Cookie Policy — Cyprus Film Crew
Operator / controller: KONIMO Productions LTD ("KONIMO", "we", "us") Platform: cyprusfilmcrew.com Effective date: 11 February 2026
1. Summary — the short version
We run a deliberately minimal, privacy-friendly cookie setup. We use only strictly necessary cookies to sign you in and keep the site secure, plus cookieless analytics. We do not use advertising, marketing, profiling, or cross-site tracking cookies, and we do not sell data to ad-tech. Because we set no non-essential cookies, no cookie-consent banner is currently required under EU/Cyprus ePrivacy rules — strictly necessary cookies are exempt from the consent requirement.
If that ever changes (see §5), we will show a consent banner and not set non-essential cookies until you agree.
2. What cookies are
Cookies are small text files a website stores in your browser. "Similar technologies" include local storage and similar browser storage. They can be session cookies (deleted when you close your browser) or persistent cookies (kept for a set time), and either first-party (set by us) or third-party (set by another domain).
3. Cookies we use
3.1 Strictly necessary — authentication & security (first-party)
Set only once you interact with sign-in. These keep you logged in and protect the sign-in flow, and the site cannot function securely without them. Exempt from consent.
Cookie (name may carry a __Secure-/__Host- prefix on our HTTPS site) | Purpose | Type / duration |
|---|---|---|
next-auth.session-token | Keeps you signed in (holds your encrypted session / JWT). Set by our authentication library (NextAuth). | First-party; session/short-lived persistent |
next-auth.csrf-token | Security — protects sign-in and account actions against cross-site request forgery (CSRF). | First-party; session |
next-auth.callback-url | Remembers where to return you after signing in. | First-party; session |
Transient OAuth state (e.g. next-auth.pkce.code_verifier, state) | Only during a Google sign-in, to complete the OAuth handshake securely. | First-party; very short-lived |
3.2 Security / anti-bot — Cloudflare Turnstile (third-party)
On sensitive forms (e.g. sign-up, contact) we run Cloudflare Turnstile to tell humans from bots. Turnstile is loaded from Cloudflare and may place a short-lived token/challenge value needed to run that check. It is used only for security — Cloudflare states Turnstile does not use cookies for cross-site tracking or advertising.
3.3 Analytics — Cloudflare Web Analytics (cookieless)
We measure aggregate traffic (page views, roughly where visitors come from) using Cloudflare Web Analytics, which is cookieless and does not track you across sites or build a profile of you. Because it sets no cookies, it needs no consent.
4. Cookies we do not use
- ❌ Advertising or re-targeting cookies
- ❌ Cross-site / third-party tracking or profiling cookies
- ❌ Social-media tracking pixels
- ❌ Selling or sharing of data with ad networks or data brokers
5. If we add non-essential cookies in future
If we ever introduce cookies that are not strictly necessary (for example richer analytics, or a future feature that needs them), we will:
- show a cookie-consent banner giving you a genuine choice (accept / reject / manage);
- set those cookies only after you opt in; and
- update this policy first.
6. Managing cookies yourself
You can block or delete cookies in your browser settings at any time. Note that blocking the strictly necessary cookies in §3.1 will stop you from being able to sign in or use logged-in features.
7. More information
This policy sits alongside our Privacy Policy (at /privacy), which covers all personal data and your GDPR rights, and our Terms & Conditions (at /terms). For any question, write to us by post at our registered address or contact us through the Platform: KONIMO Productions LTD, Stavrou Stylianide 100, Ergates, 2643, Nicosia, Cyprus. Company Registration No. HE 487989.