Cookie policy

Updated 2026-09-24

The LT version is the legally binding one.

1. In short

edapi has no analytics, advertising or tracking cookies. There is no Google Analytics, no Facebook pixel and no other tracking script.

That is why there is no consent banner either: consent is required only for non-essential cookies, and we set none. If we ever add analytics, the banner will arrive with it and such cookies will not run without consent.

2. What we actually store

sesija — the cookie that keeps you signed in. It lasts 30 days, is readable only by the server (httpOnly) and is sent only over HTTPS. Signing in is impossible without it.

salonai_locale — the language you chose, kept in browser storage (localStorage) and in a cookie of the same name (valid for 1 year), so the page opens in that language next time, including the very first server response. It is written only when you pick a language and stores nothing else.

Cloudflare Turnstile — the are-you-human check in the booking form. It may store a short-lived technical value for the result of the check. It is a protection measure; without it the form would be flooded by bots.

A Cloudflare protection cookie (for example __cf_bm) — all traffic passes through Cloudflare, which may set a short-lived cookie to tell bots from people. It stores nothing about your behaviour on the site and is not used for advertising.

3. What third parties receive

Fonts are served from our own server — the browser does not contact any third-party server for them and no cookies are set.

Photos are served from Cloudflare R2 storage and all traffic passes through Cloudflare, which sees technical request data (IP, browser type) needed for protection and delivery.

If a salon takes deposits you are redirected to a Stripe page for payment. The Stripe cookie and privacy rules apply there — it is their site, not ours.

4. How to control it

You can clear cookies and browser storage at any time in your browser settings. Deleting the session cookie signs you out and you will need to sign in again.

Cookies can also be disabled entirely in the browser, but then signing in will not work — the session cookie is essential.

5. Questions

For cookie and data questions write to support@edapi.io. How we handle personal data is described in the Privacy policy.