Version 1 · effective 7 October 2026
This text is a draft until it has passed legal review.
Cookie policy
This policy explains the cookies and similar browser storage used on the qread marketing site (qread.org), the business panel and the partner panel. Menus that businesses offer to their guests carry their own privacy and cookie notices.
How you decide
- Cookies needed for the site to work are always on.
- Functional, statistics and marketing cookies are used only if you allow them. On the first screen "Accept all", "Reject all" and "Preferences" carry the same weight.
- You can change or withdraw your choice at any time from the "Cookie preferences" link in the footer of every page.
- If you reject, we do not ask again for 6 months; we ask again if this policy or the cookie list changes materially.
Cookieless measurement
We count page views with a method that writes nothing to your browser: no IP address is stored, counts are anonymised with a salt that changes every day, and you are not tracked across days.
Cookies and storage we use
Necessary
| Name | Purpose | Duration | Provider |
|---|---|---|---|
__Host-branch | Remembers the branch you selected in the panel. | 1 year | qread |
__Host-callback | Carries the page to return to after sign-in. | Session | qread |
__Host-csrf | Protects the sign-in form against forged requests (CSRF). | Session | qread |
__Host-imp | Carries a time-limited support session while our team views your account at your request. | Up to 1 hour | qread |
__Host-oauth-nonce | Prevents replay attacks during Google sign-in. | 15 minutes | qread |
__Host-oauth-state | Verifies that a Google sign-in request is yours. | 15 minutes | qread |
__Host-pkce | Protects the verification code during Google sign-in (only while signing in). | 15 minutes | qread |
__Host-session | Keeps you signed in (encrypted session token). | 7 days | qread |
__Host-signup | Holds your sign-up draft ID while you fill in the form; it does not hold a referral code. | 24 hours | qread |
__Host-tenant | Remembers the business you selected if you have several. | Session lifetime | qread |
qr_consent | Remembers your cookie choice and a random consent ID so you are not asked again. | 6 months (rejected) / 12 months (other) | qread |
Statistics
| Name | Purpose | Duration | Provider |
|---|---|---|---|
_ga | Google Analytics ID that distinguishes visitors; set only if you consent and the tag is enabled. | 2 years | Google (Google Analytics 4) |
_ga_{id} | Keeps Google Analytics session state; set only if you consent. | 2 years | Google (Google Analytics 4) |
qread_stats_beacon | Cookieless page-view count; writes nothing to your browser, stores no IP address and counts anonymously with a daily-rotating salt. | No storage | qread |
Marketing
| Name | Purpose | Duration | Provider |
|---|---|---|---|
_gcl_au | Google Ads conversion measurement; set only if you allow marketing cookies. | 90 days | Google (Google Ads) |
qr_ref | Remembers the referral code that brought you here (first click wins); set only if you allow marketing cookies. | 60 days | qread |
Contact
Questions: destek@qread.org