Legal
Effective July 26, 2026. This policy explains what cookies GoGoLink sets on your device, why we set them, and how you can control them. The short version: we only use a small number of strictly necessary, first-party cookies to keep the service working and keep you signed in — no analytics, advertising, or tracking cookies of any kind.
Cookies are small text files that a website stores on your device when you visit it. They let the site remember things between page loads and visits — like the fact that you're signed in. Cookies set by the site you're visiting are called first-party cookies; cookies set by other companies through that site are called third-party cookies. GoGoLink only sets first-party cookies.
Every cookie we set is strictly necessary to operate GoGoLink: keeping your session alive as you move between pages, protecting forms and in-app requests against cross-site request forgery, and — only if you ask for it — keeping you signed in after you close your browser. We don't use cookies to track you across other websites, build advertising profiles, or measure your behaviour.
This is the complete list of cookies GoGoLink currently sets. All of them are first-party cookies set by our own application.
gogolink-session).
Keeps you signed in as you navigate the app, carries flash messages and interface state,
and pairs with our CSRF protection. It is HttpOnly (not readable by scripts) and expires
after up to 2 hours of inactivity.
XSRF-TOKEN).
Protects forms and in-app requests from cross-site request forgery attacks. It lasts as
long as your session.
remember_web_...).
Only set if you tick "Remember me" when signing in. It keeps you signed in after closing
your browser, is HttpOnly, and persists long-term until you sign out or it is
cleared.
We currently do not use analytics, advertising, or marketing cookies anywhere on our website or in the app — no Google Analytics, no advertising pixels, no session-recording tools, and no third-party cookies of any kind. If that ever changes, we will update this policy and request your consent beforehand, as required under the ePrivacy Directive and the GDPR. Click statistics on your short links are generated by logging the click server-side against the link that was visited — we do not place a tracking cookie on the visitor's device to do this.
Under the ePrivacy Directive and the GDPR, cookies that are strictly necessary to provide a service you have requested are exempt from the consent requirement. All of the cookies listed above fall under this exemption — GoGoLink cannot keep you signed in or protect your account without them — which is why you won't see a cookie consent banner on our site. Should we ever introduce non-essential cookies, we will ask for your consent before setting them.
We also use your browser's local storage — not a cookie — to remember your light/dark theme preference. This value never leaves your device and is not sent to our servers. You can clear it at any time through your browser's site-data settings.
You can view, block, and delete cookies through your browser's settings — usually under "Privacy" or "Site data" — including everything GoGoLink has stored. Keep in mind that because all of our cookies are strictly necessary, blocking or deleting them will sign you out and prevent parts of the service, such as signing in and submitting forms, from working.
Some cookie data, such as your session identifier, relates to your account and is therefore personal data. For details on how we handle personal data more broadly — what we collect, why, how long we keep it, and your rights under the GDPR — see our Privacy Policy.
We may update this policy from time to time — for example, if we add or remove a cookie. If we make material changes, such as introducing cookies that require consent, we'll notify you by email or through the app before they take effect.
Questions about this policy or the cookies we use? Reach us at cookies@gogolink.com.