QSLExchange
Log in Get started
Home · Cookie Policy

Cookie Policy

Last updated: April 4, 2026

This Cookie Policy explains what cookies and similar technologies QSL Exchange uses, why, and how you can control them. It should be read together with our Privacy Policy.

1. What Are Cookies?

Cookies are small text files stored on your device by your web browser when you visit a website. They help websites remember your preferences, keep you logged in, and understand how the site is used. Cookies can be "session cookies" (deleted when you close your browser) or "persistent cookies" (stored for a set period).

2. Cookies We Use

2.1 Strictly Necessary Cookies

These cookies are essential for the website to function and cannot be switched off. They are set in response to actions you take, such as logging in or filling in forms.

Cookie namePurposeDuration
qslexchange_session Maintains your authenticated session and stores temporary application state. Session (browser close) / configurable
XSRF-TOKEN Cross-Site Request Forgery (CSRF) protection token. Ensures that form submissions and API requests originate from your browser and not from a malicious third party. Session
remember_web_* Set when you choose "remember me" at login. Keeps you logged in across browser sessions without re-entering your credentials. 400 days

Strictly necessary cookies require no consent and cannot be disabled without breaking core functionality. You can delete them by clearing your browser cookies, but you will be logged out.

2.2 Analytics Cookies (Matomo)

We use Matomo Analytics — a privacy-focused, open-source analytics platform — to understand how visitors interact with our website. Matomo is configured to protect your privacy:

  • Your IP address is anonymised before being stored (last two octets removed)
  • Data is not shared with any advertising network or third party
  • Analytics data is processed and stored within the EU
  • Matomo respects the Do Not Track browser header
  • No cross-site tracking or fingerprinting is performed
Cookie namePurposeDuration
_pk_id.* Distinguishes unique visitors. Stores an anonymised visitor ID and timestamps of first and last visit. 13 months
_pk_ses.* Identifies a visitor's current browsing session. 30 minutes
_pk_ref.* Stores the referrer URL used to arrive at the site. 6 months
qsl_cookie_consent Records your cookie banner choice (accepted / rejected) so the banner is not shown again. 1 year
mtm_consent Set by Matomo to record that you accepted analytics tracking. 30 days
mtm_consent_removed Set by Matomo to record that you opted out of analytics tracking. 30 days

Analytics cookies are only placed after you give your consent via our cookie banner. You may withdraw consent at any time (see Section 4).

2.3 Functional / Preference Cookies

We do not currently use dedicated preference cookies beyond the session cookie, which stores temporary UI state (e.g. active callsign selection, flash messages).

2.4 Third-Party Cookies

We do not embed advertising networks, social media widgets, or third-party trackers that would place their own cookies on your device.

Stripe Checkout: When you click "Subscribe" and are redirected to Stripe's hosted checkout page, Stripe may set cookies under their own domain for fraud prevention and session management. These are governed by Stripe's cookie policy. QSL Exchange has no control over these cookies.

Google Fonts / CDN resources: We currently load certain fonts and scripts from external CDNs (Google Fonts, Tailwind CDN). These requests may expose your IP address to those providers. We plan to self-host these resources in a future update.

3. Legal Basis for Analytics Cookies

Analytics cookies are set on the basis of your consent (GDPR Art. 6(1)(a), and ePrivacy Directive). You can accept or decline analytics tracking when you first visit the site, and you can change your choice at any time.

4. How to Control and Opt Out of Cookies

4.1 Cookie Banner

When you first visit QSL Exchange, a cookie consent banner appears at the bottom of the page. You can accept all cookies or choose necessary-only. Your choice is stored in the qsl_cookie_consent cookie for 1 year.

4.2 Matomo Opt-Out

You can opt out of Matomo analytics tracking at any time using the control below:

4.3 Browser Settings

You can configure your browser to refuse all cookies, or to alert you when cookies are being set. Note that disabling strictly necessary cookies will prevent you from logging in.

How to manage cookies in popular browsers:

4.4 Do Not Track

Matomo respects the Do Not Track (DNT) browser header. If DNT is enabled in your browser, Matomo will not track your visit, even if you have not explicitly opted out via the banner.

5. Changes to This Cookie Policy

We may update this Cookie Policy as we change the technologies we use. Material changes will be reflected in the "Last updated" date and communicated where appropriate. We recommend reviewing this page periodically.

6. Contact

For questions about our use of cookies:
Email: privacy@qslexchange.com

Terms of Service Privacy Policy Cookie Policy Impressum