a choice that changes nothing — so instead we publish this page.
If we add analytics later
We will show a consent banner before setting anything optional, with a “Reject all” that is exactly as easy to click as “Accept all”, per-category switches that all start off, and a permanent “Cookie settings” link in the footer so you can change your mind or withdraw at any time. Until you agree, optional cookies will not be set — not set-then-deleted, simply never set.
Managing cookies yourself
You can delete or block cookies in your browser settings at any time. Blocking the two sign-in cookies above will stop you from being able to sign in — that is all they do, so there is no way around it.
Signing out ends the session your session cookie points to; the cookie itself lapses within the hour, and cms_portal_avatar is removed the next time you load a page here. Closing your browser clears the two search cookies.
Contact
Questions about this policy, or about how we handle personal data: office@cmsmasters.net
CMSMasters