Cookie policy
Last updated: 24 September 2026
This cookie policy describes how PuroCRM Oy ("PuroCRM") uses cookies and similar technologies on purocrm.fi and in the PuroCRM service. It complements the Privacy Policy.
1. What is a cookie
A cookie is a small text file, or a similar technical identifier, that is stored on the user's terminal device or used to access information already stored on it. Section 205 of the Finnish Act on Electronic Communications Services (917/2014) and Article 5(3) of the ePrivacy Directive (2002/58/EC) apply both to traditional cookies and to similar technologies such as tracking pixels and local storage.
2. How we use cookies
We use cookies for the technical operation of the service, for security, and to remember user-selected preferences. We do not use cross-site tracking and we do not disclose tracking data to advertising networks. On the marketing site we additionally use Leadfeeder visitor identification, which is third-party tracking and requires consent (section 3.4); it is not loaded before consent is given. Contact and partner-application forms use Cloudflare Turnstile bot protection, which sets no cookies on our site (section 3.5).
3. Cookie categories
3.1 Strictly necessary cookies
Cookies without which the requested service cannot function properly - sign-in session, CSRF protection, and the user-activated "remember me" feature. Under Section 205 TSL these do not require consent where storage is necessary for transmission of a communication or for providing a service the user has explicitly requested.
3.2 Functional cookies
Remember user preferences such as language, light/dark appearance, sidebar state and interface scale. These are set only when the user themselves selects a language, a theme, a sidebar state or an interface scale. Storing them is then necessary in order to provide the very function the user explicitly requested, so under section 205 of the Act on Electronic Communications Services no separate consent is required. We do not use these identifiers for tracking, for profiling, or for any other purpose.
3.3 Analytics
PuroCRM collects anonymous, aggregated website visitor statistics using a server-side mechanism that does not use cookies, does not store IP addresses, and does not perform individual user tracking. Only aggregate page-view counts are retained, broken down by page, date, device type (mobile/desktop), referrer domain and country. No information is stored on or read from the visitor's terminal device for analytics purposes, so Section 205 TSL does not apply and no consent is required.
3.4 Marketing and visitor identification
On our marketing site we use Leadfeeder visitor identification. Leadfeeder's script is a third-party tracking technology: it stores the first-party cookie _lfa (visitor / client id) and the LocalStorage values _lfa and _lfa_expiry on the terminal device, and infers, from that identifier and the IP address, which company is visiting the site. The identification is at company level - the purpose is to know which organisation visited the site, not which individual person. Leadfeeder's documentation states that the tracker does not use third-party cookies.
We classify this as requiring consent (section 205 of the Act on Electronic Communications Services; GDPR Art. 6(1)(a)). The script is not loaded and its identifiers are not set on your device before you have given consent under section 5. Withdrawing consent deletes Leadfeeder's identifiers from your device and stops the script from loading on the next page load. We do not use Leadfeeder's Consent Mode: without cookie consent their tracker would still identify companies. The purpose of the processing, the recipients and the retention are described in the Privacy Policy.
Visitor identification is also available as a feature of the PuroCRM service, where a customer company (tenant) connects its own Leadfeeder account to its own website. In that case that tenant is the controller and is responsible for cookie consent on its own site; this policy does not cover it.
3.5 Bot protection on forms (Cloudflare Turnstile)
On the contact (/contact) and partner-application (/partners) forms we use Cloudflare Turnstile to prevent spam and automated bot traffic. Turnstile sets no cookies on purocrm.fi. The cookies cf_clearance and __cf_bm belong to Cloudflare's bot management and firewall and are set only on sites served through Cloudflare's proxy; our site is not behind it, so they are not set. The widget is loaded from Cloudflare's own address challenges.cloudflare.com, and Cloudflare may set its own identifiers on its own domain. Loading it also discloses the visitor's IP address to Cloudflare - a data protection matter rather than a cookie one. Processing is based on legitimate interest (GDPR 6(1)(f)); see the Privacy Policy and Cloudflare's privacy policy for details.
4. Cookies we use
| Name | Set by | Category | Purpose | Duration | Consent |
|---|---|---|---|---|---|
purocrm-session | PuroCRM | Strictly necessary | Sign-in session | 8 h | Not required |
XSRF-TOKEN | PuroCRM | Strictly necessary | CSRF protection | Session (8 h) | Not required |
remember_web_* | PuroCRM | Strictly necessary | "Remember me" feature | ~5 years | User-activated |
locale | PuroCRM | Functional | Remember language choice | 1 year | Chosen by the user |
appearance | PuroCRM | Functional | Light/dark theme | 1 year | Chosen by the user |
sidebar_state | PuroCRM | Functional | Remember sidebar state | 7 days | Chosen by the user |
ui_scale | PuroCRM | Functional | Remember interface scale | 1 year | Chosen by the user |
cookie_consent | PuroCRM | Strictly necessary | Remember cookie-consent state | 12 months | Not required |
_lfa | Leadfeeder | Marketing and visitor identification | Web Visitors visitor / client id, used to recognise repeat visits by the same browser for company-level identification (marketing site only) | 1 year | Consent required |
_lfa_test_cookie_stored | Leadfeeder | Marketing and visitor identification | Temporary test of whether the browser accepts cookies | Expires immediately | Consent required |
_lfa (LocalStorage) | Leadfeeder | Marketing and visitor identification | The same visitor id in the browser's LocalStorage, so that it survives the cookie being removed | 1 year (as set by _lfa_expiry) | Consent required |
_lfa_expiry (LocalStorage) | Leadfeeder | Marketing and visitor identification | Stores the visitor-id lifetime in the browser's LocalStorage | 2 years | Consent required |
5. Giving, changing and withdrawing consent
On the first visit to the marketing site we display a cookie banner with three options: Accept all, Reject all, and Manage settings. The settings offer two categories: strictly necessary (always on, no consent required) and marketing and visitor identification (off by default). Only strictly necessary cookies are set before a choice is made. Storing non-necessary cookies requires an active action - merely browsing or scrolling does not constitute consent (EDPB Guidelines 05/2020).
You can change or withdraw your consent at any time via the footer link "Manage cookie settings". Withdrawing consent is as easy as giving it (GDPR Art. 7(3)). Withdrawal deletes Leadfeeder's identifiers from cookies and from the browser's LocalStorage and SessionStorage - every key beginning with _lfa, including _lfa, _lfa_test_cookie_stored and _lfa_expiry - and reloads the page so the script is not loaded again. You may also delete cookies via your browser settings - note, however, that blocking strictly necessary cookies may prevent sign-in and break the service.
A stored choice covers only the categories that existed when it was made. If we later introduce a new category, an earlier choice is not treated as consent to it; we ask again.
6. Email open and click tracking
Campaign emails sent through PuroCRM may contain open- and click-tracking using signed first-party tokens. This tracking does not use cookies or third-party services. The tenant sending the campaign is the controller for that tracking; PuroCRM acts as its processor (see section 11 of the Privacy Policy).
7. Changes to this policy
We update this cookie policy whenever there are material changes to the cookies we use, their purposes or consent management. Introducing any new non-necessary cookie always requires fresh consent.