Cookie Policy
In effect since August 2, 2026. Updated October 5, 2026.
This page explains which cookies the CercaPros website uses and why. In line with Article 30(c) of Law No. 4868/2013 on Electronic Commerce, we disclose this information and offer a simple, free way to opt out.
1. What a cookie is
A cookie is a small file the site stores in your browser to, for example, remember that you're logged in.
2. Which cookies we use
A technical (strictly necessary) session cookie (authjs.session-token) — stores the fact that you're logged in, so you don't have to re-enter your password on every page. It's set by the site's authentication system (Auth.js) on login, lasts up to 30 days and is renewed while you use the site; it's removed on logout or expiry.
Auth.js helper cookies on login: authjs.csrf-token protects the login form against forged requests, and authjs.callback-url remembers which page to return you to after login; both last until you close the browser. Signing in with Google adds authjs.pkce.code_verifier, a one-time check of that particular sign-in, which lasts up to 15 minutes. Over a secure connection, the names of the Auth.js cookies start with __Secure- or __Host-.
A technical language cookie (NEXT_LOCALE) — remembers which language you read the site in once you switch it or log in. Kept for a year. Without it the site would open in the browser's language on every visit.
A short technical marker after consents are updated (cercapros-consent-refreshed) — lives about a minute and only keeps the page from asking for consent a second time while the session is being refreshed.
A technical marker cercapros-session-ended — appears only if the session ended because the account was blocked. It holds the account's ID, encrypted, so that open tabs say the account is blocked instead of asking you to log in again. Kept for up to 30 days; removed at the next login in this browser or once the block is lifted.
Only for the site's administrators: the admin_2fa_session cookie marks that the administrator entered the two-factor code after logging in. It is signed so it cannot be forged, lasts up to 12 hours and is deleted on logout.
The login and registration pages, a password reset request, sending an SMS code, reactivating an account and the form for complaints about infringed rights run Cloudflare's “I'm not a robot” check (Turnstile). It may store its own technical data in your browser, needed to block automated sign-ups, and it receives your IP address. This is not advertising and not cross-site tracking.
Besides cookies, the site uses your browser's storage. localStorage keeps cercapros-install-dismissed-at: the time you closed the offer to install the site on your phone as an app; after that the offer is not shown for 30 days. The entry stays in the browser until you clear the site's data.
sessionStorage keeps form drafts — of a request, a response, a review, registration (name, email, phone number and the mark that it was confirmed, the role chosen and the consent boxes ticked, without the password), the specialist profile and a chat message — so that what you typed is not lost if the page reloads. A draft is deleted once the form is sent and in any case when the tab is closed; it is not sent to the server.
sessionStorage also briefly keeps cercapros:login-identifier: the email or phone number you typed in one form, so that the next one (login, registration, “Forgot your password?”) opens with it. It is deleted as soon as the next form reads it and on a successful login; an entry older than 10 minutes is not used.
We do not use analytics cookies (such as Google Analytics), advertising cookies, or cross-site tracking cookies. The site has no Facebook/Meta pixels or similar tools.
3. What the session cookie is for
Without this cookie you couldn't stay logged in after signing in — you'd have to re-authenticate on every page. It's a strictly necessary cookie, without which the basic “log in” feature doesn't work.
4. How to opt out
Since the session cookie is strictly necessary for logging in, rejecting it means you won't be able to stay logged in across pages — you can still browse the Platform without logging in.
You can delete or block cookies at any time through your browser settings — a simple, free way to opt out, as the law requires. The site's data in your browser's storage is cleared there too.
5. Changes to this policy
If we start using additional cookies (e.g., analytics), this page will be updated in advance, and where required, an explicit consent request will be added.
6. Contact
For questions about cookie use, write to info@cercapros.com.