Last updated: 29 August 2026
This Cookie & Tracking Policy explains how boxbank s.r.o., operating under the WEBDANGER brand, uses cookies and similar storage, access and tracking technologies on WEBDANGER websites and online services.
This Policy should be read together with our Privacy Policy.
Where applicable law requires consent, non-essential technologies are disabled unless and until the user provides the relevant consent.
1. Who operates WEBDANGER
WEBDANGER is operated by:
boxbank s.r.o.
Registered office:
Jana Palacha 510/50 278 01 Kralupy nad Vltavou Czech Republic
Company identification number (IČO):
24048232
Email:
contact@webdanger.com
Telephone / SMS:
+420 734 627 827
Primary website:
webdanger.com
2. What this Policy covers
This Policy applies to storage, access and tracking technologies used through WEBDANGER websites and online interfaces, including where applicable:
- cookies;
- localStorage;
- sessionStorage;
- IndexedDB;
- browser or device identifiers;
- pixels;
- tags;
- SDKs;
- embedded content;
- conversion tracking;
- analytics;
- advertising identifiers;
- consent records;
- referral identifiers;
- session identifiers;
- anti-fraud technologies;
- and similar browser/device technologies.
Rules that apply to cookies may also apply to other technologies that store information on, or access information from, a user's device.
3. What is a cookie
A cookie is a small piece of information stored on or accessed from a user's device by a website or related service.
Cookies can be used for purposes such as:
- keeping a user logged in;
- remembering settings;
- maintaining a shopping or service session;
- preventing fraud;
- measuring website usage;
- remembering consent choices;
- attributing conversions;
- or supporting advertising.
Some cookies are set directly by WEBDANGER.
Others may be set or accessed by third-party services where those services are activated and permitted.
4. First-party and third-party technologies
A first-party technology is generally operated through the WEBDANGER website or domain.
A third-party technology may be operated by another provider, such as an analytics, advertising, payment, video, security or embedded-content provider.
A technology is not automatically lawful merely because it is first-party.
Likewise, not every third-party technology requires consent in every context.
The applicable purpose and legal rules determine whether consent is required.
COOKIE CATEGORIES
5. Strictly Necessary
Strictly Necessary technologies are used for functionality that is necessary to provide a website or online service requested by the user, operate security controls or maintain essential service functionality.
Examples may include:
- login sessions;
- authentication;
- account security;
- MFA flows;
- CSRF protection;
- load balancing;
- fraud prevention;
- checkout continuity;
- shopping/service cart state;
- domain-management sessions;
- server dashboard sessions;
- privacy and consent preferences;
- language or other settings where strictly necessary to provide the user-selected functionality;
- and similar essential technologies.
Where the applicable legal exemption applies, these technologies may be used without optional cookie consent.
Strictly Necessary technology is not used as a hidden basis for unrelated advertising or behavioural profiling.
6. Preferences and Functionality
Preference or functionality technologies may remember choices such as:
- language;
- currency;
- display options;
- UI preferences;
- region;
- previously selected service configuration;
- accessibility preferences;
- or similar user-requested settings.
Some preference technologies may qualify as strictly necessary where they are genuinely required to provide a functionality expressly requested by the user.
Where they are optional and consent is required, they remain disabled until consent is given.
7. Analytics
Analytics technologies help WEBDANGER understand how visitors use the website and Services.
They may measure information such as:
- pages visited;
- session duration;
- navigation path;
- device/browser type;
- approximate geography;
- referrer;
- campaign source;
- feature usage;
- interactions;
- performance;
- conversions;
- errors;
- and aggregate trends.
Where consent is legally required, analytics technologies remain disabled until the user gives Analytics consent.
Potential analytics providers may include, where actually activated:
- Google Analytics 4;
- Microsoft Clarity;
- first-party WEBDANGER analytics;
- or other providers identified in the active cookie inventory.
8. Advertising and Marketing
Advertising technologies may be used to:
- measure advertising effectiveness;
- attribute conversions;
- create advertising audiences;
- perform remarketing;
- limit or optimise advertising;
- personalise advertising where permitted;
- and measure campaigns.
Where consent is required, these technologies remain disabled until the user gives Marketing consent.
Potential providers may include, where actually activated:
- Google Ads;
- Meta / Facebook / Instagram advertising tools;
- Seznam Sklik;
- LinkedIn Insight Tag;
- TikTok Pixel;
- Microsoft advertising technologies;
- or other advertising providers disclosed in the active inventory.
9. Embedded Content and Media
WEBDANGER may embed or display content from third-party platforms, for example:
- YouTube;
- Vimeo;
- maps;
- social-media content;
- external forms;
- or other embedded services.
Loading embedded content may cause the third party to receive information such as:
- IP address;
- browser/device data;
- page URL;
- cookie identifiers;
- account status with that third party;
- and interaction data.
Where applicable law requires consent before loading such content, WEBDANGER uses a consent-controlled or click-to-load mechanism.
10. Security and Fraud Prevention
Security technologies may be used to:
- detect bots;
- prevent account takeover;
- detect malicious traffic;
- prevent abuse;
- rate-limit requests;
- protect forms;
- detect suspicious payments;
- and maintain website integrity.
Depending on the technology and purpose, some security technologies may qualify as strictly necessary.
Where a provider uses data for additional independent purposes, its role and applicable legal requirements may differ.
CONSENT
11. Consent model
WEBDANGER uses a privacy-first consent model.
Where consent is required, the default state is:
Strictly Necessary: enabled
Preferences / Functionality: disabled unless exempt or requested
Analytics: disabled
Advertising / Marketing: disabled
Non-essential technologies are activated only after the relevant consent has been obtained.
11A. Device-access consent and personal-data legal basis are separate
Consent to store information on, or access information from, a user's device under applicable electronic-communications rules is a separate legal question from the legal basis for any subsequent processing of personal data under data-protection law.
Where both forms of consent are required for the same technology and purpose, WEBDANGER may obtain them through one appropriately designed consent interaction, provided that all legal requirements for each consent are met.
A device-storage exemption for a strictly necessary technology does not automatically authorise unrelated subsequent profiling, analytics or advertising.
12. Cookie banner
Where a consent banner is required, WEBDANGER aims to present clearly accessible options such as:
Accept all
Reject all
Manage preferences
Rejecting non-essential technologies is intended to be as straightforward as accepting them.
The website does not treat inactivity, scrolling, continued browsing or merely closing the banner as consent.
13. Closing the banner
If a user closes the banner without providing consent, non-essential technologies remain disabled.
Closing the banner does not mean:
- Analytics consent;
- Marketing consent;
- advertising consent;
- or consent to optional tracking.
14. No pre-selected optional consent
Optional Analytics or Marketing settings are not treated as validly consented merely because a checkbox or toggle was pre-selected.
Where affirmative consent is required, it requires an active user choice.
15. Granular consent
Where appropriate, users may select individual categories.
Typical settings are:
Strictly Necessary — Always Active
Preferences — Optional
Analytics — Optional
Advertising / Marketing — Optional
A user may accept all optional categories or reject all optional categories.
16. Withdrawing consent
Consent may be withdrawn at any time.
A permanent Cookie Settings or similarly labelled control is made available from the website interface, such as the footer, while the relevant consent system is in use.
Withdrawing consent should be as easy as giving it.
When consent is withdrawn:
- future optional storage/access is disabled;
- applicable tags stop firing;
- consent state is updated;
- and technologies controlled by the consent system are disabled according to the new choice.
Withdrawal does not make prior lawful processing unlawful.
17. Existing third-party cookies after withdrawal
WEBDANGER can stop its website from initiating future optional tracking under its control.
However, a third-party cookie previously placed on a device may remain until:
- it expires;
- the browser removes it;
- the relevant provider removes it;
- or the user deletes it through browser/device controls.
Where technically feasible and appropriate, WEBDANGER may trigger deletion of first-party cookies associated with withdrawn optional consent.
18. Duration of consent choices
For users subject to the Czech/EU consent framework, WEBDANGER generally uses approximately 12 months as the normal interval for renewing a cookie-consent choice, subject to the actual purpose and circumstances. This reflects current Czech supervisory-authority guidance and is not presented as an inflexible statutory maximum.
Where a user rejects optional technologies, WEBDANGER generally avoids requesting the same consent again for at least approximately 6 months, unless:
- material processing circumstances change;
- a new purpose or materially different provider is introduced;
- the previous choice cannot be read because browser data was deleted;
- or another legally justified reason requires a new request.
19. Material changes
A new consent may be requested before the normal renewal period where there is a material change to:
- processing purpose;
- provider;
- controller;
- category;
- data use;
- international-transfer context;
- or another circumstance relevant to the user's original choice.
A purely technical change to an individual cookie name does not automatically require a new consent if the purpose/provider and substantive processing remain unchanged.
20. Google Analytics 4
Where activated, Google Analytics 4 may be used to measure website and product usage.
Depending on configuration and consent, Google Analytics may process information such as:
- device/browser information;
- page and event data;
- approximate location;
- IP-related network information;
- campaign/referrer data;
- cookie/client identifiers;
- and conversion information.
Where consent is required, WEBDANGER uses Google Analytics only after Analytics consent under the strict/basic consent architecture described below.
21. Google Ads
Where activated, Google Ads technologies may be used for:
- conversion measurement;
- advertising attribution;
- remarketing;
- advertising audiences;
- and personalised advertising where permitted.
Marketing consent is required where applicable law requires it.
22. Google Consent Mode v2
Where Google Analytics or Google Ads technologies are enabled, WEBDANGER may use Google Consent Mode v2.
Relevant consent signals may include:
- `analytics_storage`;
- `ad_storage`;
- `ad_user_data`;
- `ad_personalization`;
- `functionality_storage`;
- `personalization_storage`;
- `security_storage`.
For users covered by WEBDANGER's strict consent architecture, Analytics and Advertising signals default to denied until the corresponding consent is given.
23. Basic Google Consent Mode
WEBDANGER's preferred privacy-first implementation is Basic Consent Mode for consent-dependent Google tags.
Under this implementation:
- Google Analytics and advertising tags are blocked before the relevant consent;
- no ordinary Google Analytics/Ads tag data is transmitted before the user grants the required consent through the WEBDANGER consent interface;
- tags load only after the relevant consent choice enables them.
WEBDANGER may change implementation only after verifying that the alternative complies with the applicable law and the disclosures in force.
24. Google remarketing
Where Google remarketing is activated, a user who consents to Marketing technologies may be included in audiences based on interactions such as visiting:
- web-development pages;
- hosting pages;
- domain pages;
- cloud/server pages;
- or other WEBDANGER service pages.
Users who reject Marketing technologies are not intentionally enrolled through WEBDANGER's consent-controlled Google remarketing tags.
META
25. Meta Pixel and Meta Business Tools
Where activated, Meta Business Tools such as Meta Pixel may be used to measure advertising campaigns and create or optimise advertising audiences for platforms such as Facebook and Instagram.
Depending on configuration, Meta may receive:
- page/event data;
- device/browser information;
- IP/network information;
- cookie or browser identifiers;
- conversion events;
- and information deliberately configured by WEBDANGER for supported advertising features.
WEBDANGER does not intentionally send passwords or complete payment-card data to Meta advertising tools.
26. Meta consent
Where consent is required, Meta advertising tools remain disabled until the user gives Marketing consent.
A refusal of Marketing consent does not prevent the user from using the core WEBDANGER website and Services.
MICROSOFT CLARITY
27. Microsoft Clarity
Where activated, Microsoft Clarity may be used to understand website interaction through features such as:
- heatmaps;
- session interaction analysis;
- click behaviour;
- scrolling;
- and usability diagnostics.
Where consent is required, Clarity is classified as an Analytics technology and is disabled before Analytics consent.
28. Clarity masking and sensitive fields
WEBDANGER aims to configure session-interaction tools so they do not intentionally capture:
- passwords;
- payment-card details;
- private API keys;
- authentication tokens;
- secret fields;
- and unnecessary sensitive Customer data.
Areas such as account dashboards, billing, password entry and private Customer project data may be excluded or masked where appropriate.
SEZNAM / SKLIK
29. Sklik
Where activated, Seznam Sklik technologies may be used for:
- Czech-market advertising;
- conversion measurement;
- campaign attribution;
- and remarketing.
Where consent is required, Sklik Marketing technologies remain disabled until Marketing consent is given.
30. LinkedIn Insight Tag
Where activated, LinkedIn Insight Tag may be used for:
- B2B campaign measurement;
- advertising attribution;
- website demographics in aggregated form;
- conversion tracking;
- and advertising audiences.
Where consent is required, it remains disabled until Marketing consent is given.
TIKTOK
31. TikTok Pixel
Where activated, TikTok Pixel may be used for advertising measurement, conversion tracking, audience creation and advertising optimisation.
Where consent is required, it remains disabled until Marketing consent is given.
TikTok is not represented as active merely because this Policy anticipates possible future use.
CLOUDFLARE
32. Cloudflare
WEBDANGER may use Cloudflare for functions such as:
- DNS;
- CDN;
- DDoS protection;
- WAF;
- bot protection;
- performance;
- security;
- and related infrastructure.
Cloudflare may process technical information such as:
- IP address;
- request metadata;
- network/security signals;
- HTTP headers;
- and content transmitted through enabled services.
Some Cloudflare technologies may be strictly necessary for security and network delivery and therefore may not depend on optional Analytics or Marketing consent.
33. Cloudflare Turnstile
Where activated, WEBDANGER may use Cloudflare Turnstile or a similar anti-bot mechanism to protect:
- registration;
- login;
- password reset;
- contact forms;
- checkout;
- and other abuse-sensitive interfaces.
Where the technology is genuinely necessary to secure the requested Service, it may be classified as Strictly Necessary.
It must not be repurposed for behavioural advertising.
STRIPE
34. Stripe checkout and fraud technologies
Where Stripe is used for payment processing, Stripe may use storage/access technologies necessary for purposes such as:
- payment functionality;
- fraud prevention;
- authentication;
- risk analysis;
- and checkout security.
Some such technologies may qualify as necessary for the payment Service.
Stripe's own privacy and cookie practices may apply to Stripe-hosted or Stripe-controlled components.
WEBDANGER does not classify necessary payment security as Marketing merely because a third party provides it.
CHAT
35. WEBDANGER chat
Where WEBDANGER provides a website chat, it may use a short-lived identifier, session storage, local storage or account session to preserve the conversation or maintain functionality.
Where the storage is genuinely necessary to provide the chat requested by the user, it may fall within the necessary/functionality category.
If chat information is used for optional Analytics or Advertising, the corresponding consent category applies.
36. AI chat
Where chat connects to an AI system, related personal-data processing is further described in the Privacy Policy and Data & AI Transparency Notice.
Cookie consent does not by itself create permission for every possible AI processing activity.
EMBEDDED CONTENT
37. YouTube and video
Where third-party video is embedded, WEBDANGER may use a preview or click-to-load mechanism.
Where consent is required, the third-party player is not loaded until the user makes the required choice.
A user may still access the underlying provider directly according to that provider's own terms.
38. Maps
Where external map services are embedded, the map provider may receive device/network information when the map is loaded.
WEBDANGER may use privacy-preserving or self-hosted map technologies where practical.
Where a consent-dependent third-party map is used, it is not loaded before the relevant consent.
39. Fonts and static assets
Where practical, WEBDANGER may self-host fonts and static assets to reduce unnecessary third-party requests.
If an external font or asset provider receives personal data such as IP information through requests, the provider must be reflected in the data inventory where applicable.
LINK DECORATION, CLICK IDS AND ATTRIBUTION
39A. Advertising click identifiers and campaign parameters
A visit to WEBDANGER may contain campaign or advertising parameters in the URL, such as:
- UTM parameters;
- Google click identifiers such as `gclid`;
- Meta/Facebook click identifiers such as `fbclid`;
- Microsoft advertising identifiers;
- Sklik campaign identifiers;
- affiliate/referral identifiers;
- or similar campaign parameters.
The mere presence of such a parameter in an incoming URL does not itself mean that WEBDANGER may persist it indefinitely or use it for cross-session advertising attribution without regard to consent and applicable law.
Where persistence or subsequent use of an advertising identifier requires Marketing consent, WEBDANGER does not intentionally store or activate that consent-dependent attribution before Marketing consent is obtained.
Necessary server/network logs may still temporarily contain the requested URL for security, operational or troubleshooting purposes subject to the Privacy Policy and retention controls.
39B. Server-side attribution and conversion APIs
Server-side tagging, conversion APIs, server-to-server measurement and customer-data matching do not create an exemption from consent or privacy rules merely because the browser does not set a third-party cookie.
Where a server-side advertising or attribution event depends on Marketing consent, WEBDANGER applies the same consent decision to the corresponding server-side processing.
This principle applies to technologies such as:
- Meta Conversions API;
- Google Enhanced Conversions or server-side advertising measurement;
- server-side Google Tag Manager;
- Sklik conversion measurement;
- affiliate conversion callbacks;
- or similar advertising APIs.
WEBDANGER does not intentionally use server-side tracking to circumvent a user's rejection of optional tracking.
REFERRALS AND AFFILIATES
40. Referral tracking
Where WEBDANGER operates a referral or affiliate program, it may use a referral code or similar identifier to determine which partner referred a visitor or Customer.
Referral identifiers may be stored in a first-party cookie, local storage or server-side record for a defined attribution period.
Where the technology is not strictly necessary and consent is legally required, it is not activated before the applicable consent.
41. Affiliate fraud prevention
Referral systems may process limited technical information to prevent:
- self-referral;
- duplicate attribution;
- fraudulent commissions;
- and manipulation.
Security/fraud processing remains subject to applicable privacy law.
EMAIL AND MESSAGE TRACKING
41A. Marketing email measurement
Where WEBDANGER uses tracking pixels, redirect links or similar technologies to measure marketing-email opens or clicks, that processing is subject to the applicable electronic-marketing, storage/access and privacy rules.
Marketing email tracking is not automatically authorised merely because a recipient subscribed to email communications.
Where consent or another specific legal condition is required for the tracking technology, WEBDANGER applies that requirement separately from permission to send the email itself.
Operational/security links in messages, such as password resets, invoice access or domain-renewal actions, may be logged as necessary to provide and secure the requested transaction, but are not repurposed as behavioural advertising without the appropriate legal basis and consent where required.
A/B TESTING AND PERSONALISATION
42. A/B testing
WEBDANGER may test different versions of:
- page layouts;
- headlines;
- pricing presentation;
- CTA placement;
- navigation;
- and other interface elements.
Where possible, first-party experimentation is preferred.
If an experiment uses optional tracking or personalisation requiring consent, it remains disabled until consent.
43. Personalisation
Personalisation technologies may remember a user's preferences or adapt displayed content.
Where consent is required, optional personalisation remains disabled until the relevant consent is given.
FINGERPRINTING
44. Marketing fingerprinting
WEBDANGER does not intentionally use browser/device fingerprinting for advertising or behavioural marketing as a substitute for cookie consent.
Fingerprinting must not be used to circumvent a user's rejection of optional tracking.
45. Security fingerprinting
Limited device or network signals may be used for security, abuse or fraud prevention where appropriate and lawful.
Such processing must be proportionate to the security purpose and must not be silently repurposed for unrelated advertising.
CONSENT RECORDS
46. Consent evidence
WEBDANGER may retain a record demonstrating a user's consent choice.
This may include:
- consent ID;
- timestamp;
- policy/banner version;
- categories accepted/rejected;
- locale;
- expiry/renewal date;
- and limited technical data necessary to demonstrate the choice.
A consent record should not contain unnecessary browsing history.
46A. Browser, device and account scope
A cookie-consent choice normally applies to the browser/device in which the choice is stored.
WEBDANGER does not assume that consent given on one device automatically authorises optional tracking on every other device.
If consent preferences are later synchronised to a logged-in account, the synchronization mechanism must be clearly designed, must preserve withdrawal, and must not convert an unidentified device's rejection into consent merely because the user logs in elsewhere.
47. Consent storage itself
A cookie or local identifier used solely to remember the user's cookie choice may qualify as Strictly Necessary because it is required to honour the user's privacy selection.
LOCAL STORAGE AND OTHER TECHNOLOGIES
48. localStorage and sessionStorage
WEBDANGER may use localStorage or sessionStorage for purposes such as:
- consent preferences;
- temporary UI state;
- chat functionality;
- service configuration;
- language/preferences;
- and other browser-side functionality.
These technologies are not exempt from privacy rules merely because they are not technically called “cookies”.
49. IndexedDB
Where a WEBDANGER web application uses IndexedDB or another browser database, its purpose and consent classification depend on what is stored and why.
Sensitive or unnecessary personal data should not be stored in browser-side databases merely for convenience.
50. Service workers
WEBDANGER may use service workers for technical functions such as:
- caching;
- offline functionality;
- performance;
- push-related functionality where separately enabled;
- and application delivery.
A service worker must not be used to bypass the user's tracking preferences.
USER CONTROLS
51. Cookie Settings
Users can modify their WEBDANGER consent preferences through a Cookie Settings control made available on the website.
This control may allow the user to:
- accept optional categories;
- reject optional categories;
- change previous choices;
- and withdraw consent.
52. Browser controls
Browsers typically allow users to:
- view cookies;
- delete cookies;
- block cookies;
- clear site data;
- control third-party storage;
- and use private-browsing settings.
Blocking all cookies may prevent certain necessary features from working correctly.
53. Global Privacy Control
WEBDANGER may recognise browser-based privacy signals such as Global Privacy Control (“GPC”).
Where an applicable privacy law requires WEBDANGER to treat GPC as an opt-out of sale, sharing or similar regulated advertising activity, WEBDANGER will honour the signal as required.
WEBDANGER may choose to apply GPC more broadly as a privacy-by-design measure.
54. Do Not Track
Some browsers transmit a “Do Not Track” signal.
There is no universally implemented legal or technical standard for all DNT signals.
Where applicable law imposes a required response to a browser privacy signal, WEBDANGER follows that requirement.
REGIONAL APPROACH
55. Czech Republic and European Union
For the Czech/EU environment, WEBDANGER follows an opt-in approach for non-technical storage/access technologies where consent is required.
Non-technical Analytics and Marketing technologies remain disabled unless the required consent is obtained.
56. United Kingdom
UK rules concerning storage and access technologies are governed by PECR together with applicable UK data-protection law.
The Data (Use and Access) Act 2025 introduced additional exemptions for some low-intrusion technologies.
Even where a UK exception may permit a technology without consent, WEBDANGER may apply a stricter global opt-in standard for simplicity, consistency and privacy protection.
57. California and US states
Where WEBDANGER is subject to a US state privacy law that regulates sale, sharing or targeted advertising, the consent/opt-out system may provide additional controls, including:
- recognition of GPC;
- Do Not Sell or Share mechanisms where applicable;
- targeted-advertising opt-out;
- and state-specific disclosures.
The existence of a Marketing-consent control does not replace a mandatory US opt-out where a specific law requires a different mechanism.
58. Strict global baseline
WEBDANGER's preferred baseline is:
Necessary only by default
Analytics off by default
Marketing off by default
This privacy-first baseline may be applied globally even where local law permits a less restrictive configuration.
A jurisdiction-specific implementation may be introduced only after legal and technical review.
COOKIE INVENTORY
59. Current inventory principle
The exact cookie and technology inventory depends on the production stack.
The production version of this Policy or the linked Cookie Settings interface identifies the actual active technologies with information such as:
- name/key;
- provider;
- host/domain;
- purpose;
- category;
- first/third party;
- duration;
- data processed;
- consent requirement;
- and relevant provider information.
WEBDANGER will not intentionally publish a fictional inventory containing technologies that are not deployed.
60. Example technology groups
Depending on what is active, the inventory may contain entries associated with:
- WEBDANGER authentication;
- WEBDANGER consent state;
- WEBDANGER language/currency settings;
- Cloudflare;
- Cloudflare Turnstile;
- Stripe;
- Google Analytics 4;
- Google Ads;
- Meta Pixel;
- Microsoft Clarity;
- Sklik;
- LinkedIn Insight Tag;
- TikTok Pixel;
- embedded YouTube/Vimeo;
- referral tracking;
- and other production technologies.
The active inventory is authoritative as to what is actually deployed.
CHANGES
61. Changes to this Policy
WEBDANGER may update this Policy when:
- technologies change;
- providers change;
- purposes change;
- law changes;
- consent controls change;
- or new Services are introduced.
Material changes that affect the validity or scope of previous consent may require a new consent choice.
62. Contact
Questions about cookies, tracking or consent may be sent to:
boxbank s.r.o. / WEBDANGER
Email:
contact@webdanger.com
Registered office:
Jana Palacha 510/50 278 01 Kralupy nad Vltavou Czech Republic
Effective / review date: 29 August 2026