Small files,
Big Consent
Rules.
This policy explains exactly which cookies we set, why we set them, and how to turn off everything that is not strictly required. No dark patterns - just a clear consent record.
Six things
worth knowing first.
The full policy is below. This summary is the plain-English version of it - the principles that govern every cookie we set on openitfreelancers.com.
What cookies are
Small text files stored on your device that remember things like your login session, your language, and how you use the platform.
What you control
Everything except the strictly necessary cookies. You toggle Preferences, Analytics, and Marketing independently.
What we never do
We never set non-essential cookies before you consent, and we never sell cookie data to ad networks - ever.
How long they live
Session cookies disappear when you close the browser. Persistent cookies expire after 12 or 26 months at most.
Who sets them
Most cookies are first-party (set by openitfreelancers.com). A small set of vetted vendors set cookies only with your consent.
How to withdraw
One click on the cookie panel in the footer. The change takes effect immediately and is logged for compliance.
What cookies
actually are.
A cookie is a small text file placed on your device when you visit a website. It stores a little bit of data that can be read back on your next visit - things like whether you are logged in, what language you prefer, or which engagement you last opened.
Alongside cookies, this policy also covers similar technologies - localStorage, sessionStorage, web beacons, and pixel tags. For simplicity, we refer to all of them as "cookies" throughout this page.
Anatomy of a cookie
oif_session=eyJhbGciOiJIβ¦
- NameA unique identifier for the cookie (e.g. oif_session).
- ValueThe data the cookie stores - usually encrypted or opaque.
- DomainWhich site the cookie belongs to (e.g. openitfreelancers.com).
- ExpirySession (until browser closes) or a fixed date in the future.
- Secure flagWe only set cookies over HTTPS, never over plain HTTP.
- SameSite flagRestricts cross-site use to prevent CSRF attacks.
Related to your rights
Cookie data can be personal data under GDPR. Everything in our Privacy Policy applies to cookie-derived data too.
Four categories,
four independent toggles.
Every cookie on openitfreelancers.com belongs to exactly one of these four categories. You can accept, reject, or change any category at any time.
Strictly necessary
Authentication, session persistence, CSRF protection, load balancing, and consent preference storage. The platform cannot run without them.
Example identifiers
oif_sessionoif_csrfoif_consentPreferences
Remember your language, region, interface density, and recently viewed engagements so you don't have to set them every time.
Example identifiers
oif_langoif_regionoif_themeAnalytics
First-party, IP-anonymised traffic analysis so we can measure load times, feature usage, and improve the platform experience.
Example identifiers
_oifa_oifa_sessionMarketing
Measure the performance of inbound campaigns we run. Only set with explicit consent - never used for retargeting across the web.
Example identifiers
_oifm_campaign_oifm_sourceThe full list,
cookie-by-cookie.
Here is every cookie currently in use on the platform. This table is updated whenever we add, remove, or change a cookie - historical changes are captured in the version log.
oif_sessionNecessaryOpen IT Freelancers (first-party)
Keeps you signed in securely while using the platform.
Sessionoif_csrfNecessaryOpen IT Freelancers (first-party)
Protects you from cross-site request forgery on sensitive actions.
Sessionoif_consentNecessaryOpen IT Freelancers (first-party)
Stores your cookie consent choices so we don't ask again on every page.
12 monthsoif_langPreferencesOpen IT Freelancers (first-party)
Remembers your preferred interface language.
12 monthsoif_regionPreferencesOpen IT Freelancers (first-party)
Keeps your region and local currency in sync.
12 months_oifaAnalyticsOpen IT Freelancers (first-party, IP-anonymised)
Identifies a unique visitor in aggregated traffic analysis.
26 months_oifa_sessionAnalyticsOpen IT Freelancers (first-party, IP-anonymised)
Tracks a single visit for session-duration and bounce-rate metrics.
30 minutes_oifm_campaignMarketingOpen IT Freelancers (first-party)
Attributes inbound visits to the campaign that brought them.
12 months_oifm_sourceMarketingOpen IT Freelancers (first-party)
Records the referring source for campaign performance reporting.
12 months
Third-party cookies,
tightly controlled.
We rely on a short, vetted list of vendors to make the platform work. Every one of them is bound by a Data Processing Agreement and the same security posture we apply internally.
Vetted third-party cookies.
Stripe
Payment processorNecessarySets strictly necessary cookies only on billing pages to complete card transactions and prevent fraud.
Vendor privacy policy βCloudflare
Edge security and cachingNecessarySets a security cookie to distinguish humans from bots and mitigate DDoS attacks.
Vendor privacy policy βIntercom
Support chat (when enabled)PreferencesSets a session identifier so your support conversation persists across pages. Only active when you open the chat widget.
Vendor privacy policy β
What you will not find here.
- No third-party ad networks. Ever.
- No cross-site behavioural advertising trackers.
- No social media 'like' pixels loaded without consent.
- No vendor that refuses to sign a DPA with SCCs.
Vendor updates
If we add or remove a vendor, this section and the cookie table in Section 03 are updated. Material vendor changes are announced at least 30 days in advance.
Your cookies,
your choice.
You decide which categories run on your visit. No non-essential cookie is ever set before you actively make that choice - and you can change it at any time.
Open preferences
Click "Cookie preferences" in the site footer to open the panel. Your choice is stored in the oif_consent cookie for 12 months.
Accept all
Turn on every non-essential category at once. Useful if you want the full experience including analytics and marketing.
Reject optional
Keep only strictly necessary cookies. Preferences, analytics, and marketing stay off.
Granular control
Toggle each category independently. Mix and match - for example, allow preferences but not marketing.
Change your mind
Re-open the cookie panel any time from the footer. New choices take effect immediately and are logged.
Withdraw consent
A one-click option to switch everything non-essential back off. No friction, no dark patterns.
Browser-level controls
Use your browser's cookie settings to block or delete cookies. We respect Global Privacy Control (GPC) signals.
Manage cookies
at the browser level.
In addition to our cookie panel, every modern browser lets you view, block, or delete cookies globally. Blocking strictly necessary cookies may prevent parts of the platform from working correctly.
Google Chrome
Settings β Privacy and security β Cookies and other site data. Choose "Block third-party cookies" or manage per-site exceptions.
Official vendor instructions βSafari
Safari β Settings β Privacy. Toggle "Prevent cross-site tracking" and manage "Manage Website Data".
Official vendor instructions βMozilla Firefox
Preferences β Privacy & Security β Enhanced Tracking Protection. Set to Standard, Strict, or Custom.
Official vendor instructions βMicrosoft Edge
Settings β Cookies and site permissions β Manage and delete cookies and site data. Toggle tracking prevention.
Official vendor instructions βDo Not Track & GPC: We treat Global Privacy Control signals as an opt-out of all non-essential cookies. The legacy DNT header is not widely standardised but we honour it where present.
The legal
framework.
We run a single consent layer that satisfies every major cookie-consent regime our visitors live under. If your jurisdiction has stricter rules, we default to the stricter standard.
The UK General Data Protection Regulation, which governs how personal data derived from cookies is processed.
Privacy and Electronic Communications Regulations - sets the specific rules on cookie consent in the UK.
The EU General Data Protection Regulation, which we apply for every visitor in the European Economic Area.
The EU ePrivacy Directive - the basis for the explicit-consent requirement on non-essential cookies.
California rights regime - we honour opt-out preference signals (including Global Privacy Control).
Changes to
this policy.
We revise the cookie policy whenever we add or remove a cookie, switch vendors, or when the law evolves. Material changes trigger a fresh consent prompt on your next visit.
Notification standard
A new consent prompt for material changes; a discreet banner and changelog entry for minor ones. We never backdate consent.
- 18 April 2026Current
Current policy - added Global Privacy Control (GPC) recognition, updated vendor list, refined category wording.
- 12 November 2025
Restructured into four explicit categories with independent toggles; added granular consent storage.
- 20 March 2025
Removed a third-party analytics vendor in favour of IP-anonymised first-party analytics.
- 04 June 2024
Added cookie panel to the site footer; documented session vs persistent distinction.
Questions about
cookies.
No. Strictly necessary cookies are the only ones required for the platform to work, and those cannot be turned off because they have no alternative. Every other category is optional.
4
Cookie categories
0
Ad trackers
12mo
Consent stored
GPC
Signal honoured
Prefer a conversation?
Our privacy team can walk you through any cookie we set and explain exactly what it does.
Talk to our team βManage your cookies anytime.
Open the cookie panel to toggle categories independently. Your choice is stored for 12 months and can be withdrawn with a single click.
- Accept all, reject optional, or mix and match
- Change your preferences at any time
- Your choice is logged for compliance
- No dark patterns, no nudges, no tricks
Questions about a specific cookie?
Our privacy team can explain what any cookie does, when it is set, and how to remove it. Every email is acknowledged within 72 hours.
- privacy@openitfreelancers.com
- 72-hour acknowledgement SLA
- 30-day response SLA for formal requests
- Structured form available via contact page
Our commitment: Transparent cookies, granular controls, and a consent record you can revisit whenever you want.