Cookie and first-party analytics policy
Version: 1.0
Effective: upon publication of this version
Last updated: 21 August 2026
Stable URL: https://shipvise.com/en/cookies/
Translation notice: This English version is a machine-assisted translation provided for convenience. The original Czech version is the authoritative version. Where mandatory law requires otherwise, rights granted by mandatory law remain unaffected.
This document describes cookies and similar technologies on the shipvise.com marketing website and in the app.shipvise.com Portal.
1. Basic principle
The Provider uses only the technical mechanisms necessary for operation and its own internal web analytics.
We do not use marketing, advertising or third-party remarketing cookies in the current MVP.
2. Marketing website
pg_cookie_consent
- Purpose: storing the choice of whether the user accepted or refused analytics cookies.
- Category: necessary/preference, in order to respect the choice.
- Standard duration: 365 days at most.
pg_visitor_id
- Purpose: first-party internal analytics and distinguishing repeat visits.
- Category: analytics.
- Activation: only after the user's corresponding consent.
- Standard duration: 365 days at most, unless the implementation sets a shorter duration.
pg_visitor_id must not be set before consent or after a refusal.
shipvise_session
- Purpose: a necessary short-lived session for CSRF protection and the secure processing of the contact, pilot and abuse forms.
- Category: necessary.
- Standard duration: session cookie; expires when the browser is closed.
- Settings:
HttpOnly,SameSite=Lax, path/; theSecureattribute is used over HTTPS.
3. Progity first-party analytics
The Shipvise analytics mechanism is operated internally to measure traffic and improve the website; it is not used to sell data to third parties or for advertising profiling.
Before analytics consent, the data necessary to serve the request and for security may be processed as part of ordinary HTTP traffic and basic server-side measurement, for example:
- the URL visited;
- the time;
- the referer, if the browser sends it;
- the language;
- technical data naturally transmitted by the network request, including the IP address.
After consent, analytics may in addition link visits using pg_visitor_id and process, for example, the user-agent and interaction events such as clicks on links or opening a FAQ element.
4. app.shipvise.com Portal
The Portal uses only the necessary technical cookies required for login, security and language settings:
| Cookie | Purpose | Category |
|---|---|---|
SHIPVISE_SESSION |
logged-in server-side session | necessary |
XSRF-TOKEN |
CSRF protection | necessary |
NEXT_LOCALE |
language setting | necessary/preference |
These cookies are not used for advertising profiling.
Their technical expiry is governed by the current Portal configuration. On implementation, the production documentation is to be compared with the actual cookie settings.
5. ALTCHA
Contact, pilot, abuse or other public forms may use the self-hosted ALTCHA anti-bot protection.
ALTCHA is not used for advertising or cross-site tracking. During verification, the ordinary technical data of the request needed to protect the form may be processed.
6. Consent and changing it
Where the legal regime requires consent for an analytics cookie, pg_visitor_id must not be set before active consent is given.
The user may change their choice at any time via Cookie settings. After analytics consent is withdrawn:
pg_visitor_idis deleted or is no longer used;pg_cookie_consentmay remain so that the website respects the refusal.
Refusing analytics must not block the use of the website's basic features.
7. Managing cookies in the browser
Cookies can also be deleted or blocked in the browser settings. Blocking necessary cookies may mean that login or forms do not work correctly.
8. Personal data protection
Further information on legal bases, retention and data-subject rights is available at /en/privacy/.

