Cookie and browser storage policy
Last updated: 5 September 2026 · version 2026-09-05.1
Information translation. This is a complete information translation. If there is a discrepancy, the Polish version is legally binding.
A cookie is automatically attached to requests to a matching domain. localStorage and sessionStorage do not send values by themselves, but site JavaScript can read them and transmit them to a stated endpoint. The table says when that occurs.
1. Active-mechanism matrix
| Name and type | Contents / reading and transmission | Purpose, category and recipient | Retention and removal |
|---|---|---|---|
dzialka_cookie_consent_v2localStorage, schema v3 | necessary/analytics/ads choice, version, timestamp and expiresAt. Read locally and not sent to an API. | Remembering the decision; necessary to respect the choice. | 180 days; automatically invalid after expiry. Remove site data. |
pw_fpHttpOnly cookie | Random 128-bit value; the browser sends it to InfoGrunt. No UA/screen/language components. | CSRF and short queue/report protection requested by the user; necessary, first-party InfoGrunt/SeoHost. | 30 days; remove site data. Server: CSRF 24 h, queue up to 1 h, report log without a signed-in account 30 days. |
pw_sessHttpOnly cookie | Random session secret; the server stores only SHA-256. | Optional sign-in and account functions; necessary after sign-in. | 30 days, sign-out or account deletion. |
pw_goauth_stateHttpOnly cookie | Random one-use OAuth state sent to the InfoGrunt callback. | Protection of Google sign-in selected by the user. | 10 minutes and removed after callback. |
pw_qacookie | Value 1, read by JS/API and sent as a cookie/QA marker. | Explicit ?qa=1 only; separates technical tests. | 180 days; ?qa=0 or cookie removal. |
ig_browser_nonce_v1localStorage | Random ID, creation and expiry. After consent, JS sends the ID to /api/pageview.php. | First-party analytics; analytics consent. Recipient: InfoGrunt/SeoHost. | 180 days or earlier withdrawal. Server HMACs and raw pageview: 30 complete days. |
ig_campaign_attribution_v1, ig_campaign_landing_pageview_v1sessionStorage | Allowlisted UTMs and click-ID presence flags; JS sends them to /api/pageview.php and /api/track/ping. No click-ID values. | Campaign analytics; analytics consent. InfoGrunt/SeoHost. | Tab session or withdrawal; raw server records 30 days. |
dzialkaRecentlocalStorage | Up to five queries, label, lat/lng and timestamp. The list is not sent; choosing an item starts geocoding/report use. | User-requested recent-search convenience. | 30 days with automatic cleanup; remove site data. |
ig_v_YYYY-MM-DD, ig_pop_YYYY-MM-DDlocalStorage | Local support-message counter/flag; never sent. | Local frequency control. | Seven days with automatic cleanup. |
ig_edit_reload_<id>sessionStorage | 1 flag; the value is not transmitted. | One-use protection against a listing-edit reload loop. | Tab session or completion of editing. |
_ga, _ga_* | Google Analytics identifiers. | Only after analytics consent and with active GA4; Google. | Active Google configuration, no more than the period configured there; removal attempt on withdrawal. |
__gads, __gpi, IDE, NID | Google advertising identifiers. | Only after advertising consent and with active AdSense; Google. | Google configuration; accessible cookies are removed on withdrawal where possible. |
FCCDCF, FCNEC, euconsent-v2 | Local Google CMP choices or message state, read by Google CMP. | After the local ads choice allows Google to load. Not an InfoGrunt analytics identifier. | According to CMP configuration; accessible cookies are removed on local ad withdrawal. Partner choices can be changed in the Google CMP interface. |
Ads also wait for an actual result from the certified Google CMP (TCF). The local category choice is not consent to every partner purpose. Ads stay paused without a valid result. The advertising tag is not loaded on the map, parcel report or account screens. When Google CMP is available, cookie settings include a separate button for partner choices. Switching off local advertising consent stops ads, removes the accessible local Google consent record and reloads the page to unload scripts that were already running.
2. Retired and test-only names
infogrunt_fp, dzialkaRadarSessionId, dzialkaLang*, infogrunt_theme, ig_lang, locale and lang are retired; active code removes rather than creates or transmits them. dzialka_unlock_token, dzialka_csrf, infogrunt_donate_dismissed_until and infogrunt_reports_count_for_donate exist only in unloaded legacy paywall.js. kt_fp_infogrunt.pl_day_v1 belongs to unloaded legacy traffic.js, which is also protected by analytics consent and DNT. Fixture identifiers such as __INFOGRUNT_QA_DEVELOPMENT_STATE are not part of the production bundle.
3. Consent variants
- Before a choice and “Necessary only”: no nonce, pageview, campaign, GA4, GTM, AdSense or DoubleClick.
- Analytics only: first-party pageview and GA4 only when GA4 is configured; no ads.
- Advertising only: no first-party analytics or GA4; AdSense only with an active configuration.
- Withdrawal: blocks future initialisations/requests and removes available first-party identifiers.
- DNT: analytics remains blocked.
An unknown, old or corrupted record is not consent and shows the choice again. Opening settings preserves the current choice until a new selection is explicitly saved. We cannot unload a script that has already been fetched or undo a completed request.
4. External domains and transfers
| Domain | When and why |
|---|---|
tile.openstreetmap.org, photon.komoot.io and public mapping/geocoding APIs | When map/search is used; the provider sees the technical request and connection IP. |
www.googletagmanager.com, www.google-analytics.com | GA4 only after analytics consent and with an active configuration. |
pagead2.googlesyndication.com and DoubleClick domains | AdSense only after advertising consent and with an active configuration. |
Before a choice, after “Necessary only”, after rejection, or after withdrawal, no requests are made to the listed Google domains. Google services may process data outside the EEA under mechanisms stated in their policy, including an adequacy decision or SCCs.
5. Controller
KrolTech Łukasz Król (sole proprietorship registered in Poland)Registered office and service address: ul. Korabnicka 66A, 32-050 Skawina
Electronic address: kontakt@infogrunt.pl
NIP: 9442232002
Rights and the full processing description are in the Privacy Policy.