Privacy
Last updated 30 June 2026.
Short version: privacy-first. The contact form is stored so I can reply. A visit count and a human-vs-bot check run without cookies or consent. If — and only if — you accept the consent banner, I also load Loupe's session replay, so I can see where the page confuses people; it masks everything you type, sets no third-party cookies, the recordings stay on my own servers, and I compute a device fingerprint to recognise return visits. No ad-tech, no cross-site tracking. That's it.
What I collect
Only what you type into the contact form: your name, work email, optional company, the kind of work, and your message. It's POSTed to my own API on noogoo.ch, stored in a Cloudflare D1 database, and pulled into my backend so I can reply. If your URL contained UTM parameters (e.g. ?utm_source=…), those are attached for attribution.
Analytics
Both first-party and self-hosted. (1) Always-on, anonymous, no cookies: a visit count and a human-vs-automated (bot) check. Loupe derives a privacy-preserving visitor id at Cloudflare's edge from your IP address and browser that rotates every 24 hours — your IP is never stored, and the id can't be linked across days or back to you; a separate lightweight edge counter logs a page view, the first form focus, and a submit with a per-tab sessionStorage id. This runs regardless of your choice. (2) Only if you accept the consent banner: Loupe's session replay and product analytics (how the page is used, so I can fix confusing spots) plus a device fingerprint computed in your browser to recognise return visits. Replay masks everything you type, sets no third-party cookies, and stays on my own servers; the fingerprint runs only with consent, never if you decline, and is never stored on your device. No third-party analytics either way.
What I don't collect
- No Google Analytics, Meta Pixel, Mixpanel, Segment, Microsoft Clarity or any ad-tech — the only analytics here are the cookieless counter and (with your consent) my own self-hosted Loupe.
- No advertising pixels (Meta, Google, TikTok, LinkedIn — none of them).
- No cross-site tracking, no ad-tech fingerprinting. The only device fingerprint is consent-gated — computed solely if you accept, used only to count return visits, never stored or shared.
- No analytics cookies — Loupe stores its consent flag in
localStorage, not a cookie, and records nothing (beyond the anonymous count) until you accept.
What's stored on your device
A localStorage entry noogoo.lang (your language), a sessionStorage id ng_sid for the cookieless counter (gone when you close the tab), and — once you answer the consent banner — a localStorage flag loupe_consent recording your choice plus a per-tab Loupe session id. You can wipe any of these from your browser any time.
Third parties on this page
- Cloudflare — serves the page and runs the API/database at the edge. It sees normal request metadata (IP, user-agent) as the host.
- Cloudflare Turnstile — a privacy-preserving anti-spam check on the form, in place of a CAPTCHA. No tracking cookies.
- Tailwind CSS CDN & Google Fonts — fetch a stylesheet and fonts. They set no cookies for me.
- Cal.com booking — the "Book a call" link goes to
cal.noogoo.ch, my own self-hosted Cal.com. Opens in a new tab; its cookies are scoped to that domain only.
Your rights
You can ask me to delete or export anything I have on you — the note you submitted plus any email threads. I'll do it. Reach out via any email I've sent you, or book a call from the home page.
Changes
If this page changes materially, I'll bump the date at the top and say what changed. No silent edits.