Legal

Cookie Policy

Effective 25 September 2026

This policy lists every cookie Vizitka sets, what it is for and how long it lasts. It covers vizitka.app itself, the dashboard and the other addresses we run under vizitka.app, and the websites our customers publish through Vizitka at addresses ending in .vizitka.page or on their own domains.

A cookie is a small piece of text a website stores in your browser and reads back on later visits. We set only the cookies the service needs to work, with one exception: analytics on vizitka.app itself, which sets cookies only after you accept them in the cookie banner. We set no advertising cookies and no cookies that follow you across other websites.

1. Cookies we set

Cookie

Set on

What it does

Lasts

__Host-_vizitka_app_session

Every address we serve, including customers' sites

Protects forms against cross-site forgery, carries a message from one page to the next (for example "your changes were saved"), and remembers which site the dashboard is showing. It holds no identifier of you on a customer's site.

Until you close the browser

__Host-session_id

Our own addresses only (the sign-in screen and the dashboard); never a customer's site

Keeps you signed in to your Vizitka account.

Until you sign out (set with a long expiry so that you stay signed in)

__Host-vz_lang

A site that speaks more than one language, including vizitka.app

Remembers the language you chose with the language switcher. It is set only when you choose, never from your browser's settings.

1 year

__Host-vz_consent

A site that shows a cookie banner, vizitka.app included

Remembers your answer to that site's cookie banner, so that it is not asked again and the tags you refused are not loaded.

6 months

2. Browser storage that is not a cookie

The dashboard remembers which sections of its sidebar you collapsed, in your browser's local storage. Nothing else is stored there, and it is never sent to us.

3. Cookies set by others

On vizitka.app we use Google Analytics and Google Tag Manager to see which pages are read and where visitors come from. Where the law requires consent they load only after you accept them in the cookie banner; if you reject, they are never loaded and nothing below is set. Google Tag Manager sets no cookie of its own. Google Analytics sets:

Cookie

What it does

Lasts

_ga

Tells one visitor's browser from another with a random identifier

2 years

_ga_<id>

Keeps the state of your current visit for our Google Analytics property

2 years

The Privacy Policy says what Google processes for us and on what basis.

On a customer's site, the site's owner may connect the same tools. They set the cookies above, and a Tag Manager container can load whatever tags its owner configured. Where the law requires consent, the site shows a cookie banner and loads those tags only after you accept; if you refuse, they are never loaded. The owner of the site is responsible for those tools and for telling you about them.

Cloudflare, the network every request to us passes through, may set cookies of its own on some addresses to tell a browser from a bot and to keep a connection stable, for example __cf_bm. These are set by Cloudflare for security, last a short time, and are described in Cloudflare's cookie policy.

Google Fonts. Our pages load typefaces from Google Fonts. Fetching a font file sends your IP address to Google, as any download does, but sets no cookie.

4. Managing cookies

You can delete cookies at any time, and set your browser to refuse them. If you refuse the session cookie, forms on our pages and on customers' sites cannot be submitted, and you cannot sign in to the dashboard. You can change your answer to a site's cookie banner, vizitka.app's included, by deleting the __Host-vz_consent cookie for that site; the banner then asks again.

5. Changes

We update this page when a cookie is added, removed or changed. The Privacy Policy explains how the data behind these cookies is used.