Legal / Cookies

Cookies

Last updated: 2026-08-24

Everything this site puts in your browser, why it is there, and how long it stays. It is a short page, and that is the point.

The short version

We set two cookies of our own and both are needed to run the shop. We have no analytics, no advertising pixels, no tracking of you across other sites, and nothing that would let us or anyone else recognise you somewhere else. Not as a policy position we might revisit under pressure — there is simply nothing of that kind on this site to disclose.

The list below is not a description of how we think the site behaves. It is what a browser was actually sent, measured page by page against the live site, including the payment page and the page that shows you your eSIM.

What we set

fivebars-session — your session

This holds a random identifier and nothing else. Everything it points at — what’s in your basket, whether you’re signed in — is stored on our server, not in your browser. Your browser will not let any page read it back out, and it is sent only over an encrypted connection.

XSRF-TOKEN — the form guard

A one-purpose token that lets our server tell your form submissions apart from a request another website tried to make on your behalf. It is a security control and it contains nothing about you.

Both last 2 hours from your last visit to a page, and then they are gone. Neither is a permanent marker: come back tomorrow and you arrive as somebody we have never seen.

On every page of this site except the payment page, those two are the whole list — measured, not assumed. What you bought and the email you gave us live in your order record, described on our privacy notice, not in your browser.

On the payment page

The checkout page is the only page on this site that contacts anybody but us. The card fields are supplied directly by Stripe, our payment processor, so your card number reaches them and never us. Stripe sets its own cookies and browser storage there, to keep your payment attempt together and to spot card fraud.

Two of those are written under our domain name rather than Stripe’s, so your browser lists them next to ours. They are still Stripe’s: we cannot read them, we did not choose them, and one of them is long-lived — around a year — because recognising a returning card-testing bot is the job it does.

Stripe also loads hCaptcha, a bot-detection service, to protect the payment form from automated card testing. It sets its own state in your browser too. We did not choose to add it and we cannot switch it off without giving up card payments altogether — so we are telling you it is there instead of leaving you to find it.

Stripe’s fraud checks can bring in further services of their own when something about a payment attempt looks unusual. That happens inside Stripe’s code rather than ours, we do not control it, and we would rather say so than publish a list of exactly two and quietly be wrong on the days it is three.

What reaches them is your IP address and basic information about your browser. None of it is used to advertise to you, and we ask none of them anything about you. No other page on this site loads any of it — which is measured on every other page, not assumed.

We describe what these do rather than list their cookie names and lifetimes, because those are theirs to change and we would rather leave a gap here than publish a table that quietly stops being true. Your browser will show you the full list on that page, and their own policies are linked from our privacy notice.

What we don’t set, and won’t quietly start setting

No Google Analytics or any other analytics product. No advertising or remarketing pixels — no Meta, no TikTok, no Google Ads. No A/B testing tools, no session recorders, no heatmaps, no chat widget, no social share buttons that phone home. No third-party fonts: ours are served from this domain.

There is one thing sitting behind a switch, and you should know it exists. Turning on Apple Pay or Google Pay would make the payment page contact Google as well. That switch is off. If it is ever turned on, this page and the privacy page say so in the same change that turns it on — the disclosure is not allowed to arrive later than the request.

The reason this list is short isn’t restraint. We don’t need to know which of you scrolled how far to sell a data package, and the moment we collect it, it becomes something we have to protect, disclose, and eventually explain.

If you want to clear them

Your browser can delete both of our cookies at any time, and doing so costs you nothing but a signed-in session. Blocking them entirely is also your right — the shop will not work, because there is no way to carry a basket to a payment page without something identifying the basket.

SIA "Ragnarok Solutions" · Reg. No. 50203000401 · VAT LV50203000401 · Lejasdores iela 10, Alderi, Ādažu pag., Ādažu nov., LV-2164 Latvia