The operator of this Leadskout can replace this text.
Cookies
A cookie is a small note the browser stores for this site. Leadskout uses a few first-party cookies so you can stay signed in, so a form post can be checked, and so the banner at the bottom of the page can stay dismissed after you accept it.
Cookies this site sets
Leadskout sets only the cookies described on this page. They come from this site. They are not placed by an advertising network.
- A session cookie, so a signed-in desk stays signed in while you use it.
desk_cookie_ok, for one year, after you press Accept on the banner.XSRF-TOKEN, the usual CSRF cookie that lets Leadskout check a form post.
The session cookie’s name follows the app. With the default name Leadskout, that cookie is desk-session unless the operator has set a different session cookie name. If you are looking at a browser list and you see only those, that matches this page.
Staying signed in
The session cookie keeps you signed in. It holds the session that knows your account after you enter your password, and a second code if you turned on an authenticator. Guest pages use the same kind of session so the captcha on a public form can remember the current challenge.
This cookie is first-party. It is sent back to Leadskout when you load a page or submit a form. Closing the browser does not, by itself, wipe the default session; the server drops an idle session on its own schedule. Signing out ends the signed-in session.
The choice on the banner
The first visit shows a short banner: Leadskout uses a session cookie to keep you signed in and to remember this choice. Accept posts to this site, with the form’s CSRF field, and the server sets desk_cookie_ok.
That cookie lasts one year, uses SameSite Lax, and is first-party. It stores that you accepted the banner. It does not store your name, your form answers, or a visitor’s photos. After it is set, the banner stays hidden. If you delete it, the banner can show again.
The check that protects a form post
Leadskout also sets XSRF-TOKEN. That is the usual CSRF cookie for this application. A logged-in form, including Accept on the banner, includes a matching token. The cookie and the token let Leadskout refuse a post that did not come from a page it just showed.
The token is part of staying safe while signed in. It is not used to follow you on other websites. The same session that holds your sign-in holds the server side of that check.
Cookies Leadskout does not use
Leadskout does not add Google Analytics. There is no analytics cookie, and no measurement cookie from a statistics vendor.
Leadskout does not set third-party advertising cookies. There is no marketing cookie, no ad pixel, and no cookie whose job is to follow a visitor onto other sites. If a cookie list on this site is longer than the session cookie, desk_cookie_ok, and XSRF-TOKEN, it did not come from the product described here.
Clearing a cookie in the browser
You can delete cookies for this site in your browser’s settings. Deleting the session cookie signs you out. Deleting desk_cookie_ok lets the banner show again on the next visit. Deleting XSRF-TOKEN only means the next form post will need a fresh page so the token matches.
Blocking every cookie will keep the banner from remembering Accept, and it will keep you from staying signed in. The forms that ask for a captcha also rely on the session. There is no separate preference center, because there is no advertising category to switch off.