Cookie policy
Last updated: 9 August 2026
This cookie policy describes how PuroCRM Oy ("PuroCRM") uses cookies and similar technologies on purocrm.fi and in the PuroCRM service. It complements the Privacy Policy.
1. What is a cookie
A cookie is a small text file, or a similar technical identifier, that is stored on the user's terminal device or used to access information already stored on it. Section 205 of the Finnish Act on Electronic Communications Services (917/2014) and Article 5(3) of the ePrivacy Directive (2002/58/EC) apply both to traditional cookies and to similar technologies such as tracking pixels and local storage.
2. How we use cookies
We use cookies for the technical operation of the service, for security, and to remember user-selected preferences. We do not use marketing or targeting cookies, nor cross-site tracking. As an exception, contact and partner-application forms use Cloudflare Turnstile bot protection, which may set Cloudflare cookies or similar identifiers on those form pages only.
3. Cookie categories
3.1 Strictly necessary cookies
Cookies without which the requested service cannot function properly - sign-in session, CSRF protection, and the user-activated "remember me" feature. Under Section 205 TSL these do not require consent where storage is necessary for transmission of a communication or for providing a service the user has explicitly requested.
3.2 Functional cookies
Remember user preferences such as language, light/dark appearance and sidebar state. Because the service functions in its basic form without these cookies, we treat them as consent-based.
3.3 Analytics
PuroCRM collects anonymous, aggregated website visitor statistics using a server-side mechanism that does not use cookies, does not store IP addresses, and does not perform individual user tracking. Only aggregate page-view counts are retained, broken down by page, date, device type (mobile/desktop), referrer domain and country. No information is stored on or read from the visitor's terminal device for analytics purposes, so Section 205 TSL does not apply and no consent is required.
3.4 Marketing and targeting cookies
Not in use.
3.5 Bot protection on forms (Cloudflare Turnstile)
On the contact (/contact) and partner-application (/partners) forms we use Cloudflare Turnstile to prevent spam and automated bot traffic. Turnstile may set Cloudflare cookies or similar identifiers (e.g. cf_clearance, __cf_bm) on the user's terminal device. These are set only on form pages, not site-wide. Processing is based on legitimate interest (GDPR 6(1)(f)); see the Privacy Policy and Cloudflare's privacy policy for details.
4. Cookies we use
| Name | Set by | Category | Purpose | Duration | Consent |
|---|---|---|---|---|---|
purocrm-session | PuroCRM | Strictly necessary | Sign-in session | 120 min | Not required |
XSRF-TOKEN | PuroCRM | Strictly necessary | CSRF protection | Session | Not required |
remember_web_* | PuroCRM | Strictly necessary | "Remember me" feature | ~5 years | User-activated |
locale | PuroCRM | Functional | Remember language choice | 1 year | Consent required |
appearance | PuroCRM | Functional | Light/dark theme | 1 year | Consent required |
sidebar:state | PuroCRM | Functional | Remember sidebar state | 1 year | Consent required |
cf_clearance, __cf_bm (Turnstile) | Cloudflare | Strictly necessary (form) | Bot protection on contact and partner forms | As set by Cloudflare | Not required (strict-necessity exemption, Section 205 TSL) |
cookie_consent | PuroCRM | Strictly necessary | Remember cookie-consent state | 12 months | Not required |
5. Giving, changing and withdrawing consent
On the first visit we display a cookie banner with three options: Accept all, Reject all, and Customise settings. Only strictly necessary cookies are set before a choice is made. Storing non-necessary cookies requires an active action - merely browsing or scrolling does not constitute consent (EDPB Guidelines 05/2020).
You can change or withdraw your consent at any time via the footer link "Cookie settings". Withdrawing consent is as easy as giving it (GDPR Art. 7(3)). You may also delete cookies via your browser settings - note, however, that blocking strictly necessary cookies may prevent sign-in and break the service.
6. Email open and click tracking
Campaign emails sent through PuroCRM may contain open- and click-tracking using signed first-party tokens. This tracking does not use cookies or third-party services. The tenant sending the campaign is the controller for that tracking; PuroCRM acts as its processor (see section 11 of the Privacy Policy).
7. Changes to this policy
We update this cookie policy whenever there are material changes to the cookies we use, their purposes or consent management. Introducing any new non-necessary cookie always requires fresh consent.