Cookie Policy
Last updated August 13, 2026
This page lists every cookie WhenPick sets, what it does, and how long it lasts. It is a companion to our Privacy Policy.
We do not track you
WhenPick runs no analytics, no advertising, and no third-party tracking. There is no Google Analytics, no Meta pixel, no session-recording tool, and no cross-site tracking. Every cookie below is set by WhenPick itself and is needed for the service to work.
The cookies we set
| Cookie | What it does | How long it lasts |
|---|---|---|
whenpick-session |
Keeps you signed in and preserves form state between page loads. | 120 minutes of inactivity. |
XSRF-TOKEN |
Protects forms against cross-site request forgery. | Until you close your browser. |
remember_web_* |
Keeps you signed in between visits. Only set if you choose "Remember me" when signing in. | Up to 5 years, or until you sign out. |
poll_anonymous_id |
A random identifier so you can return and edit the poll response you submitted without an account. It carries no personal information on its own. | 1 year. |
signup_anonymous_id |
The same thing for signup sheets. It lets you change or withdraw a signup you made without an account. | 1 year. |
The anonymous identifier, in detail
The two one-year identifiers deserve a fuller explanation, because a year is a long time and we would rather over-explain than under-explain.
When you respond to a poll or sign up on a sheet without creating an account, we need some way to recognise you if you come back, because otherwise you could not correct a mistake or withdraw your availability. So we generate a random value, store it in a cookie, and attach it to your response. It is not derived from anything about you, it is not shared with the host, and it is not used to build a profile or to follow you to other sites.
It is also stored in localStorage
Be aware of this one: poll_anonymous_id is also mirrored into your browser's
localStorage. If the cookie is missing but the localStorage value is present, the page recreates
the cookie from it, with a fresh one-year expiry. We do this because browsers clear cookies more aggressively than
localStorage, and losing the identifier means losing the ability to edit your own response.
The practical consequence is that deleting cookies alone will not remove this identifier. To clear it properly, use your browser's "clear site data" or "delete site settings" option for this site, which clears localStorage as well. In Chrome and Edge that is under the padlock icon in the address bar; in Firefox and Safari it is in the site-data section of settings. Once cleared, you will no longer be able to edit responses you made earlier.
What happens if you create an account
If you later sign in or register in the same browser, we use the identifier to link the responses you already submitted to your new account, so they appear in your dashboard. At that point the anonymous identifier is removed from those records and they become associated with your account instead. If you would rather that did not happen, clear your site data before signing in.
Why there is no cookie banner
Under the EU ePrivacy Directive, UK PECR and comparable rules, consent is required for cookies that are not strictly necessary for a service the user has asked for. Every cookie on this site is strictly necessary: sign-in state, CSRF protection, an opt-in "remember me" you actively choose, and the identifiers that make anonymous responses editable. We set nothing for analytics, advertising or profiling, so there is nothing meaningful for a banner to ask you about. If that ever changes, we will add a proper consent mechanism before setting a single non-essential cookie.
Managing cookies
You can block or delete cookies through your browser settings. If you block them for this site, sign-in will not work, forms will be rejected, and you will not be able to edit responses you submitted anonymously.
Contact
Questions about cookies: [email protected] .