Cookie Policy
Last updated:
Opteno uses as little of your browser’s storage as a web application can. This page lists every cookie and every stored value it sets, on which site, for how long, and why — and says plainly where it sets nothing.
1. What cookies are
A cookie is a small text file a website asks your browser to keep and to send back on each later request. Websites use them to recognise a returning browser — most often to keep you signed in.
Two other things do the same job without being cookies, and this policy covers them as well because a policy that only named cookies would be telling you less than the truth. Local storage and session storage let a page keep a value in your browser: local storage until something deletes it, session storage until you close the tab. Neither is ever sent to a server; a page has to read it and decide to send it.
Everything below is what Opteno actually sets. It was checked against the source and confirmed in a browser on the date at the top of this page. If a kind of cookie is not named here, Opteno does not set it.
2. This website sets no cookies at all
The site you are reading — the marketing pages at opteno.app — writes nothing to your browser. No cookie, no local storage, no session storage. You can check that: open your browser’s developer tools on this page, look under Storage, and it is empty.
There is therefore nothing here to consent to, nothing to opt out of, and no preference for this site to remember about you.
One third-party script does load, and it is worth being precise about it. Cloudflare serves this site, and Cloudflare Web Analytics counts page views. Cloudflare’s network inserts a small script from static.cloudflareinsights.com into the page and it reports back to opteno.app itself. It sets no cookie and stores nothing in your browser — that is the reason this product was chosen over the usual analytics tools. What it does send is the sort of thing every web request sends anyway: the page URL, the referring page, your browser and operating system, your approximate location derived from your IP address, and timing figures for how fast the page loaded. Opteno sees counts and trends from this, never a profile of you, and it is never combined with anything else.
Because Cloudflare terminates the encrypted connection for this site, Cloudflare handles your IP address whether or not that script runs. The privacy policy names Cloudflare as a sub-processor for exactly this reason.
3. The cookies the signed-in dashboard sets
Opteno’s application is a separate site at dash.opteno.app. It sets two cookies, both of them strictly necessary — without them you could not sign in, and the sign-in form could not be protected. There are no others.
Session cookies
Both of Opteno’s cookies are session cookies in the sense that matters: each expires twelve hours after your last request, and signing out deletes both immediately.
- __Host-opteno_session — what proves you are signed in. It holds a random opaque token and nothing else: no name, no email address, no account details. Only a hash of it is stored on our side, so the cookie cannot be reconstructed from our database. It is HttpOnly, so no script on the page can read it; Secure, so it is never sent unencrypted; SameSite=Lax, so it is not sent on a request another site makes; and Path=/ with no Domain, which is what the __Host- prefix means — no other host, including a subdomain, can overwrite it. It lasts twelve hours from your last request and at most thirty days from signing in, whichever comes first.
- __Host-opteno_csrf — what stops another website from acting as you. It holds a random token that the application must echo back in a request header; the two are compared on every request that changes something. This is the one cookie that is deliberately not HttpOnly, because the application has to read it in order to echo it. It carries no authority on its own: on its own it proves nothing and grants nothing. Same flags otherwise, same twelve hours.
Outside production those two names are opteno_session and opteno_csrf. The __Host- prefix is only legal on a cookie sent over HTTPS, so it is applied where the site is served over HTTPS and dropped where it is not.
Persistent storage
The dashboard remembers four interface preferences in your own browser’s storage. None of them is a cookie, none is ever sent to Opteno, and none identifies you to anyone: they exist so the screen looks the way you left it.
- opteno.sidebar.collapsed — whether you collapsed the sidebar.
- opteno.columns.dashboard.<your user id> — which columns you chose to show on the product table.
- opteno.columns.dashboard.image-size.<your user id> — how large you set the product images.
- opteno.selected-store — which store you last had open. This one is session storage, so it is gone when you close the tab.
Clearing your browser’s site data for dash.opteno.app removes all four. You will be signed out and the dashboard will go back to its defaults; nothing else is lost, because none of this is your data — your data is on the server.
Third-party cookies
There are none, on either site. Opteno embeds no advertising tag, no social button, no session-replay script, no chat widget, no A/B testing tool and no tracking pixel. The Cloudflare analytics script described above is the only third-party code that runs anywhere on the marketing site, and it sets no cookie; the dashboard’s content policy blocks even that, so no third-party script runs at all on the screens where your business data is shown.
Signing in to Shopify or to Google to connect an account takes you to Shopify’s or Google’s own site, where their cookies and their policies apply. Opteno neither sets nor reads a cookie on those domains.
4. Managing cookies in your browser
You can delete cookies and site data, and refuse new ones, in every modern browser. Blocking them for opteno.app costs you nothing, because this site sets none. Blocking them for dash.opteno.app means you cannot sign in — the session cookie is how being signed in works.
- Google Chrome: Settings → Privacy and security → Third-party cookies, and Settings → Privacy and security → Delete browsing data.
- Mozilla Firefox: Settings → Privacy & Security → Cookies and Site Data.
- Safari: Settings → Privacy → Manage Website Data.
- Microsoft Edge: Settings → Cookies and site permissions → Manage and delete cookies and site data.
Browsers move these menus between versions; if a path above has moved, your browser’s own help page for “cookies” is the reliable source.
You can also disconnect Opteno from your Shopify or Google account at any time from those accounts, which is a different thing entirely and is covered in the privacy policy.
5. Why there is no cookie banner
There is no consent banner on this site, and this section explains the reasoning rather than leaving you to guess.
The law that puts a banner on most websites — Article 5(3) of the ePrivacy Directive, and the national laws implementing it — is about storing information on your device or reading information already stored there. Opteno’s marketing site does neither. Nothing is stored, so there is nothing for you to be asked about.
The two cookies the dashboard sets are the exception that the same law makes for what is strictly necessary to provide a service you asked for. A cookie that keeps you signed in, and one that stops another site acting as you, are as strictly necessary as cookies get.
The page-view counting does process your IP address at Cloudflare, which is personal data even though nothing is stored on your device. Opteno relies on legitimate interest for that — knowing how many people read a page, with no profile and no identifier — and the privacy policy sets out that basis and how to object to it.
That is a reasoned position, not a settled one. If Opteno ever adds a tool that writes to your device for anything other than signing you in, a consent banner will be built before that tool ships, and this section will be rewritten to describe it. We would rather tell you there is no banner and why than show you one that asks for permission we do not need.
6. Changes to this policy
This page is part of the site’s source code and changes with it, so it cannot drift away from what the product does without somebody changing it on purpose. The date at the top is when it was last reviewed against the code.
If Opteno starts setting a cookie that is not listed here, this page is updated in the same change that sets it.
7. Contact
Write to [email protected] about anything on this page. It reaches a mailbox on Opteno’s own mail server that a person reads.
Opteno is operated by Ksel Technology Limited, registered in Hong Kong (company registration number 76991590). Its registered address is Unit B, 3/F., Kai Wan House, 146 Tung Choi Street, Mongkok, Kowloon, Hong Kong.
The privacy policy covers everything this page does not: what Opteno holds, where it is stored, who else touches it, how long it is kept, and how to export or delete it.