PageWren Back to pagewren.com
Legal

Cookie policy

Last updated: 20 August 2026

Draft — not yet reviewed by a lawyer. This cookie policy is a working draft. A legal review is planned; until it has taken place, this document does not claim to have been prepared or checked by a lawyer.

This cookie policy explains which cookies and similar techniques pagewren.com and the PageWren client portal (portal.pagewren.com) use, what we use them for, and how you can manage them. It supplements our privacy statement and is based on art. 11.7a of the Dutch Telecommunications Act (Telecommunicatiewet) and the General Data Protection Regulation (GDPR).

1. Who is responsible?

Picazzo Research & Development (trade name PicazzoLabs; PageWren is a PicazzoLabs service), Zinkstraat 24, Box C4687, 4823 AD Breda, the Netherlands — KvK 42060545, VAT NL005464235B85 — is the controller for the personal data processed through cookies and similar techniques on this website and the client portal. Contact: [email protected] (privacy and rights requests: [email protected]).

2. What are cookies and similar techniques?

A cookie is a small text file that a website places on your device and reads back later. Besides cookies there are comparable techniques that serve the same purpose: storing or reading data on your device, or recognising your device remotely — such as local storage in your browser, third-party scripts and pixels, and device fingerprinting. This policy treats all these techniques the same way, regardless of their technical name. Whether a technique requires prior consent depends on its purpose and its effect on your privacy — not on what it is called.

3. Our default: no tracking or advertising cookies

This website is privacy-friendly by design. We place no tracking or advertising cookies. We run no advertising networks and no tracking pixels, we do not follow you across other websites, we do not build advertising profiles of you, and we do not share or sell your data. The public landing page at pagewren.com sets no cookies at all.

We do count visits, because we need to know whether our website is found and which pages are worth keeping. That counting happens on our own server and writes nothing to your device — section 4 explains it and shows you how to switch it off.

4. Visitor statistics, counted on our own server

We count visits with Umami, open-source software we run on our own server in the Netherlands. It is not a third-party service: the figures never leave our own infrastructure, and no analytics company or advertiser ever sees them.

By default nothing is stored on your device. No cookie, no local storage, no browser database. The counting happens on our server, using the request your browser already sends when it asks for a page. The one thing that can end up stored is the opt-out below, if you choose to set it — that preference is yours, so it has to live on your side.

Per page view we record the page, the site you came from, and your country, browser, operating system, device type, screen size and language. Your IP address is not stored — the server uses it briefly to work out which country you are in, then discards it. Nothing in what we keep can be traced back to you.

Switching it off. Turn on Do Not Track in your browser and nothing is recorded at all; our script is set to honour it. Alternatively, open your browser console on this site (usually F12) and run localStorage.setItem('umami.disabled', '1'). That setting lives on your device, so clearing your site data clears it too.

Legal basis. Counting visits is still processing personal data under the GDPR, so it needs a basis: our legitimate interest (art. 6(1)(f) GDPR) in knowing whether our website is found and works. You can object at any time (art. 21 GDPR) — switch it off as above, or mail [email protected]. Switching it off is the effective route, since we store nothing that would let us find your past visits again.

5. Functional/necessary techniques

Some techniques are strictly necessary for this website to work properly. No prior consent is required for these (art. 11.7a(3) Telecommunicatiewet), because they have no — or only a negligible — effect on your privacy. Exemption from the consent requirement does not exempt us from the duty to inform you, so here they are:

NameProviderPurposeRetentionType
pw_session PageWren (portal.pagewren.com, first-party) Keeps you signed in to the client portal after email + one-time-code login 30 days Functional/necessary — exempt from the consent requirement (art. 11.7a(3) Telecommunicatiewet)
__cf_bm and other cf_* cookies Cloudflare Security: bot detection and protection against malicious traffic Typically up to 30 minutes; varies per cookie (see Cloudflare's cookie documentation) Functional/necessary — exempt from the consent requirement (art. 11.7a(3) Telecommunicatiewet)

Payments: billing and payment happen on pages hosted by Stripe (the Stripe customer billing portal). Any cookies used during checkout on Stripe's own pages are set by Stripe on its own domain and are covered by Stripe's own cookie policy.

6. Fonts, served from our own servers

This website's fonts (Bricolage Grotesque and Instrument Sans) are served from our own domain. They are not loaded from Google Fonts or any other font service, so displaying a page sends your IP address to no font provider, and there is no transfer to the United States for this purpose. The font files are redistributed under the SIL Open Font License, version 1.1, which we publish alongside them at /assets/fonts/OFL.txt.

Since August 2026 these fonts have been served from our own domain instead of Google Fonts, which used to send your IP address to Google as an independent controller. This section previously described that Google Fonts arrangement; we have left this note here rather than quietly deleting it.

7. Why there is no cookie banner

A cookie banner asks your permission to put something on your device. We do not put anything there, so there is nothing to ask you about.

That is the whole of it, but here is the reasoning if you want it. The rule behind those banners — art. 11.7a Telecommunicatiewet, which implements art. 5(3) of the ePrivacy Directive — is about storing information on your phone or computer, or reading information that is already there. It is not about measuring as such. Our visitor statistics are counted on our own server (section 4) and write nothing to your device, so the rule never comes into play. The few things that are stored — the portal login and Cloudflare's security cookies (section 5) — are the kind that are strictly necessary for a service you asked for, and those are exempt.

The GDPR still applies, and we have not skipped it: the legal basis and your right to object are in section 4. And if we ever add something that does need your consent, we will update this page and ask you before it loads.

This is our own reasoning, set out openly so you can check it. It is not a legal opinion, and no regulator has assessed or approved it.

8. Managing or deleting cookies in your browser

You can always manage, block or delete cookies and local storage yourself through your browser settings. Note that blocking or deleting certain techniques may stop parts of this website from working properly — for example, deleting pw_session signs you out of the client portal.

9. Your rights

For the personal data processed through cookies and similar techniques, you have the same rights as described in our privacy statement: among others access, rectification, erasure, restriction, objection and data portability. If you have a complaint about how we handle this data, please contact us first at [email protected]. You also have the right to lodge a complaint with the Autoriteit Persoonsgegevens (art. 77 GDPR, autoriteitpersoonsgegevens.nl).

10. Changes

We may update this cookie policy when we add or remove a technique, or when laws or regulations require it. The date at the top shows the latest revision.