Cityfolk
COOKIES

Cookie Policy

Most services publish a cookie policy that runs for pages because they have a lot to explain. We have one cookie, and it is the one that keeps you signed in. This page lists it in full: its name, what is inside it, how long it lasts. Then it sets out the one thing we count without a cookie, and the things we do not run at all, so you can check the page source and see for yourself. Cityfolk is run by RAGE AGENCY LTD, registered in England and Wales.

Gültig ab · 19 August 2026

01

The one cookie we set

cityfolk_session

  • What it does. It is your sign-in. Without it the site cannot tell one person from another, and every page would treat you as a stranger.
  • What is inside it. A signed token carrying your user id and nothing else. Not your name, not your email, not your plan, not your role. Everything else about you is read from the database on each request.
  • Category. Strictly necessary. It is not optional, because without it there is no signed-in site to use.
  • How long it lasts. Seven days, then it expires and you sign in again.
  • Its settings. httpOnly — scripts on the page cannot read it. sameSite=lax — it is not sent along with requests started by other sites. secure in production — it only travels over HTTPS. path=/ — it applies across the site.
  • Who can read it. Us. It is set by our own domain, it is signed with a key only our server holds, and it is sent to nobody else.

You can delete it in your browser at any time. Doing so signs you out. Blocking it entirely means you cannot sign in at all.

02

What we count, and what we do not run

There is one measure of how the site is used, and it needs no cookie, because it never touches your browser at all. It runs on our own server, and what it writes down is a tally.

The daily count. For each day, each page path in its normalised form, and each site language, a number goes up by one. That is the entire record: a date, a path, a language, a count. Normalised means the shape of a page rather than the page itself, /events/[id] and never the id of one particular night, so a sitting that few people looked at cannot turn into a number that is really about one person. And:

  • It stores nothing on your device and reads nothing from it. No cookie, no localStorage, no sessionStorage, no pixel, no script. There is nothing in your browser to inspect, because nothing was put there.
  • It keeps no request log. The individual page view is not written down anywhere. Only the running total is.
  • It does not keep your IP address. Your address reaches our server because that is how the internet delivers a page to you, and it goes with the request. It is never stored, never hashed into an identifier, and never joined to the count as anything other than "one more".
  • It builds no fingerprint. No user agent, no screen size, no fonts, no headers combined into a signature. The language recorded is the language the page was served in, kept as its own daily total and joined to nothing.
  • It cannot tell one visitor from another. There is no visitor id, no session id, no unique-visitor figure, and no way to reconstruct one. Ten pages read by one person and one page read by ten people look identical to us.
  • It goes nowhere else. No third-party service, no vendor account, no export, no sharing.

What that gives us is the shape of a week: which pages get read, in which language, on which day. What it cannot give us is you.

Why it needs no consent. Consent to *storage* is an ePrivacy question, and ePrivacy governs what a site puts on, or reads from, your device: regulation 6 of PECR in the UK, article 5(3) of the ePrivacy Directive in the EU, article 45c of the Telecommunications Act in Switzerland. The counter does neither, so that rule is not engaged. Consent to *processing* is a data protection question, and the UK GDPR, the EU GDPR and the revised Swiss FADP all govern personal data, meaning data about a person who is identified or identifiable. A date, a path, a language and a number is not that. It names nobody, singles nobody out, and cannot be turned back into a person, by us or by anybody else, because there is no identifier in it and it is sent to nobody. So there is no lawful basis to declare and no box to ask you to tick. If that ever stops being true, because we start keeping addresses, ids, or anything else that separates one visitor from the next, it becomes analytics like everybody else's and you will be asked first.

And the list of absences. This is the whole of it, and it is unchanged.

  • No third-party analytics. No Google Analytics, no Plausible, no Fathom, no Matomo, no product analytics, no session recording, no heatmaps. Nobody else measures this site, and no measurement leaves our own server.
  • No advertising or conversion pixels. No Meta pixel, no Google tag, no remarketing, no attribution scripts.
  • No third-party embeds pulling scripts, fonts or images from somebody else's server.
  • No localStorage or sessionStorage used to identify or follow you.
  • No cross-site tracking, no advertising identifiers, no data brokers.
  • No IP address logging. Sign-in throttling counts failed attempts against the account in the server's memory, not against your network address, so there is nothing to store. The daily count does not keep addresses either.
  • No profile of you. Nothing we count is attached to your account, and being signed in changes none of it.

There is nothing here to opt out of, because nothing here is about you.

03

If we ever add a cookie banner

A banner is only honest when there is a choice behind it. Today there is not: a cookie that is strictly necessary to deliver a service you asked for needs no consent, not under the UK rules (PECR), not under the EU ePrivacy rules, and not under Swiss law. The daily count in section 02 does not create a choice either, because it puts nothing on your device to accept or refuse. So what you get is a notice, not a consent gate.

If we later add anything optional, we will ask first, nothing optional will load before you answer, and remembering your answer will itself need a cookie:

cityfolk_cookie_consent

  • What it does. Remembers what you chose, so we do not ask again on every page.
  • What is inside it. Your choice and the date you made it. No identifier, nothing that ties back to you if you are not signed in.
  • Category. Strictly necessary / preference. Storing a refusal is not tracking, and it is the only way to honour the refusal.

We will update this page and the effective date at the top before any such cookie is set.

04

Controlling cookies yourself

Every browser lets you see the cookies a site has set, delete them, and refuse new ones. It is under Privacy or Site settings in Chrome, Safari, Firefox and Edge.

Deleting or blocking cityfolk_session signs you out and keeps you out. Nothing else we set will ever be worth blocking, because there will not be anything else unless you have said yes to it.

05

Changes

We update this page when what we set changes. The effective date at the top tells you which version you are reading. If we ever add a cookie beyond the two named here, it will be listed here before it is set, and we will email you.

Found something we have not listed here?

RAGE AGENCY LTD, trading as Cityfolk Registered in England and Wales, company number 16311448 Questions about cookies or anything else on this page: [DPO OR PRIVACY CONTACT]

[DPO OR PRIVACY CONTACT]