Cookie policy
Last updated: 7 August 2026.
This site uses no cookies
That is not a figure of speech: there is not a single cookie on this site, ours or anyone else's. There are no advertising pixels, no Google Analytics, no social buttons pulling in someone else's code. That is why you will find no banner to accept: there is nothing to ask your consent for.
Two things do remain, and both are worth explaining.
1. One entry in the tab's memory
The site stores a single value in the browser's sessionStorage — a kind of memory that, unlike cookies,
is never sent automatically and is wiped when you close the tab.
| Name | What it holds | Lifetime |
|---|---|---|
fmb-state |
An encrypted string, readable only by our server, holding: the outcome of the anti-bot check, a random technical identifier for the visit, the moment you arrived, the site you came from, and two true/false flags on whether you came from a Google Ads or a Meta advertisement. | Until you close the tab |
What it is for
Two things at once.
- Keeping the forms safe from automated submissions. When you land on the site, your browser solves a small computation in the background — nothing to click, nothing you notice — and the result is signed by our server and placed in here. It is what lets the form go through instantly when you press "send", without making you identify traffic lights or bicycles and without involving any external service.
- Knowing where a request came from. If you decide to write to us, a line about where you came from is attached to your request. By the time you send it that information would be gone: after two clicks the referring site is the site itself, and the campaign parameters have vanished from the address bar. That is why it has to be read on arrival and kept here.
What it does not hold
It holds neither your name nor your email address, and no advertising identifier. In particular
we do not keep the click identifier that Google Ads and Meta append to the address
(gclid, gbraid, wbraid, fbclid): the system only looks at
whether one is there, and records a yes or a no. Of the referring site we keep the address and the path, never the
part after the question mark, which in internal searches and other people's private areas may contain personal
data.
The contents are encrypted and signed: your browser holds it but can neither read nor alter it, and a tampered value is simply discarded by the server.
How to get rid of it
Close the tab and it is gone. You can also delete it from your browser's developer tools (Application → Session Storage) or browse in a private window. The forms keep working without it: the anti-bot check is simply repeated when you send.
2. Visit statistics
We use Liwan, a counter installed on a server of ours inside the European Union. It uses no cookies, writes nothing to your device and does not follow you from site to site. It records the page viewed, the site you came from and any campaign parameters in the address.
To count the same person once within a day — and not the day after — it computes a value derived from your IP address and browser through a hash function with a rotating element. The operation cannot be reversed and the result changes every day: the stored data cannot be traced back to you.
3. No calls to external services
The pages load nothing from third-party domains: typefaces, images and videos are all served from our own domain. Opening the site, your browser never contacts Google, Meta or any other platform. The only exception is the links you follow yourself: click through to a project or a social profile and, from that point on, the policy of the site you are opening applies.
Everything else
How we handle the data you send through the forms is explained in the Privacy policy. Any questions: info@fmbdesign.it.
