Cookie statement
Effective 9 July 2026
1. This site sets one cookie, and only when you sign in
There is no analytics, no tracking, and no advertising on compliancesme.com. The free assessment runs entirely in your browser and stores nothing unless you ask for your report or create an account.
When you sign in to your account we set a single cookie named csme_session. It keeps you signed in for 30 days, it is required for the site to work, and it carries nothing beyond your signed session. It is marked HttpOnly, Secure and SameSite=Lax, so no script can read it and it never travels over an unencrypted connection. Signing out removes it. Because it is strictly necessary to deliver a service you have asked for, it needs no consent banner.
2. Cookies set by our providers
Netlify hosts this site and may set strictly functional cookies needed to serve pages and process forms.
Cloudflare provides the verification box on the sign-in and contact forms, which tells a person apart from an automated script. It may set a cookie for that check.
Stripe sets cookies during checkout for payment processing and fraud prevention. These appear only when you go to pay.
3. Managing cookies
Your browser lets you block or delete cookies at any time. Blocking the session cookie will sign you out and prevent downloads, and blocking the Stripe cookies may prevent checkout from completing.