Cookie policy

Last updated: 9 August 2026

This cookie policy describes how PuroCRM Oy ("PuroCRM") uses cookies and similar technologies on purocrm.fi and in the PuroCRM service. It complements the Privacy Policy.

1. What is a cookie

A cookie is a small text file, or a similar technical identifier, that is stored on the user's terminal device or used to access information already stored on it. Section 205 of the Finnish Act on Electronic Communications Services (917/2014) and Article 5(3) of the ePrivacy Directive (2002/58/EC) apply both to traditional cookies and to similar technologies such as tracking pixels and local storage.

2. How we use cookies

We use cookies for the technical operation of the service, for security, and to remember user-selected preferences. We do not use marketing or targeting cookies, nor cross-site tracking. As an exception, contact and partner-application forms use Cloudflare Turnstile bot protection, which may set Cloudflare cookies or similar identifiers on those form pages only.

3. Cookie categories

3.1 Strictly necessary cookies

Cookies without which the requested service cannot function properly - sign-in session, CSRF protection, and the user-activated "remember me" feature. Under Section 205 TSL these do not require consent where storage is necessary for transmission of a communication or for providing a service the user has explicitly requested.

3.2 Functional cookies

Remember user preferences such as language, light/dark appearance and sidebar state. Because the service functions in its basic form without these cookies, we treat them as consent-based.

3.3 Analytics

PuroCRM collects anonymous, aggregated website visitor statistics using a server-side mechanism that does not use cookies, does not store IP addresses, and does not perform individual user tracking. Only aggregate page-view counts are retained, broken down by page, date, device type (mobile/desktop), referrer domain and country. No information is stored on or read from the visitor's terminal device for analytics purposes, so Section 205 TSL does not apply and no consent is required.

3.4 Marketing and targeting cookies

Not in use.

3.5 Bot protection on forms (Cloudflare Turnstile)

On the contact (/contact) and partner-application (/partners) forms we use Cloudflare Turnstile to prevent spam and automated bot traffic. Turnstile may set Cloudflare cookies or similar identifiers (e.g. cf_clearance, __cf_bm) on the user's terminal device. These are set only on form pages, not site-wide. Processing is based on legitimate interest (GDPR 6(1)(f)); see the Privacy Policy and Cloudflare's privacy policy for details.

4. Cookies we use

Name Set by Category Purpose Duration Consent
purocrm-sessionPuroCRMStrictly necessarySign-in session120 minNot required
XSRF-TOKENPuroCRMStrictly necessaryCSRF protectionSessionNot required
remember_web_*PuroCRMStrictly necessary"Remember me" feature~5 yearsUser-activated
localePuroCRMFunctionalRemember language choice1 yearConsent required
appearancePuroCRMFunctionalLight/dark theme1 yearConsent required
sidebar:statePuroCRMFunctionalRemember sidebar state1 yearConsent required
cf_clearance, __cf_bm (Turnstile)CloudflareStrictly necessary (form)Bot protection on contact and partner formsAs set by CloudflareNot required (strict-necessity exemption, Section 205 TSL)
cookie_consentPuroCRMStrictly necessaryRemember cookie-consent state12 monthsNot required

5. Giving, changing and withdrawing consent

On the first visit we display a cookie banner with three options: Accept all, Reject all, and Customise settings. Only strictly necessary cookies are set before a choice is made. Storing non-necessary cookies requires an active action - merely browsing or scrolling does not constitute consent (EDPB Guidelines 05/2020).

You can change or withdraw your consent at any time via the footer link "Cookie settings". Withdrawing consent is as easy as giving it (GDPR Art. 7(3)). You may also delete cookies via your browser settings - note, however, that blocking strictly necessary cookies may prevent sign-in and break the service.

6. Email open and click tracking

Campaign emails sent through PuroCRM may contain open- and click-tracking using signed first-party tokens. This tracking does not use cookies or third-party services. The tenant sending the campaign is the controller for that tracking; PuroCRM acts as its processor (see section 11 of the Privacy Policy).

7. Changes to this policy

We update this cookie policy whenever there are material changes to the cookies we use, their purposes or consent management. Introducing any new non-necessary cookie always requires fresh consent.