Legal
Cookie Policy
Effective date: 29 August 2026 Applies to: vizumapps.com
This policy lists every cookie vizumapps.com sets. There are three. It also explains why you are not asked to accept them, and states the condition under which that answer stops being true.
The controller of the site is identified in section 1.1 of the Privacy Policy, which also governs everything not covered here.
1. The three cookies
These are the cookies the site actually sets, read from the live response headers of https://vizumapps.com/ on 29 August 2026. There are no others.
| Name | Purpose | Duration | Set by | Type |
|---|---|---|---|---|
session_id |
Keeps you signed in. It identifies your session on the server so the site can tell one visitor from another across page loads, hold your authenticated state, and protect form submissions. Without it, signing in is impossible. | 7 days | vizumapps.com (first party) | Strictly necessary |
frontend_lang |
Records the language the site is being served to you in, so the page you get next is in the same language. It holds a language code such as en_US or es_ES and nothing else — no identifier, no visitor number, no history. |
1 year | vizumapps.com (first party) | Strictly necessary |
VZLB |
Session affinity for the load balancer. It records which of the two web servers is handling you, so that every following request goes back to the same one. | 1 hour | vizumapps.com, written by the DigitalOcean load balancer that fronts the site — our hosting processor, acting on our infrastructure, on our own domain | Strictly necessary |
All three are first-party cookies. None of them belongs to another company's advertising or analytics network, and none of them can be read from another website.
session_id is sent only over HTTPS, is not readable by JavaScript, and is restricted with SameSite=Lax. VZLB is likewise not readable by JavaScript and is restricted with SameSite=Lax.
Why VZLB cannot simply be removed
The site runs on two separate web servers. Those two servers do not share sessions and do not share the same file store. If your requests bounced between them, you would be signed out mid-visit and file uploads would land in the wrong place. VZLB is what pins you to one of them. It is load-bearing infrastructure: remove it and the service breaks.
2. Why there is no cookie banner
This is a decision, taken for a reason, and the reason is stated here so you can check it.
Article 5(3) of the ePrivacy Directive (2002/58/EC, as amended by 2009/136/EC), as implemented in each EU member state and mirrored in the UK PECR, requires prior consent before storing anything on your device — and then exempts two cases: storage whose sole purpose is carrying out the transmission of a communication over an electronic communications network, and storage strictly necessary to provide a service that you explicitly requested.
All three cookies fall inside those exemptions:
session_idis an authentication and session cookie. Without it the service you asked for — a site you can sign in to — cannot be delivered. This is the classic case of the second exemption.VZLBis a load-balancing cookie. It exists to route your request across the infrastructure that carries it, which is the first exemption, and section 1 explains why the service breaks without it.frontend_langcarries the language the page is served in and nothing else. It stores no identifier, it cannot be used to recognise you, and it cannot be combined with anything to build a profile. It is there so the site keeps answering you in the language you are reading.
Because these three are exempt, asking you to consent to them would be theatre. A banner that offers a choice which does not exist — a "reject" button that cannot be honoured without breaking the site — is worse than no banner: it teaches people that the choice is meaningless. We would rather tell you exactly what is set, and why.
The exemption removes the requirement for prior consent. It does not remove the reason to tell you what we store, which is what this page is for.
3. What we do not use
To be concrete about what the absence of a banner means here:
- No analytics. No Google Analytics, no Plausible, no Matomo, no server-side product analytics tied to a cookie.
- No advertising or conversion pixels. No Meta pixel, no Google Ads tag, no LinkedIn Insight tag.
- No third-party cookies at all. Nothing on this site is set by a domain other than vizumapps.com.
- No social media plugins that phone home when the page loads.
- No device fingerprinting, and no attempt to identify you without a cookie.
- No cross-site tracking, so there is nothing to opt out of. We do not sell or share personal information as the CCPA and CPRA define those terms, so a Global Privacy Control signal has nothing to act on here.
4. Cookies inside third-party apps
Apps published by third parties run inside a sandboxed frame that is denied the same-origin permission. A frame in that state has an opaque origin: it cannot set cookies, it cannot read the page's cookies, and it cannot reach your session. Third-party app code on this site has no cookie access of any kind.
5. Controlling cookies yourself
Every browser lets you see, block and delete cookies, usually under Settings → Privacy. You can block cookies from vizumapps.com entirely.
Here is what happens if you do, stated plainly rather than as a warning:
- You will not be able to sign in. The sign-in will appear to succeed and then drop you back out.
- Your requests may move between the two web servers mid-visit, which produces errors that look random.
- The site may switch language on you between pages.
Browsing the public catalogue pages without signing in will mostly work.
We do not use a browser's "Do Not Track" header as a signal, because none of the processing on this site is the kind that Do Not Track was designed to stop.
6. When this policy stops being valid
Read this if you are operating or auditing the site.
Everything above rests on one factual claim: that the only cookies set are the three in section 1, and that all three are strictly necessary. The day any tool with a non-necessary cookie is added, that claim becomes false and this policy becomes false with it.
That includes, and is not limited to: any web analytics package, any advertising or conversion pixel, any A/B testing or heat-mapping tool, any embedded video or map that sets its own cookies, any chat widget, any social sharing button that loads from a third-party domain, and any customer-data platform.
Adding any of them requires, on the same day and before the tool goes live:
- A consent mechanism that obtains prior, freely given, specific and informed consent, that makes refusing as easy as accepting, and that does not set the cookie before consent is given.
- A record of consent that can be produced as evidence, and a way to withdraw it that is as easy as giving it.
- This page updated with the new cookie in the table in section 1, its provider, its duration and its purpose.
- A new legal basis in the Privacy Policy, because a non-necessary cookie is not covered by any of the bases in its section 4.2 and would need GDPR consent under Article 6(1)(a).
- A fresh, informed authorization under Colombian law for the new purpose, since the authorization described in the Privacy Policy covers the purposes listed there and not others.
The exemption in section 2 is specific to these three cookies. It does not extend to the next one.
7. Changes to this policy
If the cookies change, this page changes with them, and the effective date at the top changes too. The current text is always at https://vizumapps.com/cookies.
8. Contact
Write to support@vizumapps.com with any question about this page, or about anything you found in your browser that is not listed in section 1. If you found a cookie we have not listed, tell us: that is a defect in this document and we will correct it.