Skip to main content

Cookie Policy

Last updated: September 23, 2026

This policy covers cookies and equivalent browser storage (localStorage) used by the SolidPing marketing website (www.solidping.io) and by the SolidPing hosted dashboard. It complements the Privacy Policy.

Under Article 5(3) of the ePrivacy Directive and the CNIL's guidance, storing or reading information on your device requires your consent — except where it is strictly necessary to provide a service you explicitly requested. Everything we place on your device is listed below, with which of the two it is.

The short version​

  • This marketing site's own audience measurement is cookieless. It stores nothing on your device, so there is nothing to consent to. The site also stores one browser preference locally, which never leaves your device.
  • One thing on this site does need your consent: Google's advertising tag. It measures whether our ads bring anyone here, and it sets cookies. It is off until you accept it — before you answer, no Google script is loaded and no request reaches Google at all. Refusing takes one click, changes nothing about how the site works, and is remembered.
  • The dashboard sets only what is needed to keep you signed in, plus one interface preference.
  • Product analytics are optional, disabled unless the deployment enables them, exempt from consent only where they meet the CNIL's audience-measurement criteria, and refusable — see Refusing analytics.
  • We run no cross-site tracking and no data brokers, on any surface. The Google Ads tag is conversion measurement for our own ads; we do not build audiences from it or sell anything derived from it.

Marketing website — www.solidping.io​

The site is a static build served from GitHub Pages. GitHub records visitors' IP addresses in its server logs for delivery and security purposes; we do not have access to those logs and we do not use them.

NameTypePurposeDuration
themelocalStorageRemembers your light/dark preference so the site does not flash the wrong theme on load. Never sent to a server.Until you clear browser storage
solidping_consentlocalStorageRecords your answer to the advertising-cookie question below, so we honour it and stop asking. Holds one boolean and a date, nothing else. Never sent to a server.6 months

Both are exempt: the first is a preference you set yourself, and the second exists only to remember a consent decision — storing that is what makes refusing stick, so asking permission to store it would be circular.

The site's own audience measurement sets nothing at all — see Audience measurement below.

We count page views on this site so we know which pages are worth writing and which campaigns are worth running. It is measurement, not tracking, and it is built so that Article 5(3) of the ePrivacy Directive does not bite:

  • Nothing is stored on your device. PostHog runs with in-memory persistence only — no cookie, no localStorage, no sessionStorage, no fingerprint. Because nothing is stored or read, there is nothing to ask your consent for.
  • No identifier follows you. Each page view is an independent, anonymous event. We cannot tell a returning visitor from a new one, and we do not try. No visitor profiles are created.
  • No cross-site tracking. The data is used only to measure this site's own audience, is not combined with any other source, and is not shared with or sold to anyone.
  • No click or form capture. Autocapture and session replay are both off, so what you type, click, or scroll is never recorded.
  • EU hosting. Events go to PostHog's EU instance (Frankfurt), the same processor already listed for the dashboard — see Sub-processors.
  • We honour Do Not Track and Global Privacy Control. With either enabled, the analytics code is never even downloaded.

What we receive per page view is the page URL, the referrer, any campaign tags in the link you followed, and the coarse device and country PostHog derives from the request. None of it identifies you.

To opt out: enable Do Not Track or Global Privacy Control in your browser, or block the request with any content blocker — the site is built so a blocked analytics chunk cannot break it.

NameTypePurposeDuration
_gcl_auCookieGoogle Ads conversion linker. Lets Google attribute a visit to an ad we paid for, so we know which ads are worth running. Set by googletagmanager.com on our own domain.90 days
_gcl_aw, _gcl_dc, _gac_*CookieSet by the same tag when you arrive from a Google ad, carrying the click identifier for that attribution. Not set otherwise.Up to 90 days

Google may set further cookies under its own domains once the tag is running; those are governed by Google's privacy policy and how Google uses data from sites that use its services.

Before you answer, none of this exists. We do not use Consent Mode's "denied" default, which still downloads Google's script and still contacts Google. Until you press Accept, googletagmanager.com is never requested, no Google code runs, and the cookies above are not created. This is enforced in the site's source, in src/consent/ads.ts — the site is open source, so you can check rather than take our word for it.

After you accept, the tag is told exactly what you agreed to, using Google's Consent Mode signals: advertising storage and ad-conversion measurement are granted, ad personalisation is denied, and analytics storage is denied (there is no Google Analytics here). In practice that means Google can tell us that a click on one of our ads led to a signup, and cannot use your visit to build an advertising profile or show you SolidPing ads elsewhere. The conversion we report is the click on a "Start free" button — nothing about who you are travels with it.

Campaign tags follow you into the dashboard, not into a cookie. If you arrived from an ad, the link carried a click identifier (gclid) and campaign tags (utm_*). We keep those in the page's memory only — not in a cookie, localStorage or sessionStorage — and append them to the link when you press "Start free", so the dashboard can attribute the signup to the campaign. Reload the page and they are gone. Our cookieless page-view counting receives the campaign tags and whether a click identifier was present, never the identifier itself.

The advertising tag, and how to say no​

We run ads for SolidPing. The tag exists to tell us whether they work, which is a legitimate thing to want and a non-essential thing to do — so it is opt-in.

  • One question, two equal buttons. Refuse and Accept sit side by side, look the same, and take one click each. There is no pre-ticked box, no "legitimate interest" tab hiding a second list, and no partner list, because there are no partners.
  • Refusing costs you nothing. Every page, link, and document on this site behaves identically either way.
  • Your answer is remembered for 6 months, whichever way you answered, then we ask once more.
  • Do Not Track and Global Privacy Control count as a refusal. With either enabled you are never shown the banner and the tag never loads — we take the signal as the answer instead of asking you to give it twice.
  • You can change your mind at any time, using either control on this page. Withdrawing deletes the Google cookies we can reach from the browser and reloads the page without the tag.

Hosted dashboard​

NameTypePurposeDuration
access_tokenCookieCarries your session so server-rendered and cookie-authenticated flows (notably the OAuth authorisation and consent screens) recognise you without a redirect bounce.Matches the access-token lifetime; cleared on sign-out
solidping_session_tokenlocalStorageThe access token used by the dashboard's API calls.Until sign-out
solidping_refresh_tokenlocalStorageRenews your session without making you sign in repeatedly.Until sign-out or expiry
solidping_expires_at, solidping_expires_inlocalStorageWhen the current token expires, so the dashboard refreshes it before it lapses.Until sign-out
solidping_orglocalStorageThe organisation you are currently working in, so a reload lands you back in the right place.Until sign-out
solidping_last_auth_methodlocalStorageRemembers which sign-in method you used last, so the login page offers it first.Until you clear browser storage

Functional preference​

NameTypePurposeDuration
sidebar_stateCookieWhether the navigation sidebar is expanded or collapsed.7 days

This one is a convenience rather than a strict necessity. It holds a single boolean, is not used to identify or track you, and is not shared with anyone.

Product analytics — optional, off by default​

Where the deployment has PostHog configured, the dashboard loads PostHog to understand which features are used. It is genuinely optional: with no PostHog credentials configured, the analytics code is never downloaded and no request is made to any analytics host — there is no analytics script tag in the page.

NameTypePurposeDuration
ph_*_posthogCookie / localStoragePostHog's own identifier and event queue.Up to 12 months

How it is constrained:

  • Pseudonymous identifier. You are identified to PostHog by a value derived from your organisation and user UUIDs — never your email, name, or IP-derived identity.
  • Session replay, unmasked. The dashboard records replays so we can see where a new account gets stuck before its first check — the one question the event data cannot answer, and a masked replay is not detailed enough to answer either. Replays and autocapture record layout, cursor movement, scrolling, clicks, typed input values, and the pages visited (including organisation slugs and resource identifiers in the URL) as displayed — nothing is masked or rewritten. This does not touch the targets you monitor, your checks' configuration, or any other Service data described elsewhere in this policy; it is limited to how the dashboard's own interface is operated. Replays follow the same retention as the rest of the analytics data and are never shared.
  • Person profiles only for identified users, not for anonymous visitors.
  • EU hosting. Events go to PostHog's EU instance (Frankfurt).

Refusing analytics​

Any of these works:

  • Do Not Track / Global Privacy Control — enable it in your browser; we honour it.
  • Sign out — analytics are only initialised for a signed-in dashboard session.
  • Block the request — any content blocker that blocks PostHog stops it. The dashboard is written so a blocked or failed analytics chunk can never break it.
  • Ask us — email contact@solidping.io to have analytics disabled for your organisation.

Where applicable law requires prior consent for these cookies, they are set only after that consent is given, and refusing has no effect on your ability to use the Service.

Cookies we do not use​

For the avoidance of doubt, on any SolidPing surface we operate: no retargeting or audience-building cookies, no social-media tracking pixels, no fingerprinting, no data brokers, and no sale of any data derived from cookies.

The single advertising cookie family we do set is the Google Ads conversion tag on the marketing site, described above. It is opt-in, it measures our own ads, and it is the only one. It is not present anywhere in the hosted dashboard, on status pages, or in self-hosted SolidPing — those surfaces carry no advertising code at all.

Third-party pages you may reach​

Clicking through to Slack, Discord, GitHub, or any other third-party site takes you to their property, under their cookie policy. The "Add to Slack" button on our Slack page is a static image linking to our own install endpoint — it does not load a tracker.

Self-hosted SolidPing​

If you run SolidPing yourself, the strictly-necessary session storage above still applies, because it is part of how the software works. Everything else is your choice: analytics are off unless you configure a PostHog key, and no data reaches us either way. You are the controller of your deployment and responsible for your own cookie notice — see Self-hosting & GDPR.

Managing cookies in your browser​

You can delete or block cookies and clear local storage from your browser settings (Chrome, Firefox, Safari, and Edge all expose this under privacy settings). Blocking the strictly-necessary items above will sign you out and prevent the dashboard from working.

Changes​

Changes to this policy are published on this page with an updated date. Adding any new non-essential cookie is announced before it ships.

DateChange
September 1, 2026Added the Google Ads conversion tag to the marketing site, behind a consent banner. It is the first non-essential cookie on any SolidPing surface. It loads only after you accept, and refusing is one click.
August 28, 2026Added cookieless audience measurement to the marketing site. No cookie or browser storage was added, and no consent is required.
August 9, 2026Initial publication.

Questions: contact@solidping.io.